prole/infrastructure/inventory/host_vars/merlin.prole.org.yml
chrisfu 2244d6acd6 Refactor iSCSI Synology mounts to /synology/d00x
- Rename host mount namespace from /prole/d00x to /synology/d00x

- Make LUN ownership explicit per host in inventory (myrddin=d001; merlin=d002,d004; pi=d003)

- Add safe migration cleanup for legacy /prole/d00x mounts and stale /etc/fstab entries

- Update k3s/ArgoCD/OpenTofu manifests and PV node affinities to match new mount paths

- Improve iSCSI role check-mode behavior and add quiesce/detach flow in ansible.sh
2026-03-21 10:43:06 -07:00

85 lines
2.7 KiB
YAML

---
ansible_host: 10.0.0.6
netplan_static_enabled: true
netplan_static_iface: eth0
netplan_static_address: 10.0.0.6/24
netplan_static_gateway4: 10.0.0.1
netplan_static_nameservers:
- 10.0.0.1
# MariaDB primary (USB-backed)
# Temporary borrowed USB disk for MariaDB (merlin only)
# - Disk: /dev/sda1 (exFAT)
# - Mount: /external (by UUID, discovered at runtime)
# - MariaDB datadir is expected at /srv/mariadb/mariadb, but is bind-mounted to /external/mariadb
mariadb_external_enabled: true
mariadb_external_device: /dev/sda1
mariadb_external_mountpoint: /external
mariadb_external_fstype: exfat
# exFAT does not support POSIX ownership/permissions.
# Use a root-owned mount with group access for `mysql`, instead of forcing everything to `mysql:mysql`.
mariadb_external_mount_opts: "defaults,nofail,x-systemd.device-timeout=10,uid=0,gid=mysql,umask=0002"
mariadb_external_src_datadir: /srv/mariadb/mariadb
mariadb_external_dst_datadir: /external/mariadb
mariadb_external_backup_datadir: /srv/mariadb/mariadb.pre-external
mariadb_external_migration_marker: /external/mariadb/.prole-mariadb-external-migrated
# k3s worker (stateless workloads)
k3s_enabled: true
k3s_role: agent
k3s_cluster_init: false
k3s_server_url: "https://myrddin.prole.org:6443"
# k3s datastore now lives on merlin.
# NOTE: Use IP to avoid DNS drift during migration/cutover.
k3s_datastore_mariadb_host: 10.0.0.6
k3s_datastore_mariadb_port: 3306
k3s_datastore_mariadb_db: k3s
k3s_datastore_mariadb_user: prole_k3s
k3s_datastore_endpoint: "mysql://{{ k3s_datastore_mariadb_user }}:{{ k3s_datastore_mariadb_password | urlencode }}@tcp({{ k3s_datastore_mariadb_host }}:{{ k3s_datastore_mariadb_port }})/{{ k3s_datastore_mariadb_db }}"
k3s_tls_sans:
- merlin.prole.org
k3s_service_node_labels:
- "prole.org/node-role=general"
k3s_node_taints: []
k3s_required_mounts:
- /synology/d002
- /synology/d004
# iSCSI
# `/var/lib/rancher` is local host storage (do not manage it via iSCSI).
iscsi_portal: 10.0.0.203:3260
iscsi_targets:
# PROLE-DATA-2
- iqn: "iqn.2000-01.com.synology:synology.Target-12.292d45194a1"
chap_user: "prole"
chap_password: "{{ vault_iscsi_prole_password }}"
mounts:
- name: d002
path: /synology/d002
fstype: xfs
opts: "_netdev,noatime"
src: "UUID=fe087fb0-a321-4767-b838-b4385e81693e"
# PROLE-DATA-4
# Repurposed from myrddin's former `/var/lib/rancher` Synology LUN.
- iqn: "iqn.2000-01.com.synology:synology.Target-15.292d45194a1"
chap_user: "prole"
chap_password: "{{ vault_iscsi_prole_password }}"
mounts:
- name: d004
path: /synology/d004
fstype: xfs
opts: "_netdev,noatime"
mkfs_if_missing: true
iscsi_absent_mounts: []