diff --git a/.vault/vault-keys b/.vault/vault-keys index 9dddb9f..ae38c9d 100644 --- a/.vault/vault-keys +++ b/.vault/vault-keys @@ -1,4 +1 @@ -D749E2966193DF63 -EE3E0A7A87192BB7 -3C8D0C7EF49AB5A3 -388DD8D74903017E +88CBCAD842520E46 diff --git a/.vault/vault-pass.gpg b/.vault/vault-pass.gpg index 7b6b4dd..e743d3e 100644 Binary files a/.vault/vault-pass.gpg and b/.vault/vault-pass.gpg differ diff --git a/files/manifests/secret-digitalocean-dns.yaml b/files/manifests/secret-digitalocean-dns.yaml index 4a5e725..784f633 100644 --- a/files/manifests/secret-digitalocean-dns.yaml +++ b/files/manifests/secret-digitalocean-dns.yaml @@ -1,19 +1,19 @@ $ANSIBLE_VAULT;1.1;AES256 -37633666323130636331326338626330663531323239656265636464376534653664393535323234 -3231316434616366656265373863663431333466323831350a616337336363346163363962643130 -30663862656334303862643333366237376538633937366332333535303264366562336136336363 -6632316663353138620a643230666534653231666534653837333536333930646465623533373639 -65323839643535373666313866373764663832366231333832336135623930306564363930373539 -62376134666332323837396634616465323132643933353738376166313236303063663463646561 -35653738636264653739326132366530663962306133353061653764353261333737666638343039 -34663762636439303530313865366236666131373561323337323539623266666136653232656466 -36383833336235623939653765373331313333623031376539613536663134356632313762616364 -66363036623538663635306438373962323538323234343234623364633165363865396563366339 -37363232313764646237316630643463343561653362373436346663643738356334353431356261 -39383131346237636435303338303462636531376639383765343733303133393731326538363862 -36643831303030656239613938323862323539356339386435633663306430623838653763373337 -38336431303539383831653739313063373539323937353333626235626130613266666230666365 -32326238353439393538353939306235643762646339393362633632663638666564363431663366 -66366435613262356165373538373138353031356365316262343733663763373031623435323366 -63653165386561616562623230376461383936353738313333646335623937353566303462616232 -6533356562323134643839313765393933656537633337363932 +37303132393466333261633739343530323037363563346263393337306262386434616236623830 +6439616662356337653935346434323638326432363531660a333235636264313765646330363263 +31616232373735373834393965353930316161393265366431653639646438376534656462326337 +3036653763363530330a333461643731636535643532323139393238353431313034323066363635 +31336534383163303233383936383533663437663637323335326335356135653063303133643764 +35613638663736636166353734303333666332633434313766346332373565633166356561643030 +64626163636562323964346137313238633036396232393766393137663134396663613933646539 +63666435333763323862636536313436383133343031363232333433656264386139653030383465 +63333137356463303865393939303463333031383563393837623261333734353261326333316461 +66343135656631396230303665373033663431356464636163613333643362383162613861393435 +32626562653337313638623764646463663034363065306633346365303366643166633436643936 +32653865363631623839313533333831386339633837353233313730643939336265343764643131 +34363734616237373237303039643261376664376636386164643433366436353162656232336330 +39336436353235396633313265353939373262303637373830623439303132386666646130626330 +62653462343838303266343830366565666639353362343662653234396365353339343330623039 +37653335323564323762653338666634363237303830653736623963306564643831353233663630 +32386131373263613139326534633432666364656561663461643031663230643366363036336631 +3039393835346431346231636665396138393336343963333466 diff --git a/files/manifests/wildcard-pwa-realitynetwork.yaml b/files/manifests/wildcard-pwa-laconic.yaml similarity index 51% rename from files/manifests/wildcard-pwa-realitynetwork.yaml rename to files/manifests/wildcard-pwa-laconic.yaml index a3f4e29..01a6f83 100644 --- a/files/manifests/wildcard-pwa-realitynetwork.yaml +++ b/files/manifests/wildcard-pwa-laconic.yaml @@ -1,15 +1,15 @@ apiVersion: cert-manager.io/v1 kind: Certificate metadata: - name: pwa.realitynetwork.store + name: pwa.laconic.com namespace: default spec: - secretName: pwa.realitynetwork.store + secretName: pwa.laconic.com issuerRef: name: letsencrypt-prod-wild kind: ClusterIssuer group: cert-manager.io - commonName: "*.pwa.realitynetwork.store" + commonName: "*.pwa.laconic.com" dnsNames: - - "pwa.realitynetwork.store" - - "*.pwa.realitynetwork.store" + - "pwa.laconic.com" + - "*.pwa.laconic.com" diff --git a/group_vars/all/vault.yml b/group_vars/all/vault.yml index 73a890e..eb08362 100644 --- a/group_vars/all/vault.yml +++ b/group_vars/all/vault.yml @@ -1,7 +1,7 @@ $ANSIBLE_VAULT;1.1;AES256 -35636534633536663965623866666430613934363036343661343362346534353764326662396365 -3039363533323464353932373436356362353261343836620a616132336266346238336338653434 -35616334333832356134353466623333363235373066396663363839656663326666323164393265 -6338323565323936350a356136353231613765366531366431363864356565653938613963656233 -66613965396531636331353463333436376337363932393033303937383263336637663435373262 -3361356561306233303030313438363637343433356463626536 +37613532616632663366373332616133316237633564386464643032636137356436623331313365 +3164613836383930663466306133336263393764306662620a616131366561306334656535663432 +31323566373730353338356365663764386266383831666637646361626433343162313039343964 +3837666333343133630a343534366535613765336134623532323038633466666538356235323464 +65326264393765383138393661616537323864333036353130633461383865643030366363623437 +6162376537646461343066316234663730663466303931646630 diff --git a/group_vars/lcn_cad/k8s-vault.yml b/group_vars/lcn_cad/k8s-vault.yml new file mode 100644 index 0000000..de9db9b --- /dev/null +++ b/group_vars/lcn_cad/k8s-vault.yml @@ -0,0 +1,8 @@ +$ANSIBLE_VAULT;1.1;AES256 +32623937306230646432336339336134316263616136383264623030623930633664346263643165 +3539396565353163656432303038613736343430643765330a353465613136396436613565396638 +63396333363766353737363438383262623539376666316531303535663832303363356631633735 +6666643461626262350a393136306662666232356532366666323765356330333838363162356330 +61333233666634373666636630623865333838653762393634306464336636633633646266623263 +33373831613266373839383666326264376362646638386566656362656130383861633933666564 +383930616533303265633661363335633064 diff --git a/group_vars/rnt_cad/k8s.yml b/group_vars/lcn_cad/k8s.yml similarity index 89% rename from group_vars/rnt_cad/k8s.yml rename to group_vars/lcn_cad/k8s.yml index d78f43f..c94be83 100644 --- a/group_vars/rnt_cad/k8s.yml +++ b/group_vars/lcn_cad/k8s.yml @@ -1,9 +1,9 @@ --- # default context is used for stack orchestrator deployments, for testing a custom context name can be usefull -#k8s_cluster_name: rnt-cad-cluster +#k8s_cluster_name: lcn-cad-cluster k8s_cluster_name: default -k8s_cluster_url: rnt-cad-cluster-control.realitynetwork.store -k8s_taint_servers: true +k8s_cluster_url: lcn-cad-cluster-control.laconic.com +k8s_taint_servers: false k8s_acme_email: "{{ support_email }}" @@ -50,6 +50,6 @@ k8s_manifests: secret_key: access-token # initiate wildcard cert - - name: pwa.realitynetwork.store + - name: pwa.laconic.com type: file - source: wildcard-pwa-realitynetwork.yaml + source: wildcard-pwa-laconic.yaml diff --git a/group_vars/rnt_cad/k8s-vault.yml b/group_vars/rnt_cad/k8s-vault.yml deleted file mode 100644 index 2857e57..0000000 --- a/group_vars/rnt_cad/k8s-vault.yml +++ /dev/null @@ -1,26 +0,0 @@ -$ANSIBLE_VAULT;1.1;AES256 -61316662343265383362663936373531346563663065646434336239643031356336623230623766 -3135333666356363636536656439363239356232666435370a346232636365616566313331626362 -34303965633863623237333861666564373665623938623164396162323166343337653631333130 -3034333135333535320a646561333736353838356565323737616232373461646531636233363732 -34303463323132313430653733396636313930383364363462636463333139623265636362373438 -65626331386536376666366261633835313334653739643364643639643431353730386662363839 -37636639393530633834623631363765663730383031313138656431633835343263303462313261 -33616366333262643033636563326534653133643232616636353037616261643162386465613134 -39643730666435666165353331653765386539356333623830306239323366363563613639653232 -61373933306531666334306463326161386431326132623238633235623839646236663761386530 -38633963303839343238613164643464356562616334316332366461363963363339343762326535 -66336336393537343762653731306637613030643338616164383435336632313862336464613533 -32653265613262663633623039386337666333336364396435656331376339373938653634336162 -65376433653665373838663261656635623663326433616534653963396163316662613664343561 -39616532386330663337396332316332336537663466636339356463393239356430626266653133 -35623362373030623830303762343830353962353532373638643631636239653338306462343965 -61663031313465343632326664303963623037633639356563646265326233303261663533346632 -65333637613864623237643432613262383632336532316335643938313335306262316561366137 -37303965353065336234303134323631363932613162343337353433373964623565643039636162 -66376236393334613232343434376163613836373565313235323437356463313366646461363537 -32643135636364626533666265393664396538336331663735306433303439356462393532316437 -33613665633538663963633264346461663630623566393233656536323564623361323962303962 -62333736643664343762323433666531333633383563643834346234353736653337326438646530 -66373035336238363635623933663532323362396534653235633535316332393664336164303361 -65643435623334383435666434303465623465653531356465653535633363633036 diff --git a/host_vars/rnt-cad-cluster-control/firewalld.yml b/host_vars/lcn-cad-cluster-control/firewalld.yml similarity index 79% rename from host_vars/rnt-cad-cluster-control/firewalld.yml rename to host_vars/lcn-cad-cluster-control/firewalld.yml index 0ae25d2..ebb8d03 100644 --- a/host_vars/rnt-cad-cluster-control/firewalld.yml +++ b/host_vars/lcn-cad-cluster-control/firewalld.yml @@ -13,5 +13,4 @@ firewalld_add: sources: - 10.42.0.0/16 - 10.43.0.0/16 - - 142.93.110.163/32 - - 147.182.158.116/32 + - 159.203.31.82/32 diff --git a/host_vars/rnt-daemon/firewalld.yml b/host_vars/lcn-daemon/firewalld.yml similarity index 79% rename from host_vars/rnt-daemon/firewalld.yml rename to host_vars/lcn-daemon/firewalld.yml index 6095f21..df9eba6 100644 --- a/host_vars/rnt-daemon/firewalld.yml +++ b/host_vars/lcn-daemon/firewalld.yml @@ -13,5 +13,4 @@ firewalld_add: - name: trusted sources: - - 147.182.150.60/32 - - 147.182.158.116/32 + - 147.182.144.6/32 diff --git a/host_vars/rnt-daemon/nginx.yml b/host_vars/lcn-daemon/nginx.yml similarity index 61% rename from host_vars/rnt-daemon/nginx.yml rename to host_vars/lcn-daemon/nginx.yml index 42dd959..7dd3f13 100644 --- a/host_vars/rnt-daemon/nginx.yml +++ b/host_vars/lcn-daemon/nginx.yml @@ -6,16 +6,16 @@ nginx_proxy_send_timeout: 1200 nginx_proxy_connection_timeout: 75 nginx_sites: - - name: rnt-console - url: rnt-console.realitynetwork.store + - name: lcn-console + url: lcn-console.laconic.com upstream: http://localhost:8080 template: basic-proxy ssl: true - - name: rnt-daemon - url: rnt-daemon.realitynetwork.store + - name: lcn-daemon + url: lcn-daemon.laconic.com upstream: http://localhost:9473 configs: - - rewrite ^/deployer(/.*)? https://webapp-deployer.pwa.realitynetwork.store permanent + - rewrite ^/deployer(/.*)? https://webapp-deployer.pwa.laconic.com permanent template: websocket-proxy ssl: true diff --git a/host_vars/rnt-cad-cluster-worker/firewalld.yml b/host_vars/rnt-cad-cluster-worker/firewalld.yml deleted file mode 100644 index fc1d2d8..0000000 --- a/host_vars/rnt-cad-cluster-worker/firewalld.yml +++ /dev/null @@ -1,15 +0,0 @@ ---- -firewalld_add: - - name: public - interfaces: - - enp9s0 - services: - - http - - https - - - name: trusted - sources: - - 10.42.0.0/16 - - 10.43.0.0/16 - - 142.93.110.163/32 - - 147.182.150.60/32 diff --git a/hosts b/hosts index 0bba790..27b0da4 100644 --- a/hosts +++ b/hosts @@ -1,14 +1,12 @@ [all] -rnt-daemon ansible_host=142.93.110.163 -rnt-cad-cluster-control ansible_host=147.182.150.60 -rnt-cad-cluster-worker ansible_host=147.182.158.116 +lcn-daemon ansible_host=159.203.31.82 +lcn-cad-cluster-control ansible_host=147.182.144.6 [so] -rnt-daemon +lcn-daemon -[rnt_cad] -rnt-cad-cluster-control k8s_node_type=bootstrap -rnt-cad-cluster-worker k8s_node_type=agent k8s_pod_limit=1024 k8s_external_ip=147.182.158.116 +[lcn_cad] +lcn-cad-cluster-control k8s_node_type=bootstrap k8s_pod_limit=1024 k8s_external_ip=147.182.144.6 [k8s:children] -rnt_cad +lcn_cad