Close RAIL-HO-WP-0009 declared-state gaps; leave live 6443 prune gated
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Make the k3s API tunnel-only (ADR-005), stop declaring Flannel VXLAN
open to Anywhere, tag the base role so firewall can be scoped, and
schedule the Goss declared-vs-live check. CoulombCore sets ufw_manage
false so a converge cannot enable UFW there. T02 still needs operator
approval for make converge-firewall HOST=Railiance01.
This commit is contained in:
codex 2026-08-15 15:41:59 +02:00
parent 434121be99
commit 4d9e77c968
29 changed files with 793 additions and 99 deletions

View file

@ -18,12 +18,24 @@ def load_tf_outputs():
return {}
def load_host_vars(name):
"""Load host_vars/<name>.yml if it exists."""
"""Load host_vars/<name>.yml if it exists.
The inventory script is ansible/inventory_from_yaml.py. Ansible does not
auto-load a host_vars directory next to a script inventory, so this has
to emit hostvars itself. Look in ansible/inventory/host_vars first (where
CoulombCore.yml actually lives), then the unused repo-root path.
"""
script_dir = os.path.dirname(__file__)
path = os.path.join(script_dir, '..', 'inventory', 'host_vars', f'{name}.yml')
if os.path.exists(path):
with open(path) as f:
return yaml.safe_load(f) or {}
candidates = [
os.path.join(script_dir, 'inventory', 'host_vars', f'{name}.yml'),
os.path.join(script_dir, 'inventory', 'host_vars', f'{name}.yaml'),
os.path.join(script_dir, '..', 'inventory', 'host_vars', f'{name}.yml'),
os.path.join(script_dir, '..', 'inventory', 'host_vars', f'{name}.yaml'),
]
for path in candidates:
if os.path.exists(path):
with open(path) as f:
return yaml.safe_load(f) or {}
return {}
def main():