- Update ansible.cfg with new configuration - Modify inventory/group_vars/all.yml for group variables - Update playbooks/services.yml service definitions - Remove deprecated playbooks/deploy.yml Implements: Configuration updates for new service architecture
46 lines
1.1 KiB
YAML
46 lines
1.1 KiB
YAML
traefik_acme_email: "admin@jfraeys.com"
|
|
traefik_certresolver: "cloudflare"
|
|
|
|
ansible_port: "{{ lookup('env', 'TF_VAR_ssh_port') | default(22, true) }}"
|
|
ansible_ssh_private_key_file: "{{ lookup('env', 'ANSIBLE_PRIVATE_KEY_FILE') | default(lookup('env', 'HOME') ~ '/.ssh/id_ed25519', true) }}"
|
|
|
|
grafana_hostname: "grafana.jfraeys.com"
|
|
forgejo_hostname: "git.jfraeys.com"
|
|
prometheus_hostname: "prometheus.jfraeys.com"
|
|
|
|
app_hostname: "app.jfraeys.com"
|
|
web_apps_scheme: "http"
|
|
web_apps_port: 80
|
|
|
|
auth_hostname: "auth.jfraeys.com"
|
|
lldap_base_dn: "dc=jfraeys,dc=com"
|
|
|
|
# Cloudflare IP ranges for firewall allowlisting
|
|
cloudflare_ips:
|
|
- 173.245.48.0/20
|
|
- 103.21.244.0/22
|
|
- 103.22.200.0/22
|
|
- 103.31.4.0/22
|
|
- 141.101.64.0/18
|
|
- 108.162.192.0/18
|
|
- 190.93.240.0/20
|
|
- 188.114.96.0/20
|
|
- 197.234.240.0/22
|
|
- 198.41.128.0/17
|
|
- 162.158.0.0/15
|
|
- 104.16.0.0/13
|
|
- 104.24.0.0/14
|
|
- 172.64.0.0/13
|
|
- 131.0.72.0/22
|
|
# IPv6 ranges
|
|
- 2400:cb00::/32
|
|
- 2606:4700::/32
|
|
- 2803:f800::/32
|
|
- 2405:b500::/32
|
|
- 2405:8100::/32
|
|
- 2a06:98c0::/29
|
|
- 2c0f:f248::/32
|
|
|
|
# App deployment versioning - overridden at deploy time via --extra-vars
|
|
app_version: "latest"
|
|
app_name: ""
|