Make the k3s API tunnel-only (ADR-005), stop declaring Flannel VXLAN open to Anywhere, tag the base role so firewall can be scoped, and schedule the Goss declared-vs-live check. CoulombCore sets ufw_manage false so a converge cannot enable UFW there. T02 still needs operator approval for make converge-firewall HOST=Railiance01.
62 lines
2.7 KiB
YAML
62 lines
2.7 KiB
YAML
# Ansible group vars — applied to all managed hosts.
|
|
#
|
|
# custodian_agent_pubkey: "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIC/V9fe5MGKdhTBz9KwEvC1NE+HjdoCtQocpGxP6Pko9 custodian-agent"
|
|
#
|
|
# HOW TO SET THIS:
|
|
# 1. Generate the keypair on the workstation (one-time):
|
|
# cd ~/the-custodian && make custodian-keygen
|
|
# This creates ~/.ssh/id_custodian_agent (private, never committed)
|
|
# and writes the public key to:
|
|
# ~/railiance-infra/ansible/inventory/group_vars/all.yaml ← this file
|
|
#
|
|
# 2. Commit the updated all.yaml (public key only — safe to commit).
|
|
#
|
|
# 3. Deploy to all managed hosts:
|
|
# cd ~/railiance-infra && make provision-custodian-agent
|
|
#
|
|
# The key below is a placeholder — replace by running `make custodian-keygen`.
|
|
|
|
custodian_agent_user: tegwick
|
|
custodian_agent_pubkey: "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIC/V9fe5MGKdhTBz9KwEvC1NE+HjdoCtQocpGxP6Pko9 custodian-agent"
|
|
|
|
# ops-bridge tunnel key — injected by the base role so ops-bridge connectivity
|
|
# is available as early as SSH infrastructure is up.
|
|
# Private key lives at ~/.ssh/id_ops on the workstation. Never commit the private key.
|
|
ops_bridge_user: tegwick
|
|
ops_bridge_pubkey: "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIKQmXbAVlEa8dzGx8Hk2S7AITpz6sMWdCN0MeMOzL82u ops-bridge@custodian"
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# k3s API firewall (6443/tcp) — tunnel only (ADR-005)
|
|
#
|
|
# Public allowlist is empty. Reach the API over ops-bridge:
|
|
# bridge up k3s-api-railiance01 # local 16444
|
|
# bridge up k3s-api-coulombcore # local 16443
|
|
#
|
|
# Revoked addresses are pruned on a firewall-tagged converge so rotated or
|
|
# retired grants do not remain standing. Do not add new public sources here
|
|
# without amending ADR-005.
|
|
k3s_api_allowed_sources: []
|
|
|
|
k3s_api_revoked_sources:
|
|
- address: "89.244.90.248"
|
|
comment: "hand grant added 2026-08-12/15; retired by ADR-005"
|
|
- address: "89.244.90.236"
|
|
comment: "rotated ISP lease; retired by ADR-005"
|
|
- address: "89.244.90.255"
|
|
comment: "rotated ISP lease; retired by ADR-005"
|
|
- address: "89.244.90.246"
|
|
comment: "rotated ISP lease, superseded 2026-08-11"
|
|
- address: "85.132.220.102"
|
|
comment: "historic operator address; also the 2026-08-15 workstation lease"
|
|
|
|
# Single-node clusters need no public VXLAN grant. Set peer addresses here
|
|
# only when a second node must exchange Flannel frames (RAIL-BS-WP-0007).
|
|
flannel_vxlan_allowed_sources: []
|
|
|
|
# HostEurope Nydus agent — provider dashboard, root-password reset, backups.
|
|
# Required by the VPS platform (hosteurope/260308-dependency-nydus.md).
|
|
# Source-restricting it would break the provider; Anywhere is intentional.
|
|
ufw_extra_allowed:
|
|
- port: "2224"
|
|
proto: tcp
|
|
comment: "nydus-ex-api dashboard agent"
|