mirror of
https://github.com/dredx/prole.git
synced 2026-09-24 17:54:32 +00:00
- enforce app-cluster-only rendering for public ingress hosts with DB-cluster guardrails\n- fix Supabase/GitLab/authority ingress host ownership and ingress-class safety checks\n- normalize persisted home-directory paths to /Users/chrisfu and update gke config defaults\n- add/adjust regression tests for ingress placement/hostname and cfg path normalization Co-authored-by: Junie <junie@jetbrains.com>
285 lines
14 KiB
INI
285 lines
14 KiB
INI
; Prole Master Configuration File
|
|
; Generated by install.py on 2026-04-11 23:08:03
|
|
; This file is used as input for Ansible deployment and k8s cluster creation.
|
|
|
|
[User]
|
|
; User-editable values; derived values below reference these by default.
|
|
; No user values captured yet for this section.
|
|
|
|
[Inputs]
|
|
; Screen-scoped inputs used for unattended replays (-S)
|
|
argocd.node_selector = gandalf.prole.org
|
|
build.deploy_env = Dev
|
|
build.run_build = false
|
|
database_options.distribution = percona
|
|
database_options.ext.dblink = true
|
|
database_options.ext.pg_buffercache = true
|
|
database_options.ext.pg_cron = true
|
|
database_options.ext.pg_freespacemap = true
|
|
database_options.ext.pg_repack = true
|
|
database_options.ext.pg_stat_monitor = true
|
|
database_options.ext.pg_stat_statements = true
|
|
database_options.ext.pg_tde = true
|
|
database_options.ext.pgaudit = true
|
|
database_options.ext.pgbadger = true
|
|
database_options.ext.pgcrypto = true
|
|
database_options.ext.pgrowlocks = true
|
|
database_options.ext.pgvector = true
|
|
database_options.ext.postgis = true
|
|
database_options.ext.postgres_fdw = true
|
|
database_options.version_type = v18
|
|
dependencies.ansible.install = true
|
|
dependencies.auto_install_missing = true
|
|
dependencies.brew.install = true
|
|
dependencies.docker.install = true
|
|
dependencies.k3d.install = true
|
|
dependencies.kubectl.install = true
|
|
dependencies.kubectx.install = true
|
|
dependencies.opentofu.install = true
|
|
dependencies.python.install = true
|
|
dependencies.verify_all = false
|
|
disk_selection.disk_type = local
|
|
disk_selection.local_path = /Users/chrisfu/dev/prole/prole-tools-app/dist
|
|
disk_selection.removable_mount =
|
|
env_setup.APP_CLUSTER_KUBECONTEXT = knoe.dev.prole.org
|
|
env_setup.APP_CLUSTER_MODE = standard
|
|
env_setup.APP_CLUSTER_NAME = knoe-dev-0
|
|
env_setup.CLUSTER_NAME = ${CLUSTER_NAME}
|
|
env_setup.DATABASE_NAMESPACE = ${DATABASE_NAMESPACE}
|
|
env_setup.DB_CLUSTER_KUBECONTEXT = knoe.dev.prole.org
|
|
env_setup.DB_CLUSTER_MODE = standard
|
|
env_setup.DB_CLUSTER_NAME = knoe-cnpg-0
|
|
env_setup.PROLE_CONF = /Users/chrisfu/dev/prole/conf
|
|
env_setup.PROLE_DATA = /Users/chrisfu/dev/prole/data
|
|
env_setup.PROLE_HOME = /Users/chrisfu/dev/prole
|
|
env_setup.PROLE_LOGS = /Users/chrisfu/dev/prole/logs
|
|
env_setup.PROLE_SERVICE = /Users/chrisfu/dev/prole/etc
|
|
gitops.git_provider = GitLab
|
|
gitops.node_selector = gandalf.prole.org
|
|
init_cluster.app_cluster_kubecontext = knoe.dev.prole.org
|
|
init_cluster.app_cluster_machine_type = e2-small
|
|
init_cluster.app_cluster_mode = standard
|
|
init_cluster.app_cluster_name = knoe-dev-0
|
|
init_cluster.app_cluster_node_count = 3
|
|
init_cluster.argocd_enabled = false
|
|
init_cluster.at_rest_encryption_enabled = true
|
|
init_cluster.cluster_env = service
|
|
init_cluster.db_boot_disk_size_gb = 50
|
|
init_cluster.db_boot_disk_type = pd-standard
|
|
init_cluster.db_cluster_kubecontext = knoe.dev.prole.org
|
|
init_cluster.db_cluster_machine_type = e2-standard-2
|
|
init_cluster.db_cluster_mode = standard
|
|
init_cluster.db_cluster_name = knoe-cnpg-0
|
|
init_cluster.db_cluster_node_count = 3
|
|
init_cluster.db_cluster_region =
|
|
init_cluster.db_cluster_zones =
|
|
init_cluster.deployment_target = prole-service-cluster
|
|
init_cluster.gitops_enabled = true
|
|
init_cluster.k3s_server_url = https://myrddin.prole.org:6443
|
|
init_cluster.k3s_token = ${PROLE_SECRET:v1:vCWJZS-Sd3PspQvq:vvRx07ahtfy0r5l8VlvOvDjz2N-Ejstk1ilhBhTiQwmgaxF4RLsDjzZb9rHLjuagjnujJ2jv7F_7s8IHXA6a1baxyn58zHFctXn3AJWPDEVGpEu-iUQDuc5bDOMEVmC73wJ3Ormxs7ihhkWSrbyjYpeRfQUjYesGvJTJ1Q==}
|
|
init_cluster.kerberos_enabled = true
|
|
init_cluster.mode = k3s
|
|
init_cluster.start_cluster = true
|
|
init_cluster.supabase_analytics_enabled = true
|
|
init_cluster.supabase_auth_enabled = true
|
|
init_cluster.supabase_enabled = true
|
|
init_cluster.supabase_meta_enabled = true
|
|
init_cluster.supabase_realtime_enabled = true
|
|
init_cluster.supabase_studio_enabled = false
|
|
init_cluster.supabase_studio_url = db.0.knoe.dev
|
|
init_cnpg_deploy.force_rollout = false
|
|
init_cnpg_deploy.run_deploy = true
|
|
init_db_build.run_build = true
|
|
init_password.app_cluster_name = knoe-dev-0
|
|
init_password.cluster_name = ${CLUSTER_NAME}
|
|
init_password.db_cluster_name = knoe-cnpg-0
|
|
init_password.db_host_port = 5432
|
|
init_password.db_namespace = ${DATABASE_NAMESPACE}
|
|
init_password.db_password = ${PROLE_SECRET:v1:WNTnxKiwpKQokh_r:ETrt-VAR8rBiU6lCjudmKWzgCeVHimNG}
|
|
init_password.db_password_confirm = ${PROLE_SECRET:v1:WNTnxKiwpKQokh_r:ETrt-VAR8rBiU6lCjudmKWzgCeVHimNG}
|
|
init_password.db_username = root
|
|
init_password.generate_ssh_key = true
|
|
init_scripts.run_scripts = true
|
|
kerberos_config.enabled = true
|
|
kerberos_config.init_authority = true
|
|
kerberos_config.kdc = 10.0.0.3
|
|
kerberos_config.password = ${PROLE_SECRET:v1:U-EPMl7qv4heEB1k:BEcXGbI_LT4lCXwBuvFEGgPbLFa9MpVzECObdH0pbLtClDHf}
|
|
kerberos_config.realm = PROLE.ORG
|
|
kerberos_config.test_connection = false
|
|
kerberos_config.user = administrator
|
|
network_scan.run = true
|
|
ollama_config.model =
|
|
ollama_config.server_host = fairyland.prole.org
|
|
ollama_config.server_port = 11434
|
|
supabase_config.pv_base_dir = /synology/d005
|
|
supabase_config.pv_node = gandalf.prole.org
|
|
|
|
[Global]
|
|
; Variables used by name in more than one place or assumed global scope
|
|
ARGOCD_NAMESPACE = argocd
|
|
ARGOCD_NODE_SELECTOR = gandalf.prole.org
|
|
ARTIFACT_REGISTRY = us-west3-docker.pkg.dev/plenary-truck-485623-p7/knoe-system
|
|
CLUSTER_ENV = service
|
|
CLUSTER_NAME = knoe-db
|
|
CNPG_ELIGIBLE_NODES = gandalf.prole.org,merlin.prole.org,myrddin.prole.org
|
|
CNPG_PLACEMENT_PLAN_FILE = /Users/chrisfu/dev/prole/conf/cnpg-placement/knoe-system-knoe-db.json
|
|
CNPG_PLACEMENT_PLAN_HASH = 75c4114781519174
|
|
CNPG_PLACEMENT_PLAN_ID = cnpg-placement-75c4114781519174
|
|
CNPG_STAGE1_NODE = gandalf.prole.org
|
|
DATABASE_NAMESPACE = knoe-db
|
|
DB_HOST_PORT = 5432
|
|
DB_PASSWORD = ${PROLE_SECRET:v1:t7NgRHfXTXH-mHcx:CRbKP9b6ccuxrTMMeJ742Q48_vegoUY4}
|
|
DEPLOYMENT_MODE = k3s
|
|
DEPLOYMENT_TARGET = prole-service-cluster
|
|
DOCKER_IMPORT_DIR =
|
|
DOCKER_PRELOAD = false
|
|
GITEA_NODE_SELECTOR = gandalf.prole.org
|
|
K3S_SERVER = https://myrddin.prole.org:6443
|
|
K3S_TOKEN = ${PROLE_SECRET:v1:gnQjvO_dhM7qkU_g:kFb7E6IQ40RM64JfsrJWBPzkJsMaLXNpNPxfho6t8w5KAeWCAyrw2bMsQtJ8n7cPc_SLWh_zX53Sa1pvEOclmd79e-c_Qff0gZleba1PzzfkjsYRfVlpzQ34gdAHrNHQG2mKnpkcyrNFZ0j6J-w4c3m_m6bTN1cV1KQvMQ==}
|
|
KNOE_DB_USER = root
|
|
KNOE_IMAGE_REGISTRY = gitlab-registry.gitlab.svc.cluster.local:5000
|
|
MONITORING_STORAGE_CLASS = merlin-local-iscsi
|
|
OPENTOFU_URL = http://127.0.0.1:8080
|
|
OPTIONAL_WORKLOADS_MIN_READY_SCHEDULABLE_NODES = 2
|
|
PROLE_HOME = /Users/chrisfu/dev/prole
|
|
PROLE_K3S_SERVER = https://myrddin.prole.org:6443
|
|
PROLE_K3S_TOKEN = ${PROLE_SECRET:v1:vCWJZS-Sd3PspQvq:vvRx07ahtfy0r5l8VlvOvDjz2N-Ejstk1ilhBhTiQwmgaxF4RLsDjzZb9rHLjuagjnujJ2jv7F_7s8IHXA6a1baxyn58zHFctXn3AJWPDEVGpEu-iUQDuc5bDOMEVmC73wJ3Ormxs7ihhkWSrbyjYpeRfQUjYesGvJTJ1Q==}
|
|
REGISTRY_NAMESPACE = knoe-system
|
|
SERVICE_NAMESPACE = knoe-system
|
|
SUPABASE_PV_BASE = /synology/d005
|
|
SUPABASE_PV_BASE_DIR = /synology/d005
|
|
SUPABASE_PV_NODE = gandalf.prole.org
|
|
SUPABASE_STUDIO_HOSTNAME = db.0.knoe.dev,db.prole.org
|
|
GITLAB_PUBLIC_HOSTS = git.knoe.dev,git.prole.org
|
|
AUTHORITY_ENABLED = true
|
|
AUTH_HOSTNAME = api.prole.org
|
|
AUTH_VERIFY_PATH = /auth/verify
|
|
AUTH_LOGIN_PATH = /auth/login
|
|
AUTH_RESPONSE_HEADERS = X-Prole-User,X-Prole-Email,X-Prole-Groups
|
|
PROTECTED_GIT_HOSTS = git.knoe.dev,git.prole.org
|
|
PROTECTED_DB_HOSTS = db.0.knoe.dev,db.prole.org
|
|
SYNOLOGY_ROOTS = /synology/d001,/synology/d002,/synology/d004,/synology/d005
|
|
|
|
[Welcome]
|
|
; No configuration values captured yet for this section.
|
|
|
|
[Dependencies]
|
|
STATUS = All installed
|
|
|
|
[Network]
|
|
AD_DC_HOST = myrddin.prole.org
|
|
AD_DC_IP = 10.0.0.3
|
|
ANSIBLE_DOMAIN = prole.org
|
|
ANSIBLE_INFRASTRUCTURE = ${HOME}/dev/prole/infrastructure
|
|
ANSIBLE_INVENTORY = ${HOME}/dev/prole/infrastructure/inventory
|
|
ANSIBLE_REALM = PROLE.ORG
|
|
ANSIBLE_TOPOLOGY = {"domain":"prole.org","realm":"PROLE.ORG","internal_records":{"aventage.prole.org":"10.0.0.206","fairyland.prole.org":"10.0.0.208","loghost.prole.org":"10.0.0.3","merlin.prole.org":"10.0.0.6","morana.prole.org":"10.0.0.66","morgoth.prole.org":"10.0.0.204","myrddin.prole.org":"10.0.0.3","pi.prole.org":"10.0.0.5","raspberry.prole.org":"10.0.0.4","retropie.prole.org":"10.0.0.207","synology.prole.org":"10.0.0.203","zinfandel.prole.org":"10.0.0.205"},"ad_dc":{"host":"myrddin.prole.org","ip":"10.0.0.3"},"k3s":{"server_url":"https://myrddin.prole.org:6443","server_host":"myrddin.prole.org","token_present":true},"groups":{"iscsi":["pi.prole.org","raspberry.prole.org","myrddin.prole.org","retropie.prole.org","merlin.prole.org","gandalf.prole.org"],"pihole":["pi.prole.org","raspberry.prole.org"],"ad_dc":["myrddin.prole.org"],"k3s_servers":["myrddin.prole.org"],"k3s_agents":["merlin.prole.org","gandalf.prole.org"],"k3s_hosts:children":["k3s_servers","k3s_agents"],"linux_hosts":["pi.prole.org","raspberry.prole.org","myrddin.prole.org","retropie.prole.org","merlin.prole.org","gandalf.prole.org"],"ssl_hosts":["myrddin.prole.org"],"mariadb_primary":["merlin.prole.org"],"mariadb_replica":["raspberry.prole.org"],"mariadb:children":["mariadb_primary","mariadb_replica"],"merlin_bootstrap":["merlin"],"k3s_hosts":["gandalf.prole.org"]},"hosts":{"merlin":"10.0.0.6","merlin.prole.org":"10.0.0.6","myrddin.prole.org":"10.0.0.3","pi.prole.org":"10.0.0.5","raspberry.prole.org":"10.0.0.4","retropie.prole.org":"10.0.0.207"},"unmapped_hosts":["gandalf.prole.org","k3s_agents","k3s_servers","mariadb_primary","mariadb_replica"]}
|
|
KDC_ANSIBLE_DETECTED = 10.0.0.3
|
|
KDC_AUTO_DETECTED = 10.0.0.3
|
|
KERBEROS_AUTO_ENABLED = True
|
|
|
|
[Port Forwards]
|
|
PORT_FORWARD_K3S_MAPPING_1 = id=argocd;namespace=argocd;target=svc/argocd-server;address=0.0.0.0;hostPort=8081;servicePort=80;protocol=TCP;description=ArgoCD
|
|
PORT_FORWARD_K3S_MAPPING_10 = id=supabase-studio;namespace=supabase;target=svc/studio;address=0.0.0.0;hostPort=18080;servicePort=3000;protocol=TCP;description=Supabase Studio
|
|
PORT_FORWARD_K3S_MAPPING_11 = id=supabase-auth;namespace=supabase;target=svc/auth;address=127.0.0.1;hostPort=9999;servicePort=9999;protocol=TCP;description=Supabase Auth (GoTrue)
|
|
PORT_FORWARD_K3S_MAPPING_12 = id=supabase-rest;namespace=supabase;target=svc/rest;address=0.0.0.0;hostPort=3001;servicePort=3000;protocol=TCP;description=Supabase REST (PostgREST)
|
|
PORT_FORWARD_K3S_MAPPING_13 = id=supabase-realtime;namespace=supabase;target=svc/realtime;address=0.0.0.0;hostPort=4000;servicePort=4000;protocol=TCP;description=Supabase Realtime
|
|
PORT_FORWARD_K3S_MAPPING_14 = id=gitea-http;namespace=gitea;target=svc/gitea-http;address=0.0.0.0;hostPort=13000;servicePort=3000;protocol=TCP;description=Gitea Web
|
|
PORT_FORWARD_K3S_MAPPING_15 = id=gitea-ssh;namespace=gitea;target=svc/gitea-ssh;address=0.0.0.0;hostPort=22;servicePort=22;protocol=TCP;description=Gitea SSH
|
|
PORT_FORWARD_K3S_MAPPING_2 = id=garage;namespace=knoe-system;target=svc/garage;address=0.0.0.0;hostPort=3900;servicePort=3900;protocol=TCP;description=Garage S3
|
|
PORT_FORWARD_K3S_MAPPING_3 = id=openbao;namespace=knoe-system;target=svc/openbao;address=0.0.0.0;hostPort=8200;servicePort=8200;protocol=TCP;description=OpenBao
|
|
PORT_FORWARD_K3S_MAPPING_4 = id=opentofu;namespace=knoe-system;target=svc/opentofu;address=0.0.0.0;hostPort=8080;servicePort=8080;protocol=TCP;description=OpenTofu
|
|
PORT_FORWARD_K3S_MAPPING_5 = id=dashboard;namespace=kubernetes-dashboard;target=svc/kubernetes-dashboard-kong-proxy;address=127.0.0.1;hostPort=8443;servicePort=443;protocol=TCP;description=Kubernetes Dashboard
|
|
PORT_FORWARD_K3S_MAPPING_6 = id=postgres;namespace=${DATABASE_NAMESPACE};target=svc/knoe-db-rw;address=0.0.0.0;hostPort=5432;servicePort=5432;protocol=TCP;description=PostgreSQL (primary)
|
|
PORT_FORWARD_K3S_MAPPING_7 = id=prometheus;namespace=monitoring;target=svc/kps-kube-prometheus-stack-prometheus;address=127.0.0.1;hostPort=9090;servicePort=9090;protocol=TCP;description=Prometheus UI
|
|
PORT_FORWARD_K3S_MAPPING_8 = id=grafana;namespace=monitoring;target=svc/kps-grafana;address=0.0.0.0;hostPort=3000;servicePort=80;protocol=TCP;description=Grafana UI
|
|
PORT_FORWARD_K3S_MAPPING_9 = id=supabase-kong;namespace=supabase;target=svc/kong;address=0.0.0.0;hostPort=8000;servicePort=8000;protocol=TCP;description=Supabase API (Kong)
|
|
|
|
[System Environment]
|
|
PROLE_CONF = ${HOME}/dev/prole/conf
|
|
PROLE_DATA = ${HOME}/dev/prole/data
|
|
PROLE_HOME = ${HOME}/dev/prole
|
|
PROLE_LOGS = ${HOME}/dev/prole/logs
|
|
PROLE_SERVICE = ${HOME}/dev/prole/etc
|
|
|
|
[Monitoring]
|
|
GRAFANA_ADMIN_PASSWORD = ${PROLE_SECRET:v1:L2BhAyHRKVei4cGM:-J83-HR_CpnPFpiB6NbOXKdmmagVW2qL}
|
|
MONITORING_STORAGE_CLASS = merlin-local-iscsi
|
|
|
|
[Kerberos Authentication]
|
|
AD_PORT_FORWARD = 1
|
|
AD_PROXY_HOST_NETWORK = 1
|
|
AD_PROXY_IMAGE = alpine/socat
|
|
AD_PROXY_SERVICE = prole-kerberos-ad-dc
|
|
AD_TCP_PORTS = 88 389 445 464 636
|
|
AD_UDP_PORTS = 88 464
|
|
ENABLED = True
|
|
KDC = 10.0.0.3
|
|
PASSWORD = ${PROLE_SECRET:v1:SmpyHqa_Io4rpm1V:IfQesVrD3v_8cbjTf1Ls1cV0K4ENNCwPecr38EJX-rDDScOB}
|
|
REALM = PROLE.ORG
|
|
SERVER = 10.0.0.3
|
|
STATUS = Initialized
|
|
USER = administrator
|
|
|
|
[Ollama]
|
|
OLLAMA_HOST = http://fairyland.prole.org:11434
|
|
OLLAMA_SERVER_HOST = fairyland.prole.org
|
|
OLLAMA_SERVER_PORT = 11434
|
|
|
|
[Optional Features]
|
|
ARGOCD_ENABLED = False
|
|
AT_REST_ENCRYPTION_ENABLED = true
|
|
GITOPS_ENABLED = true
|
|
GITOPS_PROVIDER = GitLab
|
|
KERBEROS_ENABLED = true
|
|
SUPABASE_ENABLED = true
|
|
|
|
[GitOps]
|
|
|
|
[Database Creation]
|
|
APP_CLUSTER_NAME = knoe-dev-0
|
|
DB_CLUSTER_NAME = knoe-cnpg-0
|
|
DB_USER = root
|
|
|
|
[Initialize Cluster]
|
|
ENVIRONMENT = service
|
|
K3S_SERVER_URL = https://myrddin.prole.org:6443
|
|
K3S_TOKEN = ${PROLE_SECRET:v1:vCWJZS-Sd3PspQvq:vvRx07ahtfy0r5l8VlvOvDjz2N-Ejstk1ilhBhTiQwmgaxF4RLsDjzZb9rHLjuagjnujJ2jv7F_7s8IHXA6a1baxyn58zHFctXn3AJWPDEVGpEu-iUQDuc5bDOMEVmC73wJ3Ormxs7ihhkWSrbyjYpeRfQUjYesGvJTJ1Q==}
|
|
|
|
[Dev Cluster (k3d)]
|
|
CLUSTER_ENV = k3d-knoe-dev-cluster
|
|
DISPLAY_NAME = knoe-dev-cluster
|
|
KUBECTL_CONTEXT = service
|
|
MODE = k3d
|
|
|
|
[Service Cluster (k3s)]
|
|
CLUSTER_ENV = prole-service-cluster
|
|
DISPLAY_NAME = prole-service-cluster
|
|
K3S_SERVER_URL = https://myrddin.prole.org:6443
|
|
K3S_TOKEN = ${PROLE_SECRET:v1:vCWJZS-Sd3PspQvq:vvRx07ahtfy0r5l8VlvOvDjz2N-Ejstk1ilhBhTiQwmgaxF4RLsDjzZb9rHLjuagjnujJ2jv7F_7s8IHXA6a1baxyn58zHFctXn3AJWPDEVGpEu-iUQDuc5bDOMEVmC73wJ3Ormxs7ihhkWSrbyjYpeRfQUjYesGvJTJ1Q==}
|
|
MODE = k3s
|
|
PIPELINE_URL = http://127.0.0.1:8080
|
|
|
|
[GCP]
|
|
; No configuration values captured yet for this section.
|
|
|
|
[Prod Cluster (k8s)]
|
|
ARTIFACTS_DIR =
|
|
CLUSTER_ENV = prole-prod-cluster
|
|
DISPLAY_NAME = prole-prod-cluster
|
|
MODE = k8s
|
|
PIPELINE_URL = http://127.0.0.1:8080
|
|
|
|
[Docker Build]
|
|
; No configuration values captured yet for this section.
|
|
|
|
[Initialization Scripts]
|
|
STATUS = Completed
|
|
|
|
[Deployment]
|
|
MODE = k3s
|
|
TARGET = prole-service-cluster
|
|
|
|
[Install]
|
|
STATUS = Failed
|