feat(demo): add full inventories for mbazürich and phbern #2

Open
Simon wants to merge 5 commits from feat/demo-mbaz-phbe-inventories into main
2 changed files with 7 additions and 1 deletions
Showing only changes of commit 91d5be8d21 - Show all commits

View file

@ -8,3 +8,6 @@ _authentik: "{{ lookup('community.hashi_vault.hashi_vault', vault_mount + '/data
# the LAN with a valid cert and matches the iss claim authentik emits. # the LAN with a valid cert and matches the iss claim authentik emits.
authentik_outpost_ldap_host: "https://auth.gymb.souveredu.ch" authentik_outpost_ldap_host: "https://auth.gymb.souveredu.ch"
authentik_outpost_ldap_token: "{{ _authentik.ldap_outpost_token }}" authentik_outpost_ldap_token: "{{ _authentik.ldap_outpost_token }}"
# auth.gymb.* presents a valid Let's Encrypt cert via the reverseproxy, so
# verify the chain instead of relying on the role's insecure default.
authentik_outpost_ldap_insecure: "false"

View file

@ -10,7 +10,10 @@ _authentik: "{{ lookup('community.hashi_vault.hashi_vault', vault_mount + '/data
# via the internal DNS view to the DMZ reverseproxy the storage subnet can # via the internal DNS view to the DMZ reverseproxy the storage subnet can
# reach). Token must match the storage-proxy-outpost registered in # reach). Token must match the storage-proxy-outpost registered in
# authentik (see application/authentik.yml authentik_proxy_outposts). # authentik (see application/authentik.yml authentik_proxy_outposts).
# Verify the authentik TLS chain: auth.gymb.* presents a valid Let's
# Encrypt cert via the reverseproxy and the storage subnet reaches it, so
# there's no reason to disable verification (verified: ssl_verify_result=0).
authentik_outpost_proxy_host: "https://auth.gymb.souveredu.ch" authentik_outpost_proxy_host: "https://auth.gymb.souveredu.ch"
authentik_outpost_proxy_token: "{{ _authentik.proxy_outpost_token }}" authentik_outpost_proxy_token: "{{ _authentik.proxy_outpost_token }}"
authentik_outpost_proxy_insecure: "true" authentik_outpost_proxy_insecure: "false"
authentik_outpost_proxy_network: "proxy" authentik_outpost_proxy_network: "proxy"