--- # Same token as authentik_ldap_outpost.token above — outpost uses it to # authenticate against the authentik server it talks to. _authentik: "{{ lookup('community.hashi_vault.hashi_vault', vault_mount + '/data/authentik', url=vault_addr) }}" # Public FQDN resolves (internal DNS view) to the DMZ reverseproxy the # backend subnet can reach, so the outpost->authentik round-trip stays in # the LAN with a valid cert and matches the iss claim authentik emits. authentik_outpost_ldap_host: "https://auth.mbaz.souveredu.ch" authentik_outpost_ldap_token: "{{ _authentik.ldap_outpost_token }}" # auth.mba.* presents a valid Let's Encrypt cert via the reverseproxy, so # verify the chain instead of relying on the role's insecure default. authentik_outpost_ldap_insecure: "false"