diff --git a/.claude/settings.local.json b/.claude/settings.local.json new file mode 100644 index 0000000..0361bbb --- /dev/null +++ b/.claude/settings.local.json @@ -0,0 +1,31 @@ +{ + "permissions": { + "allow": [ + "Bash(xargs ls -la)", + "Bash(git add *)", + "Bash(git commit -q -m ' *)", + "Bash(xargs grep -lE \"^marp:|^---$\")", + "Bash(git -C ~/Projects/MakerFLOSS_Troubleshooting push)", + "Bash(git -C ~/Projects/MakerFLOSS push)", + "Bash(git -C ~/Projects/MakerFLOSS_Troubleshooting rev-parse --show-toplevel)", + "Bash(cat \"$\\(git -C ~/Projects/MakerFLOSS_Troubleshooting rev-parse --show-toplevel\\)/.superpowers/sdd/progress.md\")", + "Bash(git -C ~/Projects/AnsibleBaobabV4 rev-parse --abbrev-ref HEAD)", + "Bash(git -C ~/Projects/AnsibleBaobabV4 status --porcelain)", + "Read(//home/sjat/.ansible/vault-keys/**)", + "Bash(timeout 8 ssh -p 7576 -o BatchMode=yes -o ConnectTimeout=6 sjat@makerfloss.eu 'echo VPS_OK; docker ps --format \"{{.Names}}\" | grep -c traefik')", + "Bash(command -v wg)", + "Bash(sudo apt-get install -y wireguard-tools)", + "Bash(.venv/bin/ansible-vault view *)", + "Bash(.venv/bin/ansible-vault encrypt *)", + "Bash(shred -u /dev/shm/secrets.plain.yml)", + "Bash(rm -f /dev/shm/secrets.plain.yml)", + "Bash(.venv/bin/ansible-playbook play_setup.yml -i inventories/prod/hosts.yml --limit makerfloss -t wireguard-server,firewall)", + "Bash(ssh *)", + "Bash(.venv/bin/ansible-playbook play_containers.yml -i inventories/prod/hosts.yml --limit makerfloss -t traefik)", + "Bash(timeout 12 openssl s_client -connect 88.99.32.236:443 -servername whoami.tappaas.makerfloss.eu)", + "Bash(openssl x509 *)", + "Bash(grep -qxF '.superpowers/' .git/info/exclude)", + "Bash(echo '.superpowers/')" + ] + } +} diff --git a/runbooks/publishing-services-mf01.md b/runbooks/publishing-services-mf01.md index fc1ba20..d5136c4 100644 --- a/runbooks/publishing-services-mf01.md +++ b/runbooks/publishing-services-mf01.md @@ -53,6 +53,22 @@ To use a hostname other than the container's default name, set that service's `hostnames` via its own `container_traefik_overrides` (do **not** put hostnames in the host-wide dict — that would force every service to the same name). +## Publishing under a bare hostname (not `*.mf01`) + +Done for `laser.makerfloss.eu` on 2026-08-16 (`baobab.laser-course` on mf01). +The wildcard cert/route only covers `*.mf01.makerfloss.eu`, so a bare name +needs **one** VPS-side addition: a `Host()` file router in +`traefik_extra_dynamic_files` (`host_vars/makerfloss.yml`, see +`laser-delegate.yml`) pointing at `http://10.13.0.8:80` with +`tls.certResolver: letsencrypt` — a `Host()` router triggers DNS-01 issuance for +exactly that name (took ~2 min). Plus the `A` record for the name → VPS. On +mf01, set the service's own `_traefik_overrides.hostnames`; if that role +sets `container_traefik_overrides` at role-vars level (laser-course does, +gcodeoverlay doesn't), repeat `entrypoints: [web]`, `tls: false`, +`certresolver: ""` there because it outranks the host-wide dict. Auth +middlewares from container labels are enforced by mf01's Traefik and work +unchanged. Deploy mf01 first, then `--limit makerfloss -t traefik`. + ## Reach / management - Ansible reaches mf01 at its stable wg IP `10.13.0.8` via ProxyJump through the