runbook: publishing a bare hostname from mf01 (laser.makerfloss.eu pattern)
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
parent
df25542953
commit
ab1fd9712e
2 changed files with 47 additions and 0 deletions
31
.claude/settings.local.json
Normal file
31
.claude/settings.local.json
Normal file
|
|
@ -0,0 +1,31 @@
|
||||||
|
{
|
||||||
|
"permissions": {
|
||||||
|
"allow": [
|
||||||
|
"Bash(xargs ls -la)",
|
||||||
|
"Bash(git add *)",
|
||||||
|
"Bash(git commit -q -m ' *)",
|
||||||
|
"Bash(xargs grep -lE \"^marp:|^---$\")",
|
||||||
|
"Bash(git -C ~/Projects/MakerFLOSS_Troubleshooting push)",
|
||||||
|
"Bash(git -C ~/Projects/MakerFLOSS push)",
|
||||||
|
"Bash(git -C ~/Projects/MakerFLOSS_Troubleshooting rev-parse --show-toplevel)",
|
||||||
|
"Bash(cat \"$\\(git -C ~/Projects/MakerFLOSS_Troubleshooting rev-parse --show-toplevel\\)/.superpowers/sdd/progress.md\")",
|
||||||
|
"Bash(git -C ~/Projects/AnsibleBaobabV4 rev-parse --abbrev-ref HEAD)",
|
||||||
|
"Bash(git -C ~/Projects/AnsibleBaobabV4 status --porcelain)",
|
||||||
|
"Read(//home/sjat/.ansible/vault-keys/**)",
|
||||||
|
"Bash(timeout 8 ssh -p 7576 -o BatchMode=yes -o ConnectTimeout=6 sjat@makerfloss.eu 'echo VPS_OK; docker ps --format \"{{.Names}}\" | grep -c traefik')",
|
||||||
|
"Bash(command -v wg)",
|
||||||
|
"Bash(sudo apt-get install -y wireguard-tools)",
|
||||||
|
"Bash(.venv/bin/ansible-vault view *)",
|
||||||
|
"Bash(.venv/bin/ansible-vault encrypt *)",
|
||||||
|
"Bash(shred -u /dev/shm/secrets.plain.yml)",
|
||||||
|
"Bash(rm -f /dev/shm/secrets.plain.yml)",
|
||||||
|
"Bash(.venv/bin/ansible-playbook play_setup.yml -i inventories/prod/hosts.yml --limit makerfloss -t wireguard-server,firewall)",
|
||||||
|
"Bash(ssh *)",
|
||||||
|
"Bash(.venv/bin/ansible-playbook play_containers.yml -i inventories/prod/hosts.yml --limit makerfloss -t traefik)",
|
||||||
|
"Bash(timeout 12 openssl s_client -connect 88.99.32.236:443 -servername whoami.tappaas.makerfloss.eu)",
|
||||||
|
"Bash(openssl x509 *)",
|
||||||
|
"Bash(grep -qxF '.superpowers/' .git/info/exclude)",
|
||||||
|
"Bash(echo '.superpowers/')"
|
||||||
|
]
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
@ -53,6 +53,22 @@ To use a hostname other than the container's default name, set that service's
|
||||||
`hostnames` via its own `container_traefik_overrides` (do **not** put hostnames
|
`hostnames` via its own `container_traefik_overrides` (do **not** put hostnames
|
||||||
in the host-wide dict — that would force every service to the same name).
|
in the host-wide dict — that would force every service to the same name).
|
||||||
|
|
||||||
|
## Publishing under a bare hostname (not `*.mf01`)
|
||||||
|
|
||||||
|
Done for `laser.makerfloss.eu` on 2026-08-16 (`baobab.laser-course` on mf01).
|
||||||
|
The wildcard cert/route only covers `*.mf01.makerfloss.eu`, so a bare name
|
||||||
|
needs **one** VPS-side addition: a `Host()` file router in
|
||||||
|
`traefik_extra_dynamic_files` (`host_vars/makerfloss.yml`, see
|
||||||
|
`laser-delegate.yml`) pointing at `http://10.13.0.8:80` with
|
||||||
|
`tls.certResolver: letsencrypt` — a `Host()` router triggers DNS-01 issuance for
|
||||||
|
exactly that name (took ~2 min). Plus the `A` record for the name → VPS. On
|
||||||
|
mf01, set the service's own `<svc>_traefik_overrides.hostnames`; if that role
|
||||||
|
sets `container_traefik_overrides` at role-vars level (laser-course does,
|
||||||
|
gcodeoverlay doesn't), repeat `entrypoints: [web]`, `tls: false`,
|
||||||
|
`certresolver: ""` there because it outranks the host-wide dict. Auth
|
||||||
|
middlewares from container labels are enforced by mf01's Traefik and work
|
||||||
|
unchanged. Deploy mf01 first, then `--limit makerfloss -t traefik`.
|
||||||
|
|
||||||
## Reach / management
|
## Reach / management
|
||||||
|
|
||||||
- Ansible reaches mf01 at its stable wg IP `10.13.0.8` via ProxyJump through the
|
- Ansible reaches mf01 at its stable wg IP `10.13.0.8` via ProxyJump through the
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue