reference-ansible/inventories/demo-gymburgdorf/host_vars/application
Simon Bärlocher 91d5be8d21
fix(demo-gymburgdorf): verify authentik TLS chain from outposts
Both outposts reach authentik over auth.gymb.*, which presents a valid
Let's Encrypt cert via the reverseproxy (verified: ssl_verify_result=0
from the storage subnet). Drop the insecure TLS skip:

- proxy outpost: authentik_outpost_proxy_insecure -> "false"
- ldap outpost: pin authentik_outpost_ldap_insecure "false" instead of
  relying on the role default ("true").

Addresses the automated security review finding (TLS verification disabled).
2026-06-05 14:29:18 +02:00
..
authentik.yml feat(demo-gymburgdorf): gate garage-webui via storage-local proxy outpost 2026-06-05 14:27:37 +02:00
authentik_outpost_ldap.yml fix(demo-gymburgdorf): verify authentik TLS chain from outposts 2026-06-05 14:29:18 +02:00
bookstack.yml refactor(demo-gymburgdorf): drop DNS workarounds now backend can reach DMZ 2026-06-05 13:49:30 +02:00
collabora.yml chore(demo-gymburgdorf): finish ACME, LDAP, DMZ routing for live inventory 2026-05-27 23:18:58 +02:00
drawio.yml fix(demo-gymburgdorf): route cross-host ForwardAuth via dedicated outpost FQDN 2026-06-04 11:07:48 +02:00
homarr.yml refactor(demo-gymburgdorf): drop DNS workarounds now backend can reach DMZ 2026-06-05 13:49:30 +02:00
main.yml chore: wip on demo-gymburgdorf inventory and architecture notes 2026-05-27 23:12:57 +02:00
nextcloud.yml refactor(demo-gymburgdorf): drop DNS workarounds now backend can reach DMZ 2026-06-05 13:49:30 +02:00
opnform.yml refactor(demo-gymburgdorf): drop DNS workarounds now backend can reach DMZ 2026-06-05 13:49:30 +02:00
send.yml docs(reference-ansible): add docs/ tree and document repo, playbooks, Makefile 2026-05-28 11:20:54 +02:00
traefik.yml docs(reference-ansible): add docs/ tree and document repo, playbooks, Makefile 2026-05-28 11:20:54 +02:00