watchtower is being destroyed. Removed from [vps], with its host_vars, its push token, and the six Gatus endpoints that referenced it (liveness, disk, two systemd services, the ntfy DNS record and the ntfy HTTP check). ntfy went with it - it ran nowhere else - so services/ntfy is deleted, subdomains.ntfy and ntfy_topic are gone from group_vars, and the ntfy playbook is out of site.yml. ntfy_topic already had no readers: the three infra/4xx plays that used it were deleted when their checks were superseded. Two things this exposed. services/ntfy/deploy_ntfy_playbook.yml was pointing at the WRONG MACHINE. It said `hosts: observability`, which resolves to the host `monitoring` (64.226.70.190) - but ntfy ran on watchtower, and ntfy.contrapeso.xyz pointed there. Running it would have installed ntfy on the new VPS. Moot now, but it is the same stale-identity failure as the rest: the group meant watchtower when the play was written, and nobody revisited it when the group changed. Watchtower was in [vps] and NO role group at all, while running caddy, ntfy and Uptime Kuma - nothing in the repo managed any of it. More seriously: ntfy-emergency-app on vipy (avisame.contrapeso.xyz) sends its notifications to https://ntfy.contrapeso.xyz, topic "emergencia". Destroying watchtower breaks it, and it is an EMERGENCY notifier - it would fail silently at exactly the moment it matters. That is NOT resolved here, deliberately: standing ntfy up elsewhere, pointing at ntfy.sh, or retiring the app are all decisions, not cleanups. What this change does is make the break impossible to miss. The URL was derived from subdomains.ntfy, so deleting that would have turned it into an undefined variable buried in a template. It is now an explicit ntfy_service_url in the app's own vars, still holding the old value, with the three options written above it. The ntfy credentials stay in the vault because that app still needs them - the vault was restored from HEAD and only watchtower's push token removed, rather than re-handling the plaintext. Verified: no reference to watchtower or its IP anywhere in the repo; Gatus down from 91 to 85 endpoints, 85 UP, 0 DOWN. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
74 lines
2.8 KiB
INI
74 lines
2.8 KiB
INI
[vps]
|
|
vipy ansible_host=167.172.107.33 ansible_user=counterweight ansible_port=22 ansible_ssh_private_key_file=~/.ssh/counterganzua
|
|
spacey ansible_host=64.227.112.128 ansible_user=counterweight ansible_port=22 ansible_ssh_private_key_file=~/.ssh/counterganzua
|
|
monitoring ansible_host=64.226.70.190 ansible_user=counterweight ansible_port=22 ansible_ssh_private_key_file=~/.ssh/counterganzua
|
|
|
|
[nodito_host]
|
|
nodito ansible_host=192.168.1.139 ansible_user=counterweight ansible_port=22 ansible_ssh_private_key_file=~/.ssh/counterganzua
|
|
|
|
# Requires the tailnet to be up on the control node.
|
|
[nodito_vms]
|
|
knots_box_local ansible_host=knots-box lan_ip=192.168.1.135 ansible_user=counterweight ansible_port=22 ansible_ssh_private_key_file=~/.ssh/counterganzua
|
|
fulcrum_box_local ansible_host=fulcrum-box lan_ip=192.168.1.140 ansible_user=counterweight ansible_port=22 ansible_ssh_private_key_file=~/.ssh/counterganzua
|
|
mempool_box_local ansible_host=mempool-box lan_ip=192.168.1.142 ansible_user=counterweight ansible_port=22 ansible_ssh_private_key_file=~/.ssh/counterganzua
|
|
memos_box_local ansible_host=memos-box lan_ip=192.168.1.145 ansible_user=counterweight ansible_port=22 ansible_ssh_private_key_file=~/.ssh/counterganzua
|
|
forgejo_runner_local ansible_host=forgejo-runner-box lan_ip=192.168.1.132 ansible_user=counterweight ansible_port=22 ansible_ssh_private_key_file=~/.ssh/counterganzua
|
|
arbret_staging_local ansible_host=arbret-staging-box lan_ip=192.168.1.147 ansible_user=counterweight ansible_port=22 ansible_ssh_private_key_file=~/.ssh/counterganzua
|
|
small_backups_local ansible_host=small-backups-box lan_ip=192.168.1.131 ansible_user=counterweight ansible_port=22 ansible_ssh_private_key_file=~/.ssh/counterganzua
|
|
|
|
# Local connection to laptop: this assumes you're running ansible commands from your personal laptop
|
|
[lapy]
|
|
localhost ansible_connection=local ansible_user=counterweight
|
|
|
|
[arbret]
|
|
prd-arbret ansible_host=167.99.242.62 ansible_user=counterweight ansible_port=22 ansible_ssh_private_key_file=~/.ssh/counterganzua
|
|
|
|
[edge]
|
|
vipy
|
|
|
|
# The group is `observability`, NOT `monitoring` — there is a HOST named
|
|
# `monitoring` on line 5, and a group with the same name makes `hosts: monitoring`
|
|
# ambiguous. Ansible resolved it to the host and warned:
|
|
# [WARNING]: Found both group and host with same name: monitoring
|
|
[observability]
|
|
monitoring
|
|
|
|
[vpn_control]
|
|
spacey
|
|
|
|
[hypervisor]
|
|
nodito
|
|
|
|
[bitcoin]
|
|
knots_box_local
|
|
|
|
[electrum]
|
|
fulcrum_box_local
|
|
|
|
[mempool]
|
|
mempool_box_local
|
|
|
|
[memos]
|
|
memos_box_local
|
|
|
|
[ci_runner]
|
|
forgejo_runner_local
|
|
|
|
[control]
|
|
localhost
|
|
|
|
# Every machine Ansible may configure as a server.
|
|
# Deliberately EXCLUDES [control] (your laptop) and [arbret].
|
|
[managed:children]
|
|
vps
|
|
nodito_host
|
|
nodito_vms
|
|
|
|
# Hosts that run Caddy and therefore have /etc/caddy/sites-enabled.
|
|
[caddy:children]
|
|
edge
|
|
observability
|
|
vpn_control
|
|
|
|
[backup_store]
|
|
small_backups_local
|