prole/infrastructure/inventory/host_vars/merlin.prole.org.yml
chrisfu 436c6214df checkpoint: k3s agent config + node labels + registry optimizations
- k3s: render server-only config keys only for servers; add regression test; make guardrail test non-sudo

- k3s/site: add post-provision node labeling tasks + playbook tier; extend inventory node label mapping

- registry: default namespace to common-services and skip redundant image pushes by probing registry manifests (installer + init scripts)
2026-03-07 03:14:26 -08:00

49 lines
1.4 KiB
YAML

---
ansible_host: 10.0.0.6
netplan_static_enabled: true
netplan_static_iface: eth0
netplan_static_address: 10.0.0.6/24
netplan_static_gateway4: 10.0.0.1
netplan_static_nameservers:
- 10.0.0.1
# MariaDB primary (USB-backed)
# k3s worker (stateless workloads)
k3s_enabled: true
k3s_role: agent
k3s_cluster_init: false
k3s_server_url: "https://myrddin.prole.org:6443"
# k3s datastore now lives on merlin.
# NOTE: Use IP to avoid DNS drift during migration/cutover.
k3s_datastore_mariadb_host: 10.0.0.6
k3s_datastore_mariadb_port: 3306
k3s_datastore_mariadb_db: k3s
k3s_datastore_mariadb_user: prole_k3s
k3s_datastore_endpoint: "mysql://{{ k3s_datastore_mariadb_user }}:{{ k3s_datastore_mariadb_password | urlencode }}@tcp({{ k3s_datastore_mariadb_host }}:{{ k3s_datastore_mariadb_port }})/{{ k3s_datastore_mariadb_db }}"
k3s_tls_sans:
- merlin.prole.org
k3s_service_node_labels: []
# No iSCSI mounts on merlin
iscsi_portal: 10.0.0.203
iscsi_targets:
# PROLE-K3S-1 (moved from retropie)
- iqn: "iqn.2000-01.com.synology:synology.Target-16.292d45194a1"
chap_user: "prole"
chap_password: "{{ vault_iscsi_prole_password }}"
mounts:
- path: /var/lib/rancher
fstype: ext4
opts: "_netdev,noatime"
# Use PARTUUID (stable across mkfs) because we intentionally re-initialize the filesystem.
src: "PARTUUID=29f70e08-5bf1-4803-b94c-ed82fa37f082"
iscsi_absent_mounts: []