mirror of
https://github.com/fscotto/infra.git
synced 2026-09-28 03:03:49 +00:00
Add Atlas media and storage services [Phase 1] (#9)
* Add Atlas media and storage services * Document Atlas backend phase one and WireGuard deployment * Enable Atlas NAS management and document bootstrap workflow * Harden Atlas network, SSH, firewall, and sharing * Rotate Ansible Vault secrets * Allow configurable Aegis SSH users and authorized keys * Manage Aegis SSH authorized key fragments * Manage SSH authorized key fragments for infrastructure hosts * Harden Rocky storage and sharing configuration * Verify WireGuard handshakes and restore Podman networking
This commit is contained in:
committed by
GitHub
parent
73bf2cd62a
commit
160d63c02d
18
ansible/roles/wireguard_overlay/defaults/main.yml
Normal file
18
ansible/roles/wireguard_overlay/defaults/main.yml
Normal file
@@ -0,0 +1,18 @@
|
||||
---
|
||||
wireguard_overlay_enabled: false
|
||||
wireguard_interface: wg0
|
||||
wireguard_config_dir: /etc/wireguard
|
||||
wireguard_private_key_path: "{{ wireguard_config_dir }}/{{ wireguard_interface }}.key"
|
||||
wireguard_config_path: "{{ wireguard_config_dir }}/{{ wireguard_interface }}.conf"
|
||||
wireguard_address: CHANGEME_WIREGUARD_ADDRESS
|
||||
wireguard_listen_port: 0
|
||||
wireguard_mtu: 1420
|
||||
wireguard_firewalld_zone: wireguard
|
||||
wireguard_public_firewalld_zone: public
|
||||
wireguard_enable_ipv4_forwarding: false
|
||||
wireguard_reload_rootful_podman_networks: false
|
||||
wireguard_handshake_retries: 12
|
||||
wireguard_handshake_delay: 5
|
||||
wireguard_peers: []
|
||||
wireguard_packages:
|
||||
- wireguard-tools
|
||||
Reference in New Issue
Block a user