--- # Managed-switch group — non-secret facts + connection model. # # The switch is NOT a Linux host: we don't sudo, and we don't use the global # ansible_user/key. The hardening role connects FROM the control node TO the # switch over SSH via an expect engine (delegated, connection: local). # # Secret (vault_sg2428lp_admin_password) lives in this group's vault.yml, # populated from 1Password by etc/set-switch-1password.sh. ansible_connection: local ansible_become: false # Management endpoint + credentials (password resolved from vault). switch_mgmt_ip: "{{ ansible_host }}" switch_admin_user: "admin" switch_admin_password: "{{ vault_sg2428lp_admin_password }}" # 1Password source-of-truth reference (used by the op -> vault bridge script). switch_op_account: "VM7LPYA4XFF4TE2DEI7ZHMZWEA" switch_op_reference: "op://knoey/TP-Link SG2428LP/password" # ── Desired identity + management addressing ───────────────────────────────── # Static management IP, OFF DHCP. 10.0.0.10 sits below the DHCP pool # (10.0.0.20–10.0.0.199), so it never collides with a lease. switch_hostname: "sg2428lp" switch_fqdn: "{{ switch_hostname }}.{{ prole_domain }}" # sg2428lp.prole.org switch_mgmt_ip_static: "10.0.0.10" switch_mgmt_netmask: "255.255.255.0" switch_mgmt_gateway: "10.0.0.1" switch_mgmt_vlan: 1 # One-time migration source: the DHCP address the switch currently answers on. # After cutover, set this host's ansible_host to switch_mgmt_ip_static (.10). switch_dhcp_ip: "10.0.0.153"