feat(demo): add full inventories for mbazürich and phbern
Both demo sites had only a hosts.yml, so every role ran on its defaults (authentik.local.test etc.) and nothing was reachable under the real FQDN. Add the complete group_vars + host_vars analogous to gymburgdorf, with the mbaz.souveredu.ch / phbe.souveredu.ch domain bases, matching Bao mounts, DMZ split-horizon (public + *.int.*), authentik OIDC/LDAP/proxy outposts, nextcloud with S3+LDAP+OIDC, collabora, drawio, garage, send, opnform, homarr and bookstack. authentik_domains lists the *.int.* name too so Traefik requests a cert the DMZ can verify; the storage proxy outpost carries a config block (required by the outpost blueprint serializer).
This commit is contained in:
parent
a8c8ac3e1e
commit
d45e358efc
44 changed files with 1458 additions and 10 deletions
2
inventories/demo-phbern/group_vars/all/ansible.yml
Normal file
2
inventories/demo-phbern/group_vars/all/ansible.yml
Normal file
|
|
@ -0,0 +1,2 @@
|
|||
---
|
||||
ansible_python_interpreter: /usr/bin/python3
|
||||
1
inventories/demo-phbern/group_vars/all/docker.yml
Normal file
1
inventories/demo-phbern/group_vars/all/docker.yml
Normal file
|
|
@ -0,0 +1 @@
|
|||
docker_registry_mirrors: ["https://registry-mirror.wksbern.ch"]
|
||||
2
inventories/demo-phbern/group_vars/all/vault.yml
Normal file
2
inventories/demo-phbern/group_vars/all/vault.yml
Normal file
|
|
@ -0,0 +1,2 @@
|
|||
vault_addr: "https://bao.digitalboard.ch"
|
||||
vault_mount: "demo-phbern"
|
||||
Loading…
Add table
Add a link
Reference in a new issue