summaryrefslogtreecommitdiff
path: root/inventory/host_vars/sk-cloudio/vars.yml
blob: b5c95965421c6869604bb1d25ce58711d6d793ab (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
---
system_lvm_volume_size_root: 3584M
system_lvm_volume_size_varlog: 5G
install:
  cloud:
    credentials: "{{ vault_hroot_robot_account }}"
    server_name: "{{ host_name }}"
  disks:
    primary: software-raid
    raid:
      level: 1
      members:
      - /dev/nvme0n1
      - /dev/nvme1n1
  system_lvm:
    size: 15G


apt_repo_components:
  - main
  - contrib  ## for zfs
  - non-free-firmware

spreadspace_apt_repo_components:
  - main
  - container


zfs_arc_size:
  min: 2GB
  max: 16GB

zfs_pools:
  storage:
    mountpoint: /srv/storage
    create_vdevs: mirror /dev/nvme0n1p3 /dev/nvme1n1p3

zfs_sanoid_modules:
  storage/nextcloud:
    use_template: production
    recursive: yes
    process_children_only: yes
  storage/etherpad-lite:
    use_template: production
    recursive: yes
    process_children_only: yes
  storage/keycloak:
    use_template: production
    recursive: yes
    process_children_only: yes
  storage/onlyoffice:
    use_template: production
    recursive: yes
    process_children_only: yes


docker_pkg_provider: docker-com

docker_storage:
  type: zfs
  pool: storage
  name: docker
  properties:
    quota: 40G

kubelet_storage:
  type: zfs
  pool: storage
  name: kubelet
  properties:
    quota: 20G

kubernetes_version: 1.29.2
kubernetes_container_runtime: docker
kubernetes_standalone_max_pods: 100
kubernetes_standalone_pod_cidr: 192.168.255.0/24
kubernetes_standalone_cni_variant: with-portmap

kubernetes_standalone_local_services_tcp:
  - 25

postfix_base_mynetworks:
  - "127.0.0.0/8"
  - "[::ffff:127.0.0.0]/104"
  - "[::1]/128"
  - "{{ kubernetes_standalone_pod_cidr }}"
postfix_base_inet_protocols:
  - "ipv4"


acme_directory_server: "{{ acme_directory_server_le_live_v2 }}"
acme_client: acmetool

## TODO: remove once migration of elevate services has been done
ssh_users_root:
  - equinox
  - dan
  - brt