platform/platform-infra/ansible/group_vars/all.yml
Bart Van Geyt 7a65e7f7c6 fix(ansible/backup): create /etc/sanoid and install its defaults
Some sanoid packages (e.g. on Ubuntu 26.04) don't ship /etc/sanoid, so the
config template failed with 'Destination directory does not exist'. Create
the directory explicitly, and copy the packaged sanoid.defaults.conf into
it (sanoid requires it beside sanoid.conf) so the first timer run succeeds.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-09 05:28:08 +02:00

86 lines
4.5 KiB
YAML

# ─────────────────────────────────────────────────────────────────────────────
# heleos platform — host baseline variables (Phase 1)
# Edit these to match your environment before running the playbook.
# ─────────────────────────────────────────────────────────────────────────────
# --- General ----------------------------------------------------------------
host_timezone: "Europe/Brussels"
# --- ZFS --------------------------------------------------------------------
# The pool is created on a DEDICATED second virtual disk. Attach a disk to the
# VM first (e.g. /dev/sdb or /dev/vdb) and set it here.
#
# ⚠️ zpool create is DESTRUCTIVE to the target disk. The playbook refuses to
# touch a disk that already contains a filesystem/partition unless you set
# zfs_pool_force: true. For production prefer a stable /dev/disk/by-id/... path.
zfs_pool_name: tank
zfs_pool_disk: /dev/sdb
zfs_pool_force: false
zfs_compression: lz4 # lz4 (fast) or zstd (denser)
# Datasets created under the pool. Web roots and per-site/customer datasets are
# created later by the provisioning CLI (Phase 4); here we create the fixed
# platform datasets + the customers parent. See docs/03-naming-conventions.md.
zfs_child_datasets:
- { path: "platform" }
- { path: "platform/docker", mountpoint: "/var/lib/docker" }
- { path: "platform/mariadb" }
- { path: "platform/db-backups" }
- { path: "platform/traefik" }
- { path: "platform/forgejo" }
- { path: "platform/monitoring" }
- { path: "customers" }
# --- Docker -----------------------------------------------------------------
# APT codename for Docker's repo. Defaults to the VM's release. Docker only
# publishes repos for LTS + recent codenames — on a non-LTS Ubuntu (e.g.
# oracular/plucky) set this to the nearest LTS, e.g. "noble".
docker_apt_codename: "noble"
# Native ZFS storage driver keeps image layers as ZFS datasets under the pool
# (data-root sits on tank/platform/docker). Switch to overlay2 only if you have
# a specific reason.
docker_storage_driver: zfs
docker_data_root: /var/lib/docker
# Address pool for the many per-site bridge networks (avoids subnet exhaustion).
docker_address_pool_base: "10.201.0.0/16"
docker_address_pool_size: 24
# --- Firewall (nftables + Docker egress) ------------------------------------
ssh_port: 22
firewall_allowed_tcp_ports: [80, 443] # SSH is added automatically via ssh_port
# Outbound SMTP from containers is blocked (spam prevention from hacked sites).
smtp_blocked_ports: [25, 465, 587]
smtp_relay_host: "" # optional: allow SMTP only to this host
# --- SSH hardening ----------------------------------------------------------
# ⚠️ If ssh_disable_password_auth is true you MUST provide admin_authorized_keys
# for admin_user, or you will lock yourself out. The playbook asserts this.
admin_user: "{{ ansible_user }}"
admin_authorized_keys: [] # list of public key strings
ssh_disable_password_auth: false # flip to true once key login is verified
# --- Backups / DR (Phase 5) -------------------------------------------------
mariadb_container: mariadb
mariadb_env_file: /opt/heleos/platform-infra/stacks/mariadb/.env
deployments_dir: /opt/heleos/deployments
# ZFS snapshots via sanoid (files stream). Retention is per policy below.
backup_snapshots_enabled: true
sanoid_datasets:
- { name: "{{ zfs_pool_name }}/customers", recursive: true, hourly: 36, daily: 30, weekly: 8, monthly: 6 }
- { name: "{{ zfs_pool_name }}/platform", recursive: true, hourly: 0, daily: 14, weekly: 4, monthly: 3 }
# Per-database dumps (DB stream), automysqlbackup-style rotation via docker exec.
db_backup_enabled: true
db_backup_dir: "/{{ zfs_pool_name }}/platform/db-backups"
db_backup_oncalendar: "*-*-* 01:30:00"
db_backup_keep_daily: 14
db_backup_keep_weekly: 8
db_backup_keep_monthly: 6
# Offsite. Leave the targets empty to disable that stream.
zfs_offsite_target: "" # e.g. "user@backup-host:backup/heleos"
zfs_offsite_datasets: ["{{ zfs_pool_name }}/customers", "{{ zfs_pool_name }}/platform"]
zfs_offsite_oncalendar: "*-*-* 03:00:00"
db_offsite_target: "" # e.g. "user@backup-host:/srv/heleos/db-backups"
db_offsite_oncalendar: "*-*-* 03:30:00"