diff --git a/.vault/vault-keys b/.vault/vault-keys index ae38c9d..35cf68a 100644 --- a/.vault/vault-keys +++ b/.vault/vault-keys @@ -1 +1 @@ -88CBCAD842520E46 +3942AFDDEEC4A263 diff --git a/.vault/vault-pass.gpg b/.vault/vault-pass.gpg index e743d3e..f567565 100644 Binary files a/.vault/vault-pass.gpg and b/.vault/vault-pass.gpg differ diff --git a/files/manifests/secret-digitalocean-dns.yaml b/files/manifests/secret-digitalocean-dns.yaml index 784f633..7216162 100644 --- a/files/manifests/secret-digitalocean-dns.yaml +++ b/files/manifests/secret-digitalocean-dns.yaml @@ -1,19 +1,19 @@ $ANSIBLE_VAULT;1.1;AES256 -37303132393466333261633739343530323037363563346263393337306262386434616236623830 -6439616662356337653935346434323638326432363531660a333235636264313765646330363263 -31616232373735373834393965353930316161393265366431653639646438376534656462326337 -3036653763363530330a333461643731636535643532323139393238353431313034323066363635 -31336534383163303233383936383533663437663637323335326335356135653063303133643764 -35613638663736636166353734303333666332633434313766346332373565633166356561643030 -64626163636562323964346137313238633036396232393766393137663134396663613933646539 -63666435333763323862636536313436383133343031363232333433656264386139653030383465 -63333137356463303865393939303463333031383563393837623261333734353261326333316461 -66343135656631396230303665373033663431356464636163613333643362383162613861393435 -32626562653337313638623764646463663034363065306633346365303366643166633436643936 -32653865363631623839313533333831386339633837353233313730643939336265343764643131 -34363734616237373237303039643261376664376636386164643433366436353162656232336330 -39336436353235396633313265353939373262303637373830623439303132386666646130626330 -62653462343838303266343830366565666639353362343662653234396365353339343330623039 -37653335323564323762653338666634363237303830653736623963306564643831353233663630 -32386131373263613139326534633432666364656561663461643031663230643366363036336631 -3039393835346431346231636665396138393336343963333466 +63633338396236313234306464383335353566353937633863343265653731336333646465643631 +3236643738343764336239623661643633646634626563640a643734346564343863323133306465 +39653535343331353762376533306137323861306631333337363435353161356664306265306566 +3037363762623261630a303665383163323639386463323832343738656138336466356331623031 +30373433646538626164646235663336623063346135363634376462663734396366626533663963 +61353165363531303932333630373530353366353264373663663339336135353434663736326434 +31383766336166353331313139333563316665323831373338666338343835613131643666613766 +32376461306338323034633634613236303462373962376430343864626130353837336566616532 +31633963373261373530326334373363613166373837353234366430653831633032396132333365 +34356237333663356230373136623637346639646436336562393862383561376361326235373937 +37333762643530396436636132336435613334386165356162303164646361323662383762633138 +37626630393934663134663565316136646431653035663861373561653536626636653333303239 +36333438373264653163646235346365363538393732383131353731336330336539393364623038 +35333263383464626264393832313135356562656631666362323533366336313334343735376661 +63666362343566386139356537303330666634366638376537373763363563313962656666303132 +36653361343631633235373833303633623534633563346134613937396266393233623665373535 +64313061663363383536613665636332343130663735626238363462353830646437623531323632 +6235656635626437316361623438386233303366326662313731 diff --git a/files/manifests/wildcard-pwa-laconic.yaml b/files/manifests/wildcard-pwa-laconic.yaml index 01a6f83..a3f4e29 100644 --- a/files/manifests/wildcard-pwa-laconic.yaml +++ b/files/manifests/wildcard-pwa-laconic.yaml @@ -1,15 +1,15 @@ apiVersion: cert-manager.io/v1 kind: Certificate metadata: - name: pwa.laconic.com + name: pwa.realitynetwork.store namespace: default spec: - secretName: pwa.laconic.com + secretName: pwa.realitynetwork.store issuerRef: name: letsencrypt-prod-wild kind: ClusterIssuer group: cert-manager.io - commonName: "*.pwa.laconic.com" + commonName: "*.pwa.realitynetwork.store" dnsNames: - - "pwa.laconic.com" - - "*.pwa.laconic.com" + - "pwa.realitynetwork.store" + - "*.pwa.realitynetwork.store" diff --git a/group_vars/all/vault.yml b/group_vars/all/vault.yml index eb08362..65d12bf 100644 --- a/group_vars/all/vault.yml +++ b/group_vars/all/vault.yml @@ -1,7 +1,7 @@ $ANSIBLE_VAULT;1.1;AES256 -37613532616632663366373332616133316237633564386464643032636137356436623331313365 -3164613836383930663466306133336263393764306662620a616131366561306334656535663432 -31323566373730353338356365663764386266383831666637646361626433343162313039343964 -3837666333343133630a343534366535613765336134623532323038633466666538356235323464 -65326264393765383138393661616537323864333036353130633461383865643030366363623437 -6162376537646461343066316234663730663466303931646630 +66346338653832313132613830623362636535646538363836646437613432636464313036353463 +6566333839313861656164363636316564616235313336330a383066396535616138633965313439 +62323436333565306239643734343038366431373361303431373462336133313530376537383562 +3566636265616663650a656337656133303764323634326262376565613730313139363262633334 +36376361633564386262343030613330366364326334633837323264623864323136336331343838 +6234626131323230616135313130343530366365343332396234 diff --git a/group_vars/lcn_cad/k8s-vault.yml b/group_vars/lcn_cad/k8s-vault.yml index de9db9b..65b4954 100644 --- a/group_vars/lcn_cad/k8s-vault.yml +++ b/group_vars/lcn_cad/k8s-vault.yml @@ -1,8 +1,8 @@ $ANSIBLE_VAULT;1.1;AES256 -32623937306230646432336339336134316263616136383264623030623930633664346263643165 -3539396565353163656432303038613736343430643765330a353465613136396436613565396638 -63396333363766353737363438383262623539376666316531303535663832303363356631633735 -6666643461626262350a393136306662666232356532366666323765356330333838363162356330 -61333233666634373666636630623865333838653762393634306464336636633633646266623263 -33373831613266373839383666326264376362646638386566656362656130383861633933666564 -383930616533303265633661363335633064 +65333631323235633862386330323936633539353965343065393839346330623066303464356532 +6135333365346533313131653634363636326438303239310a613861356564343431306438646537 +36376165343837636261626436373032616639356666623538356130353936656262636432366262 +3131656631643361620a353832373664303931333534336163373162316566346661633966323931 +63393066323831393637666433323836323331653563353635326439623733356638313762323363 +33656231396535373437653865313837393331353565363933623366326133626664646335343764 +656236313362386235363532313235353334 diff --git a/group_vars/lcn_cad/k8s.yml b/group_vars/lcn_cad/k8s.yml index c94be83..46feeb0 100644 --- a/group_vars/lcn_cad/k8s.yml +++ b/group_vars/lcn_cad/k8s.yml @@ -2,7 +2,7 @@ # default context is used for stack orchestrator deployments, for testing a custom context name can be usefull #k8s_cluster_name: lcn-cad-cluster k8s_cluster_name: default -k8s_cluster_url: lcn-cad-cluster-control.laconic.com +k8s_cluster_url: lcn-control.realitynetwork.store k8s_taint_servers: false k8s_acme_email: "{{ support_email }}" @@ -50,6 +50,6 @@ k8s_manifests: secret_key: access-token # initiate wildcard cert - - name: pwa.laconic.com + - name: pwa.realitynetwork.store type: file source: wildcard-pwa-laconic.yaml diff --git a/host_vars/lcn-cad-cluster-control/firewalld.yml b/host_vars/lcn-control/firewalld.yml similarity index 89% rename from host_vars/lcn-cad-cluster-control/firewalld.yml rename to host_vars/lcn-control/firewalld.yml index ebb8d03..055f3c8 100644 --- a/host_vars/lcn-cad-cluster-control/firewalld.yml +++ b/host_vars/lcn-control/firewalld.yml @@ -13,4 +13,4 @@ firewalld_add: sources: - 10.42.0.0/16 - 10.43.0.0/16 - - 159.203.31.82/32 + - 159.203.31.21/32 diff --git a/host_vars/lcn-daemon/firewalld.yml b/host_vars/lcn-daemon/firewalld.yml deleted file mode 100644 index df9eba6..0000000 --- a/host_vars/lcn-daemon/firewalld.yml +++ /dev/null @@ -1,16 +0,0 @@ ---- -firewalld_add: - - name: public - interfaces: - - ens3 - services: - - http - - https - ports: - - 26657/tcp - - 26656/tcp - - 1317/tcp - - - name: trusted - sources: - - 147.182.144.6/32 diff --git a/host_vars/lcn-daemon/nginx.yml b/host_vars/lcn-daemon/nginx.yml deleted file mode 100644 index 7dd3f13..0000000 --- a/host_vars/lcn-daemon/nginx.yml +++ /dev/null @@ -1,21 +0,0 @@ ---- -nginx_packages_intall: false -nginx_server_name_hash: 64 -nginx_proxy_read_timeout: 1200 -nginx_proxy_send_timeout: 1200 -nginx_proxy_connection_timeout: 75 - -nginx_sites: - - name: lcn-console - url: lcn-console.laconic.com - upstream: http://localhost:8080 - template: basic-proxy - ssl: true - - - name: lcn-daemon - url: lcn-daemon.laconic.com - upstream: http://localhost:9473 - configs: - - rewrite ^/deployer(/.*)? https://webapp-deployer.pwa.laconic.com permanent - template: websocket-proxy - ssl: true diff --git a/hosts b/hosts index 27b0da4..fe4a878 100644 --- a/hosts +++ b/hosts @@ -1,12 +1,8 @@ [all] -lcn-daemon ansible_host=159.203.31.82 -lcn-cad-cluster-control ansible_host=147.182.144.6 - -[so] -lcn-daemon +lcn-control ansible_host=134.122.32.58 [lcn_cad] -lcn-cad-cluster-control k8s_node_type=bootstrap k8s_pod_limit=1024 k8s_external_ip=147.182.144.6 +lcn-control k8s_node_type=bootstrap k8s_pod_limit=1024 k8s_external_ip=134.122.32.58 [k8s:children] lcn_cad diff --git a/site.yml b/site.yml index f30d9a4..07e279d 100644 --- a/site.yml +++ b/site.yml @@ -6,15 +6,6 @@ - role: firewalld - role: nginx -- name: Setup stack orchestrator - hosts: so - become: true - roles: - - role: so - tags: - - never - - so - - name: Setup k8s clusters hosts: k8s become: true