ansible-edda/inventory/host_vars/valkyrie/vars.yml

52 lines
2.3 KiB
YAML

---
# --------------------------------------------------------------------------------------------------
# system:mail
# --------------------------------------------------------------------------------------------------
system_mail_smtp_pass: "{{ vault_system_mail_smtp_pass }}"
# --------------------------------------------------------------------------------------------------
# system:base
# --------------------------------------------------------------------------------------------------
system_base_udp_ports:
- 546 # dhcpv6
- "{{ vpn_wireguard_port }}"
# --------------------------------------------------------------------------------------------------
# system:var
# --------------------------------------------------------------------------------------------------
system_var_hostname: "valkyrie"
# --------------------------------------------------------------------------------------------------
# vpn
# --------------------------------------------------------------------------------------------------
vpn_subnet_id: 1
# --------------------------------------------------------------------------------------------------
# vpn:wireguard
# --------------------------------------------------------------------------------------------------
vpn_wireguard_role: "server"
vpn_wireguard_interface_private_key: "{{ vault_vpn_wireguard_interface_private_key }}"
vpn_wireguard_clients:
- public_key: "{{ vault_vpn_wireguard_clients_0_public_key }}"
preshared_key: "{{ vault_vpn_wireguard_clients_0_preshared_key }}"
inet_subnet: "\
{{ hostvars.yggdrasil.vpn_bridge_inet_prefix }}.0/\
{{ hostvars.yggdrasil.vpn_bridge_inet_prefixlen }}"
inet6_subnet: "\
{{ hostvars.yggdrasil.vpn_bridge_inet6_prefix }}::/\
{{ hostvars.yggdrasil.vpn_bridge_inet6_prefixlen }}"
# --------------------------------------------------------------------------------------------------
# services
# --------------------------------------------------------------------------------------------------
services_host_services:
rproxy:
inet_address: "{{ vpn_bridge_inet_prefix }}.2"
inet6_address: "{{ vpn_bridge_inet6_prefix }}::2"
tcp: [80, 443]
restic: true
www:
inet_address: "{{ vpn_bridge_inet_prefix }}.3"
inet6_address: "{{ vpn_bridge_inet6_prefix }}::3"
restic: false