all: children: all_servers: hosts: reverseproxy: ansible_host: 172.16.9.114 ansible_user: root application: ansible_host: 172.16.19.111 ansible_user: root storage: ansible_host: 172.16.19.112 ansible_user: root turn: ansible_host: 172.16.9.115 ansible_user: root traefik_servers: children: all_servers: backend_servers: hosts: application: storage: garage_servers: hosts: storage: nextcloud_servers: hosts: application: collabora_servers: hosts: application: drawio_servers: hosts: application: authentik_servers: hosts: application: authentik_outpost_ldap_servers: hosts: application: # Proxy (ForwardAuth) outpost co-located with garage on storage, so # the garage-webui ForwardAuth subrequest stays on the local docker # network instead of crossing an extra reverseproxy hop (which mangles # X-Forwarded-Host and breaks the embedded outpost's app matching). authentik_outpost_proxy_servers: hosts: storage: send_servers: hosts: application: opnform_servers: hosts: application: homarr_servers: hosts: application: bookstack_servers: hosts: application: