From 08e92ca3b8ee6c38c3e19126378e51b46cf63b16 Mon Sep 17 00:00:00 2001 From: Elizabeth Hunt Date: Mon, 11 Aug 2025 18:39:55 -0700 Subject: Oauth proxy and monitoring init --- group_vars/all.yml | 70 +++++++++++++++++++++++++++++++++++++++++++++--------- 1 file changed, 59 insertions(+), 11 deletions(-) (limited to 'group_vars/all.yml') diff --git a/group_vars/all.yml b/group_vars/all.yml index a285422..d1c7a24 100644 --- a/group_vars/all.yml +++ b/group_vars/all.yml @@ -11,7 +11,7 @@ ansible_user: serve # -- -- loadbalancer_ip: "10.128.0.200" homelab_network: "10.128.0.0/16" -swarm_network: "10.0.0.0/16" +swarm_network: "10.0.0.0/8" docker_network: "172.16.0.0/12" headnet_network: "100.64.0.0/10" rfc1918_cgnat_networks: @@ -29,6 +29,8 @@ headscale_nodes_domain: "in.{{ domain }}" mail_domain: "mail.{{ domain }}" oci_domain: "oci.{{ domain }}" passwd_domain: "passwd.{{ domain }}" +oauth_proxy_domain: "fwdauth.{{ domain }}" +outbound_domain: "outbound.{{ domain }}" # -- -- # -- -- @@ -56,6 +58,10 @@ homelab_build: false deployment_time: "{{ now(utc=true,fmt='%s') }}" # -- -- +# -- -- +admins: "coffee_admins@{{ idm_domain }}" +# -- -- + # -- -- me_lizcoffee_key: "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQDRHu3h9mDjQyFbojcxGKW0hPUDfgUmb2WCzd4Dv2qISM3GGt9LjD8o0IbWRNaTf5UyId5lu7wNHtygs5ZDfUVnlfxrI1CmoExuqkYFjy+R9Cu0x1J2w7+MrKPBd5akLCuKTTnXbyv79T0tLb07rCpGHojW8HH6wdDtg0siVqsPqZVTjg7WGbBYqiqlA5p8s+V9xN1q8lTOZrRI0PdgoU8W+1oIr9OHSG1ZeUBQx60izTEwMnWBxY2aA8SQolIVvsJCcMMc/EAnaz/rdJ5IkeqXGslIhUI7WCPHnPWN8CSdwMOLi5BNaOAK7Y2FkfKTUlO7I52BL87Cl3YpMxR0mTDrfSJTSp0B3ZAbUIXDA7biSh04YLwGQVI799vcyJf355A60btPaiuiBgI0am3h0WxnOACg7K6eV023EiUQ24UjlQ8pufHcJ1oDW8v6LHlp/atCWOl9KQIun9UUg8DD8/BLPprc0wzAV6Nco0ZIedouxZuUhduYYvUrLJ+ICpaZg6oPGitVJPIgyyI+WTfjRN4WTj/Z3Yhuj0RqF8b5ea4FNWuJtfF724t7SVnZsYlZGSCqL8gaEzbIATVe3THn5VwbK+S4ELD/9W6MOd6aZcTOK2yP3jlwjcjnW8sLuX+2qNwtSVVa4o5VsRZU40Da+3flzoBsyUwSE3H2PsFPH29lIQ== lizzy@yubikey" # -- -- @@ -68,11 +74,24 @@ mesh: forward_dns: true split_vpn_dns_to: "10.128.0.44" private_records: [] + public_healthchecks: [] + private_healthchecks: [] liz: gateway: "{{ loadbalancer_ip }}" domain: "{{ domain }}" forward_dns: false split_vpn_dns_to: "{{ loadbalancer_ip }}" + public_healthchecks: + - "https://{{ domain }}" + - "https://{{ idm_domain }}/status" + - "https://{{ headscale_host }}/health" + - "https://fwdauth.{{ domain }}/oauth2/sign_in" + - "https://test.{{ domain }}/" + private_healthchecks: + - "https://bin.{{ domain }}" + - "https://ci.{{ domain }}" + - "https://notes.{{ domain }}" + - "https://passwd.{{ domain }}/alive" private_records: - type: "A" name: "piplup.{{ domain }}" @@ -96,9 +115,6 @@ mesh: - type: "A" name: "bin.{{ domain }}" ip: "{{ loadbalancer_ip }}" - - type: "A" - name: "ci.{{ domain }}" - ip: "{{ loadbalancer_ip }}" - type: "A" name: "idm.{{ domain }}" ip: "{{ loadbalancer_ip }}" @@ -123,6 +139,9 @@ mesh: - type: "A" name: "src.{{ domain }}" ip: "{{ loadbalancer_ip }}" + - type: "A" + name: "fwdauth.{{ domain }}" + ip: "{{ loadbalancer_ip }}" - type: "A" name: "swarm.{{ domain }}" ip: "{{ loadbalancer_ip }}" @@ -130,13 +149,42 @@ mesh: name: "traefik.{{ domain }}" ip: "{{ loadbalancer_ip }}" - type: "A" - name: "piplup.pocket.{{ domain }}" - ip: "10.128.0.101" - - type: "A" - name: "togepi.pocket.{{ domain }}" - ip: "10.128.0.102" + name: "prometheus.{{ domain }}" + ip: "{{ loadbalancer_ip }}" - type: "A" - name: "roton.pocket.{{ domain }}" - ip: "10.128.0.103" + name: "mon.{{ domain }}" + ip: "{{ loadbalancer_ip }}" # -- -- +# -- -- + +logo: | + --| |-- + --| ~ welcome to ~ |-- + --| |-- + --| .-. _ .--. .--. |-- + --| :.: :_; : .-': .-' |-- + --| :.: .-..---. .--. .--. : `; : `;.--. .--. |-- + --| :.:_ : :`-'_.' _ ' ..'' .; :: : : :' '_.'' '_.' |-- + --| `.__;:_;`.___;:_;`.__.'`.__.':_; :_;`.__.'`.__.' |-- + --| |-- + --| ~₊˚⊹ ⋆˚✿˖°~ -────୨ৎ────- ~₊˚⊹ ⋆˚✿˖°~ |-- + --| ⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⣀⣀⣀⣀⣀⣀⣀⡀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀ |-- + --| ⠀⠀⠀⠀⠀⠀⠀⠀⠀⣀⠤⠒⠉⠉⠉⣀⣂⣅⠬⡉⠭⢛⠿⢟⡶⣄⡀⠀⠀⠀⠀ we'll get brewing |-- + --| ⠀⠀⠀⠀⠀⠀⠀⣠⠞⠁⠀⣄⢎⢩⢸⢉⣵⡖⢰⣶⣮⢹⣦⣡⢊⢻⡿⣦⠀⠀⠀ right away! |-- + --| ⠀⠀⠀⠀⠀⠀⢠⡇⠀⠀⢎⠕⢭⢪⡶⠈⢿⣷⣿⠟⣋⣚⣯⣒⣣⡑⢨⢻⡇⠀⣀⣀⠀⠀⠀ |-- + --| ⠀⠀⠀⠀⠀⣀⡼⣧⠀⠄⡊⢼⡩⣾⢌⠳⡜⣉⡠⡜⡞⣵⣊⡧⡠⠝⣣⡾⠁⠀⠻⠿⠗⠀⠀ /) /) (\ (\ |-- + --| ⠀⠀⠀⣢⣾⡟⣥⠻⣷⣌⡀⠬⡘⢅⡟⡇⡮⣷⡾⡿⢋⣉⢣⢔⣎⠿⠊⠀⠀⡴⣛⠆⠌⠀⠀ ( . .) (. . ) |-- + --| ⠀⢀⣶⡟⣡⣿⣿⣟⢯⣟⢿⣷⣶⣯⣬⣵⣾⣷⣶⡾⠧⠞⠓⠉⠀⠀⠀⢀⠘⠈⠀⠠⢘⡤⠀ ( づ ˚♡︎˖ ⊂ ) |-- + --| ⠄⣾⠏⣐⣛⡻⢿⣿⣯⣿⣿⣿⣾⣽⣛⣍⢃⡂⢄⠀⡀⠀⡀⠄⢂⠄⠡⢈⠒⡈⢒⠘⠴⢀⠀ |-- + --| ⢰⣿⠀⠈⠻⣜⣄⠈⢙⣾⢿⣿⣿⣿⡿⣜⢣⡜⢢⠁⠄⡐⢠⢉⠂⠌⠀⡀⠄⠐⡀⠄⠐⠀⢐ ___ |-- + --| ⠸⣟⠀⡐⡅⠈⠑⠀⠊⠝⠈⢖⡿⠿⣿⣾⡱⢊⠅⡌⡰⢌⢆⠣⠈⢀⠐⠀⠄⠂⠠⡈⠠⣈⡧ (...) |-- + --| ⠀⢿⣆⠱⣘⣧⣤⣀⣀⡀⢒⡥⣑⢨⠒⡰⠯⠾⡼⠶⠙⢈⠀⣀⠂⡄⢂⣁⢢⣑⣶⡽⣳⠟⠁ _ \ _ |-- + --| ⠀⠀⠻⣧⡜⢹⣿⣿⣿⣿⣿⣿⣿⣿⣷⣦⣴⡀⡀⠀⠛⠺⢿⣶⣿⣾⣷⣿⣿⣿⢟⣵⠏⠀⠀ ('> <') |-- + --| ⠀⠀⠀⠈⠿⣶⣉⠻⢿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣷⣧⣤⢀⠀⠀⠈⠉⠙⠻⣯⡷⠟⠁⠀⠀⠀ (v) (v) |-- + --| ⠀⠀⠀⠀⠀⠈⠙⠿⣶⣽⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣾⣞⣤⠀⠀⠀⠈⠀⠀⠀⠀⠀⠀\(__w w__)/ |-- + --| ⠀⠀⠀⠀⠀⠀⠀⠀⠀⠈⠉⠛⠛⠛⠿⠿⠿⠿⠿⠿⠛⠛⠛⠉⠉⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀ |-- + --| |-- + --| |-- + +# -- -- -- cgit v1.2.3-70-g09d2