Both demo sites had only a hosts.yml, so every role ran on its defaults (authentik.local.test etc.) and nothing was reachable under the real FQDN. Add the complete group_vars + host_vars analogous to gymburgdorf, with the mbaz.souveredu.ch / phbe.souveredu.ch domain bases, matching Bao mounts, DMZ split-horizon (public + *.int.*), authentik OIDC/LDAP/proxy outposts, nextcloud with S3+LDAP+OIDC, collabora, drawio, garage, send, opnform, homarr and bookstack. authentik_domains lists the *.int.* name too so Traefik requests a cert the DMZ can verify; the storage proxy outpost carries a config block (required by the outpost blueprint serializer).
8 lines
371 B
YAML
8 lines
371 B
YAML
---
|
|
# Send: anonymized self-hosted file-share (no login). First entry is the
|
|
# canonical public FQDN (used as BASE_URL); the *.int.* entry covers the
|
|
# server-to-server hop from the DMZ reverseproxy with a cert SAN that
|
|
# matches the backend hostname (same split-horizon pattern as cloud/draw).
|
|
send_domains:
|
|
- "send.mbaz.souveredu.ch"
|
|
- "send.int.mbaz.souveredu.ch"
|