Close RAIL-HO-WP-0009 declared-state gaps; leave live 6443 prune gated
Make the k3s API tunnel-only (ADR-005), stop declaring Flannel VXLAN open to Anywhere, tag the base role so firewall can be scoped, and schedule the Goss declared-vs-live check. CoulombCore sets ufw_manage false so a converge cannot enable UFW there. T02 still needs operator approval for make converge-firewall HOST=Railiance01.
This commit is contained in:
parent
434121be99
commit
4d9e77c968
29 changed files with 793 additions and 99 deletions
|
|
@ -18,12 +18,24 @@ def load_tf_outputs():
|
|||
return {}
|
||||
|
||||
def load_host_vars(name):
|
||||
"""Load host_vars/<name>.yml if it exists."""
|
||||
"""Load host_vars/<name>.yml if it exists.
|
||||
|
||||
The inventory script is ansible/inventory_from_yaml.py. Ansible does not
|
||||
auto-load a host_vars directory next to a script inventory, so this has
|
||||
to emit hostvars itself. Look in ansible/inventory/host_vars first (where
|
||||
CoulombCore.yml actually lives), then the unused repo-root path.
|
||||
"""
|
||||
script_dir = os.path.dirname(__file__)
|
||||
path = os.path.join(script_dir, '..', 'inventory', 'host_vars', f'{name}.yml')
|
||||
if os.path.exists(path):
|
||||
with open(path) as f:
|
||||
return yaml.safe_load(f) or {}
|
||||
candidates = [
|
||||
os.path.join(script_dir, 'inventory', 'host_vars', f'{name}.yml'),
|
||||
os.path.join(script_dir, 'inventory', 'host_vars', f'{name}.yaml'),
|
||||
os.path.join(script_dir, '..', 'inventory', 'host_vars', f'{name}.yml'),
|
||||
os.path.join(script_dir, '..', 'inventory', 'host_vars', f'{name}.yaml'),
|
||||
]
|
||||
for path in candidates:
|
||||
if os.path.exists(path):
|
||||
with open(path) as f:
|
||||
return yaml.safe_load(f) or {}
|
||||
return {}
|
||||
|
||||
def main():
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue