diff --git a/ansible/host_vars/fulcrum_box_local/main.yml b/ansible/host_vars/fulcrum_box_local/main.yml new file mode 100644 index 0000000..2cf3c65 --- /dev/null +++ b/ansible/host_vars/fulcrum_box_local/main.yml @@ -0,0 +1,6 @@ +# fulcrum-box: the Electrum server. +# +# Read by the fulcrum role here and by the socket-proxy play on the edge host, +# which publishes the port. See host_vars/knots_box_local/main.yml for why this +# lives in host_vars rather than in the role's defaults. +fulcrum_ssl_port: 50002 diff --git a/ansible/host_vars/knots_box_local/main.yml b/ansible/host_vars/knots_box_local/main.yml new file mode 100644 index 0000000..fb15905 --- /dev/null +++ b/ansible/host_vars/knots_box_local/main.yml @@ -0,0 +1,14 @@ +# knots-box: Bitcoin Knots and the DATUM Gateway. +# +# These ports are read twice: by the role that deploys the service here, and by +# the socket-proxy / Caddy plays that run on the EDGE host and publish them. +# A role default is invisible to that second play, which is why these live in +# host_vars rather than roles//defaults/ - the edge play reads them as +# hostvars['knots_box_local']., and the role picks them up automatically +# because host_vars outranks role defaults. +# +# They used to live in services_config.yml, a file 30 plays had to remember to +# name in vars_files: and that four role defaults silently depended on. +bitcoin_p2p_port: 8333 +datum_gateway_api_port: 7152 +datum_gateway_stratum_port: 23334 diff --git a/ansible/host_vars/mempool_box_local/main.yml b/ansible/host_vars/mempool_box_local/main.yml new file mode 100644 index 0000000..f46a1a5 --- /dev/null +++ b/ansible/host_vars/mempool_box_local/main.yml @@ -0,0 +1,6 @@ +# mempool-box: the Mempool block explorer. +# +# Read by the mempool role here and by the Caddy play on the edge host, which +# proxies to it. See host_vars/knots_box_local/main.yml for why this lives in +# host_vars rather than in the role's defaults. +mempool_frontend_port: 8080 diff --git a/ansible/infra/410_disk_usage_alerts.yml b/ansible/infra/410_disk_usage_alerts.yml index 85947d9..b286add 100644 --- a/ansible/infra/410_disk_usage_alerts.yml +++ b/ansible/infra/410_disk_usage_alerts.yml @@ -14,8 +14,6 @@ - name: Deploy Disk Usage Monitoring hosts: managed become: yes - vars_files: - - ../services_config.yml vars: disk_usage_threshold_percent: 80 diff --git a/ansible/infra/420_system_healthcheck.yml b/ansible/infra/420_system_healthcheck.yml index a69b456..9813d0c 100644 --- a/ansible/infra/420_system_healthcheck.yml +++ b/ansible/infra/420_system_healthcheck.yml @@ -14,8 +14,6 @@ - name: Deploy System Healthcheck Monitoring hosts: managed become: yes - vars_files: - - ../services_config.yml vars: healthcheck_interval_seconds: 60 # Send healthcheck every 60 seconds (1 minute) diff --git a/ansible/infra/430_cpu_temp_alerts.yml b/ansible/infra/430_cpu_temp_alerts.yml index 048f216..2e00bdb 100644 --- a/ansible/infra/430_cpu_temp_alerts.yml +++ b/ansible/infra/430_cpu_temp_alerts.yml @@ -14,8 +14,6 @@ - name: Deploy CPU Temperature Monitoring hosts: hypervisor become: yes - vars_files: - - ../services_config.yml vars: temp_threshold_celsius: 80 diff --git a/ansible/infra/920_join_headscale_mesh.yml b/ansible/infra/920_join_headscale_mesh.yml index 3a8641c..4decb5d 100644 --- a/ansible/infra/920_join_headscale_mesh.yml +++ b/ansible/infra/920_join_headscale_mesh.yml @@ -1,8 +1,6 @@ - name: Join machine to headscale mesh network hosts: managed become: yes - vars_files: - - ../services_config.yml vars: headscale_host_name: "spacey" headscale_subdomain: "{{ subdomains.headscale }}" diff --git a/ansible/roles/bitcoin_knots/defaults/main.yml b/ansible/roles/bitcoin_knots/defaults/main.yml index cd9d9c1..3a12ad1 100644 --- a/ansible/roles/bitcoin_knots/defaults/main.yml +++ b/ansible/roles/bitcoin_knots/defaults/main.yml @@ -15,9 +15,11 @@ bitcoin_conf_dir: /etc/bitcoin # Network bitcoin_rpc_port: 8332 -# Shared with the socket-proxy play on the edge host, so it lives in -# services_config.yml rather than only here. -bitcoin_p2p_port: "{{ service_settings.bitcoin.p2p_port }}" +# The edge host's socket-proxy/Caddy play needs this too, and a role default is +# invisible outside this role. The authoritative value for the live deployment is +# in host_vars/knots_box_local/main.yml, which outranks this; the value here is the +# protocol standard, so the role still works standalone. +bitcoin_p2p_port: 8333 bitcoin_rpc_bind: "0.0.0.0" # Build options diff --git a/ansible/roles/datum_gateway/defaults/main.yml b/ansible/roles/datum_gateway/defaults/main.yml index 3a8cac4..b9829f9 100644 --- a/ansible/roles/datum_gateway/defaults/main.yml +++ b/ansible/roles/datum_gateway/defaults/main.yml @@ -14,8 +14,12 @@ datum_gateway_log_dir: /var/log/datum-gateway datum_gateway_bin_path: /usr/local/bin/datum_gateway # Ports -datum_gateway_stratum_port: "{{ service_settings.datum_gateway.stratum_port }}" -datum_gateway_api_port: "{{ service_settings.datum_gateway.api_port }}" +# The edge host's socket-proxy/Caddy play needs this too, and a role default is +# invisible outside this role. The authoritative value for the live deployment is +# in host_vars/knots_box_local/main.yml, which outranks this; the value here is the +# protocol standard, so the role still works standalone. +datum_gateway_stratum_port: 23334 +datum_gateway_api_port: 7152 # Stratum settings datum_vardiff_min: 524288 # Minimum share difficulty (must be power of 2; OCEAN floor overrides if higher) diff --git a/ansible/roles/fulcrum/defaults/main.yml b/ansible/roles/fulcrum/defaults/main.yml index 0d5c190..cc778d4 100644 --- a/ansible/roles/fulcrum/defaults/main.yml +++ b/ansible/roles/fulcrum/defaults/main.yml @@ -25,9 +25,11 @@ bitcoin_rpc_port: 8332 # Bitcoin Knots RPC port # Network - Fulcrum server fulcrum_tcp_port: 50001 -# Shared with the socket-proxy play on the edge host, so it lives in -# services_config.yml rather than only here. -fulcrum_ssl_port: "{{ service_settings.fulcrum.ssl_port }}" +# The edge host's socket-proxy/Caddy play needs this too, and a role default is +# invisible outside this role. The authoritative value for the live deployment is +# in host_vars/fulcrum_box_local/main.yml, which outranks this; the value here is the +# protocol standard, so the role still works standalone. +fulcrum_ssl_port: 50002 # Binding address for Fulcrum TCP/SSL server: # - "127.0.0.1" = localhost only (use when Caddy is on the same box) # - "0.0.0.0" = all interfaces (use when Caddy is on a different box) diff --git a/ansible/roles/mempool/defaults/main.yml b/ansible/roles/mempool/defaults/main.yml index 586b004..2f983c6 100644 --- a/ansible/roles/mempool/defaults/main.yml +++ b/ansible/roles/mempool/defaults/main.yml @@ -22,9 +22,11 @@ fulcrum_tls: "false" mempool_network: "mainnet" # Container ports (internal) -# Sourced from services_config.yml: the Caddy play on the edge host needs this -# too, and a role default is not visible outside this role. -mempool_frontend_port: "{{ service_settings.mempool.frontend_port }}" +# The edge host's socket-proxy/Caddy play needs this too, and a role default is +# invisible outside this role. The authoritative value for the live deployment is +# in host_vars/mempool_box_local/main.yml, which outranks this; the value here is the +# protocol standard, so the role still works standalone. +mempool_frontend_port: 8080 mempool_backend_port: 8999 # MariaDB settings diff --git a/ansible/services/bitcoin-knots/deploy_bitcoin_knots_playbook.yml b/ansible/services/bitcoin-knots/deploy_bitcoin_knots_playbook.yml index 709cb30..0ca1e13 100644 --- a/ansible/services/bitcoin-knots/deploy_bitcoin_knots_playbook.yml +++ b/ansible/services/bitcoin-knots/deploy_bitcoin_knots_playbook.yml @@ -9,8 +9,6 @@ - name: Build and Deploy Bitcoin Knots from Source hosts: bitcoin become: yes - vars_files: - - ../../services_config.yml vars: # Preserves the push URL this check has been reporting to. The role knows # nothing about Uptime Kuma — this is just "a URL that accepts a ping". @@ -21,8 +19,6 @@ - name: Setup public Bitcoin P2P forwarding on the edge host hosts: edge become: yes - vars_files: - - ../../services_config.yml tasks: - name: Expose Bitcoin P2P through a socket proxy ansible.builtin.include_role: @@ -30,7 +26,7 @@ vars: socket_proxy_name: bitcoin-p2p socket_proxy_description: "Bitcoin P2P" - socket_proxy_listen_port: "{{ service_settings.bitcoin.p2p_port }}" + socket_proxy_listen_port: "{{ hostvars['knots_box_local'].bitcoin_p2p_port }}" socket_proxy_upstream_host: "{{ hostvars['knots_box_local'].ansible_host }}" socket_proxy_documentation: "https://github.com/bitcoin/bitcoin" socket_proxy_free_bind: true diff --git a/ansible/services/datum-gateway/deploy_datum_gateway_playbook.yml b/ansible/services/datum-gateway/deploy_datum_gateway_playbook.yml index ebb9633..84de178 100644 --- a/ansible/services/datum-gateway/deploy_datum_gateway_playbook.yml +++ b/ansible/services/datum-gateway/deploy_datum_gateway_playbook.yml @@ -10,8 +10,6 @@ - name: Deploy DATUM Gateway on the bitcoin host hosts: bitcoin become: yes - vars_files: - - ../../services_config.yml vars: # Preserves the push URL this check reports to. The role knows nothing about # Uptime Kuma — this is just "a URL that accepts a ping". @@ -22,8 +20,6 @@ - name: Configure Caddy reverse proxy for the DATUM Gateway dashboard on the edge host hosts: edge become: yes - vars_files: - - ../../services_config.yml tasks: - name: Publish the DATUM Gateway dashboard through Caddy ansible.builtin.include_role: @@ -31,7 +27,7 @@ vars: caddy_site_name: datum-gateway caddy_site_domain: "{{ subdomains.datum_gateway }}.{{ root_domain }}" - caddy_site_upstream: "{{ hostvars['knots_box_local'].ansible_host }}:{{ service_settings.datum_gateway.api_port }}" + caddy_site_upstream: "{{ hostvars['knots_box_local'].ansible_host }}:{{ hostvars['knots_box_local'].datum_gateway_api_port }}" caddy_site_resolvers: "100.100.100.100" caddy_site_basic_auth: - user: "{{ datum_dashboard_username }}" @@ -47,8 +43,6 @@ - name: Setup public Stratum port forwarding on the edge host hosts: edge become: yes - vars_files: - - ../../services_config.yml tasks: - name: Expose the DATUM Stratum port through a socket proxy ansible.builtin.include_role: @@ -56,7 +50,7 @@ vars: socket_proxy_name: datum-stratum socket_proxy_description: "DATUM Stratum" - socket_proxy_listen_port: "{{ service_settings.datum_gateway.stratum_port }}" + socket_proxy_listen_port: "{{ hostvars['knots_box_local'].datum_gateway_stratum_port }}" socket_proxy_upstream_host: "{{ hostvars['knots_box_local'].ansible_host }}" # Matches the UFW comment already on the edge host; the derived default # would say "DATUM Stratum" and rewrite the rule. diff --git a/ansible/services/forgejo-runner/deploy_forgejo_runner_playbook.yml b/ansible/services/forgejo-runner/deploy_forgejo_runner_playbook.yml index 9195087..031f081 100644 --- a/ansible/services/forgejo-runner/deploy_forgejo_runner_playbook.yml +++ b/ansible/services/forgejo-runner/deploy_forgejo_runner_playbook.yml @@ -2,8 +2,6 @@ - name: Install Forgejo Runner on Debian 13 hosts: ci_runner become: yes - vars_files: - - ../../services_config.yml vars: # Preserves the push URL this host has been reporting to all along, so the # move to a role changes no behaviour. The role itself knows nothing about diff --git a/ansible/services/forgejo/deploy_forgejo_playbook.yml b/ansible/services/forgejo/deploy_forgejo_playbook.yml index a929d42..04d7041 100644 --- a/ansible/services/forgejo/deploy_forgejo_playbook.yml +++ b/ansible/services/forgejo/deploy_forgejo_playbook.yml @@ -2,7 +2,6 @@ hosts: edge become: yes vars_files: - - ../../services_config.yml - ./forgejo_vars.yml vars: forgejo_subdomain: "{{ subdomains.forgejo }}" diff --git a/ansible/services/fulcrum/deploy_fulcrum_playbook.yml b/ansible/services/fulcrum/deploy_fulcrum_playbook.yml index 6b8e207..8927aba 100644 --- a/ansible/services/fulcrum/deploy_fulcrum_playbook.yml +++ b/ansible/services/fulcrum/deploy_fulcrum_playbook.yml @@ -5,8 +5,6 @@ - name: Deploy Fulcrum Electrum Server hosts: electrum become: yes - vars_files: - - ../../services_config.yml vars: # Preserves the push URL this check has been configured with. The role knows # nothing about Uptime Kuma — this is just "a URL that accepts a ping". @@ -17,8 +15,6 @@ - name: Setup public Fulcrum SSL forwarding on the edge host hosts: edge become: yes - vars_files: - - ../../services_config.yml tasks: - name: Expose Fulcrum SSL through a socket proxy ansible.builtin.include_role: @@ -26,5 +22,5 @@ vars: socket_proxy_name: fulcrum-ssl socket_proxy_description: "Fulcrum SSL" - socket_proxy_listen_port: "{{ service_settings.fulcrum.ssl_port }}" + socket_proxy_listen_port: "{{ hostvars['fulcrum_box_local'].fulcrum_ssl_port }}" socket_proxy_upstream_host: "{{ hostvars['fulcrum_box_local'].ansible_host }}" diff --git a/ansible/services/headscale/deploy_headscale_playbook.yml b/ansible/services/headscale/deploy_headscale_playbook.yml index 4308b1e..11c967e 100644 --- a/ansible/services/headscale/deploy_headscale_playbook.yml +++ b/ansible/services/headscale/deploy_headscale_playbook.yml @@ -2,7 +2,6 @@ hosts: vpn_control become: no vars_files: - - ../../services_config.yml - ./headscale_vars.yml vars: headscale_subdomain: "{{ subdomains.headscale }}" diff --git a/ansible/services/lnbits/deploy_lnbits_playbook.yml b/ansible/services/lnbits/deploy_lnbits_playbook.yml index 3aa7a95..5d0c21d 100644 --- a/ansible/services/lnbits/deploy_lnbits_playbook.yml +++ b/ansible/services/lnbits/deploy_lnbits_playbook.yml @@ -2,7 +2,6 @@ hosts: edge become: yes vars_files: - - ../../services_config.yml - ./lnbits_vars.yml vars: lnbits_subdomain: "{{ subdomains.lnbits }}" diff --git a/ansible/services/memos/deploy_memos_playbook.yml b/ansible/services/memos/deploy_memos_playbook.yml index e078d84..756ab4f 100644 --- a/ansible/services/memos/deploy_memos_playbook.yml +++ b/ansible/services/memos/deploy_memos_playbook.yml @@ -2,7 +2,6 @@ hosts: memos become: yes vars_files: - - ../../services_config.yml - ./memos_vars.yml vars: memos_subdomain: "{{ subdomains.memos }}" @@ -158,7 +157,6 @@ hosts: edge become: yes vars_files: - - ../../services_config.yml - ./memos_vars.yml vars: memos_subdomain: "{{ subdomains.memos }}" diff --git a/ansible/services/mempool/deploy_mempool_playbook.yml b/ansible/services/mempool/deploy_mempool_playbook.yml index c2c8f4f..76a3eb0 100644 --- a/ansible/services/mempool/deploy_mempool_playbook.yml +++ b/ansible/services/mempool/deploy_mempool_playbook.yml @@ -2,8 +2,6 @@ - name: Deploy Mempool Block Explorer with Docker hosts: mempool become: yes - vars_files: - - ../../services_config.yml vars: # Preserves the three push URLs these checks have been reporting to all # along, so the move to a role changes no behaviour. The role knows nothing @@ -19,8 +17,6 @@ - name: Configure Caddy reverse proxy for Mempool on the edge host hosts: edge become: yes - vars_files: - - ../../services_config.yml vars: mempool_domain: "{{ subdomains.mempool }}.{{ root_domain }}" tasks: @@ -30,5 +26,5 @@ vars: caddy_site_name: mempool caddy_site_domain: "{{ mempool_domain }}" - caddy_site_upstream: "mempool-box:{{ service_settings.mempool.frontend_port }}" + caddy_site_upstream: "{{ hostvars['mempool_box_local'].ansible_host }}:{{ hostvars['mempool_box_local'].mempool_frontend_port }}" caddy_site_resolvers: "100.100.100.100" diff --git a/ansible/services/ntfy-emergency-app/deploy_ntfy_emergency_app_playbook.yml b/ansible/services/ntfy-emergency-app/deploy_ntfy_emergency_app_playbook.yml index 1b53732..c759592 100644 --- a/ansible/services/ntfy-emergency-app/deploy_ntfy_emergency_app_playbook.yml +++ b/ansible/services/ntfy-emergency-app/deploy_ntfy_emergency_app_playbook.yml @@ -2,7 +2,6 @@ hosts: edge become: yes vars_files: - - ../../services_config.yml - ./ntfy_emergency_app_vars.yml vars: ntfy_emergency_app_subdomain: "{{ subdomains.ntfy_emergency_app }}" diff --git a/ansible/services/ntfy/deploy_ntfy_playbook.yml b/ansible/services/ntfy/deploy_ntfy_playbook.yml index d6253b5..afd8e69 100644 --- a/ansible/services/ntfy/deploy_ntfy_playbook.yml +++ b/ansible/services/ntfy/deploy_ntfy_playbook.yml @@ -2,7 +2,6 @@ hosts: monitoring become: yes vars_files: - - ../../services_config.yml - ./ntfy_vars.yml vars: ntfy_subdomain: "{{ subdomains.ntfy }}" diff --git a/ansible/services/ntfy/setup_ntfy_uptime_kuma_notification.yml b/ansible/services/ntfy/setup_ntfy_uptime_kuma_notification.yml index 861bfa5..7588618 100644 --- a/ansible/services/ntfy/setup_ntfy_uptime_kuma_notification.yml +++ b/ansible/services/ntfy/setup_ntfy_uptime_kuma_notification.yml @@ -15,7 +15,6 @@ hosts: monitoring become: no vars_files: - - ../../services_config.yml - ./ntfy_vars.yml vars: diff --git a/ansible/services/personal-blog/deploy_personal_blog_playbook.yml b/ansible/services/personal-blog/deploy_personal_blog_playbook.yml index 968f423..5e3780d 100644 --- a/ansible/services/personal-blog/deploy_personal_blog_playbook.yml +++ b/ansible/services/personal-blog/deploy_personal_blog_playbook.yml @@ -2,7 +2,6 @@ hosts: edge become: yes vars_files: - - ../../services_config.yml - ./personal_blog_vars.yml vars: personal_blog_subdomain: "{{ subdomains.personal_blog }}" diff --git a/ansible/services/phoenixd/deploy_phoenixd_playbook.yml b/ansible/services/phoenixd/deploy_phoenixd_playbook.yml index 45bea3c..0df1223 100644 --- a/ansible/services/phoenixd/deploy_phoenixd_playbook.yml +++ b/ansible/services/phoenixd/deploy_phoenixd_playbook.yml @@ -4,8 +4,6 @@ - name: Deploy phoenixd on the edge host hosts: edge become: yes - vars_files: - - ../../services_config.yml vars: # phoenixd's health check has never reported anywhere since the Uptime Kuma # decommissioning — its systemd Environment= was left empty. Leaving it empty diff --git a/ansible/services/vaultwarden/deploy_vaultwarden_playbook.yml b/ansible/services/vaultwarden/deploy_vaultwarden_playbook.yml index 987fe27..d03363c 100644 --- a/ansible/services/vaultwarden/deploy_vaultwarden_playbook.yml +++ b/ansible/services/vaultwarden/deploy_vaultwarden_playbook.yml @@ -2,7 +2,6 @@ hosts: edge become: yes vars_files: - - ../../services_config.yml - ./vaultwarden_vars.yml vars: vaultwarden_subdomain: "{{ subdomains.vaultwarden }}" diff --git a/ansible/services_config.yml b/ansible/services_config.yml deleted file mode 100644 index 531b824..0000000 --- a/ansible/services_config.yml +++ /dev/null @@ -1,24 +0,0 @@ -# Cross-host service settings. -# -# These exist because a value is needed by the service's own role on one host -# AND by a play that runs on the edge host. A role default is invisible to that -# second play, so it cannot live in roles//defaults/. -# -# Everything else that used to be here has moved: -# subdomains, ntfy topic, headscale namespace -> group_vars/all/main.yml -# caddy_sites_dir -> roles/caddy_site/defaults/ -# *.tailscale_hostname -> deleted; inventory already -# holds each box's identity as ansible_host, and an edge play reads it with -# hostvars[''].ansible_host. Three copies of one name is how -# bitcoin_rpc_host ended up labelled "knots_box" while pointing at -# fulcrum-box. -service_settings: - mempool: - frontend_port: 8080 - bitcoin: - p2p_port: 8333 - datum_gateway: - api_port: 7152 - stratum_port: 23334 - fulcrum: - ssl_port: 50002