runbook: publishing a bare hostname from mf01 (laser.makerfloss.eu pattern)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
sjat 2026-08-16 06:26:32 +02:00
parent df25542953
commit ab1fd9712e
2 changed files with 47 additions and 0 deletions

View file

@ -0,0 +1,31 @@
{
"permissions": {
"allow": [
"Bash(xargs ls -la)",
"Bash(git add *)",
"Bash(git commit -q -m ' *)",
"Bash(xargs grep -lE \"^marp:|^---$\")",
"Bash(git -C ~/Projects/MakerFLOSS_Troubleshooting push)",
"Bash(git -C ~/Projects/MakerFLOSS push)",
"Bash(git -C ~/Projects/MakerFLOSS_Troubleshooting rev-parse --show-toplevel)",
"Bash(cat \"$\\(git -C ~/Projects/MakerFLOSS_Troubleshooting rev-parse --show-toplevel\\)/.superpowers/sdd/progress.md\")",
"Bash(git -C ~/Projects/AnsibleBaobabV4 rev-parse --abbrev-ref HEAD)",
"Bash(git -C ~/Projects/AnsibleBaobabV4 status --porcelain)",
"Read(//home/sjat/.ansible/vault-keys/**)",
"Bash(timeout 8 ssh -p 7576 -o BatchMode=yes -o ConnectTimeout=6 sjat@makerfloss.eu 'echo VPS_OK; docker ps --format \"{{.Names}}\" | grep -c traefik')",
"Bash(command -v wg)",
"Bash(sudo apt-get install -y wireguard-tools)",
"Bash(.venv/bin/ansible-vault view *)",
"Bash(.venv/bin/ansible-vault encrypt *)",
"Bash(shred -u /dev/shm/secrets.plain.yml)",
"Bash(rm -f /dev/shm/secrets.plain.yml)",
"Bash(.venv/bin/ansible-playbook play_setup.yml -i inventories/prod/hosts.yml --limit makerfloss -t wireguard-server,firewall)",
"Bash(ssh *)",
"Bash(.venv/bin/ansible-playbook play_containers.yml -i inventories/prod/hosts.yml --limit makerfloss -t traefik)",
"Bash(timeout 12 openssl s_client -connect 88.99.32.236:443 -servername whoami.tappaas.makerfloss.eu)",
"Bash(openssl x509 *)",
"Bash(grep -qxF '.superpowers/' .git/info/exclude)",
"Bash(echo '.superpowers/')"
]
}
}

View file

@ -53,6 +53,22 @@ To use a hostname other than the container's default name, set that service's
`hostnames` via its own `container_traefik_overrides` (do **not** put hostnames
in the host-wide dict — that would force every service to the same name).
## Publishing under a bare hostname (not `*.mf01`)
Done for `laser.makerfloss.eu` on 2026-08-16 (`baobab.laser-course` on mf01).
The wildcard cert/route only covers `*.mf01.makerfloss.eu`, so a bare name
needs **one** VPS-side addition: a `Host()` file router in
`traefik_extra_dynamic_files` (`host_vars/makerfloss.yml`, see
`laser-delegate.yml`) pointing at `http://10.13.0.8:80` with
`tls.certResolver: letsencrypt` — a `Host()` router triggers DNS-01 issuance for
exactly that name (took ~2 min). Plus the `A` record for the name → VPS. On
mf01, set the service's own `<svc>_traefik_overrides.hostnames`; if that role
sets `container_traefik_overrides` at role-vars level (laser-course does,
gcodeoverlay doesn't), repeat `entrypoints: [web]`, `tls: false`,
`certresolver: ""` there because it outranks the host-wide dict. Auth
middlewares from container labels are enforced by mf01's Traefik and work
unchanged. Deploy mf01 first, then `--limit makerfloss -t traefik`.
## Reach / management
- Ansible reaches mf01 at its stable wg IP `10.13.0.8` via ProxyJump through the