139 lines
7.1 KiB
YAML
139 lines
7.1 KiB
YAML
---
|
|
|
|
users:
|
|
- name: admin
|
|
password_hash: !vault |
|
|
$ANSIBLE_VAULT;1.1;AES256
|
|
30623138653735643561343061356531373430393662383764633038383238383837626636393432
|
|
3138653539356430306266663864343563616332656131310a343632323363653665646363366437
|
|
66643430626437333461656231303339656435346261336238313036306431396333643965666631
|
|
3665393163623266320a373838313538626438623330393533353931336331623464613664633430
|
|
32303734396634376431383936643431313561303864343930393363623130663236666636353637
|
|
63613237383666656263316661333031643032323266636464313839653065316138343035346161
|
|
64313037336666353136383462333832373031623637636630326330313832333265386632343139
|
|
30306638356434376635346637346134653064613236326333656566383137353166393063333563
|
|
32623638343263313463313062303465626439356461613235656661623364656138
|
|
ssh_public_keys:
|
|
- "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDKNzJdo6/c7uXrg0lqVwyXOhcNxO/BnylyJeqoBe4rAO5fhjwWLsvMAeCEmYa/3i8ITSvurFEou7BELo25vM58dNfGQHig52LrA/GU/jwDAhHyTXP3AvqqgIFa0ysMaHasYny6oqXi+eb2w/KimtgOhe5/oUdNBe/KgqZ+hP3qlTchxBl5MEzZIKgXTXQeYJpYYrnFb0l/R8qSkFBJv2xzxVJxEamN71SG7OIsi9m14D6hd2pNDHDDqHgKBVbN5irxDuJAzHN5upzfziXiYCOusud23tX6/nNv8t03CbB7FW0OxaCGhAjbavTFAf164L9GM7j76BGsLwWSh2HhG9G9lKs2bEI3IQudllMc6p9N6j2FhMOCKK6YYekdAOVc3ozTFc73VLkXtN8pnTC8OCSavthSt5jOUd0qTsQGH91lWlEkVe0bWi+s9nggfeWFM7HMVmqsR1jYlOXoi5s7xYwKLUdeUjRk3/rkzIFoOxquE5sVVuNDRNCaqcpPVY4k0gE= openpgp:0x8880F3E0"
|
|
- "ssh-ed25519 \
|
|
AAAAC3NzaC1lZDI1NTE5AAAAIJRnXU2My2iMXl1yCIEoASZYAUW0q1qn3P5tSUI0B0+4 \
|
|
openpgp:0xAD2BFD7F"
|
|
opendoas_settings: "permit persist admin as root"
|
|
- name: ansible
|
|
password_hash: ""
|
|
ssh_public_keys:
|
|
- "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDKNzJdo6/c7uXrg0lqVwyXOhcNxO/BnylyJeqoBe4rAO5fhjwWLsvMAeCEmYa/3i8ITSvurFEou7BELo25vM58dNfGQHig52LrA/GU/jwDAhHyTXP3AvqqgIFa0ysMaHasYny6oqXi+eb2w/KimtgOhe5/oUdNBe/KgqZ+hP3qlTchxBl5MEzZIKgXTXQeYJpYYrnFb0l/R8qSkFBJv2xzxVJxEamN71SG7OIsi9m14D6hd2pNDHDDqHgKBVbN5irxDuJAzHN5upzfziXiYCOusud23tX6/nNv8t03CbB7FW0OxaCGhAjbavTFAf164L9GM7j76BGsLwWSh2HhG9G9lKs2bEI3IQudllMc6p9N6j2FhMOCKK6YYekdAOVc3ozTFc73VLkXtN8pnTC8OCSavthSt5jOUd0qTsQGH91lWlEkVe0bWi+s9nggfeWFM7HMVmqsR1jYlOXoi5s7xYwKLUdeUjRk3/rkzIFoOxquE5sVVuNDRNCaqcpPVY4k0gE= openpgp:0x8880F3E0"
|
|
- "ssh-ed25519 \
|
|
AAAAC3NzaC1lZDI1NTE5AAAAIJRnXU2My2iMXl1yCIEoASZYAUW0q1qn3P5tSUI0B0+4 \
|
|
openpgp:0xAD2BFD7F"
|
|
opendoas_settings: "permit nopass ansible"
|
|
|
|
|
|
|
|
forgejo_clean_binaries: false
|
|
forgejo_version: 11.0.2
|
|
|
|
forgejo_app_name: "cuqmbr's Forgejo"
|
|
forgejo_app_slogan: ""
|
|
forgejo_run_mode: prod
|
|
|
|
forgejo_db_type: postgres
|
|
forgejo_db_host: 192.168.0.3:5432
|
|
forgejo_db_name: forgejo_db
|
|
forgejo_db_username: forgejo
|
|
forgejo_db_password: !vault |
|
|
$ANSIBLE_VAULT;1.1;AES256
|
|
32373165333932643133666362336336326538646533303763343465336338393538666235616464
|
|
3065363334323132633161646437366636653462333237350a643161303166376532636562373331
|
|
39353331613939643639323431653233356161313937616536656363643933643734393032623831
|
|
3562373130643365630a633836326638666261386330653134333938306162646466393133316335
|
|
39323030373266393239353633343863313566356533636539666463336538656535613137373634
|
|
64633934393538336630373233373961613735363838333237356332313461303231323031313630
|
|
31663564373062306165373238376430653837316139353663313730376339386233633330653234
|
|
38386138316334376635616532383530663163663666643430666432623633303166376338613761
|
|
62373866303234613635366432333661393465636335626537353561643035306265666139663238
|
|
63623835303537626162653564303430383962646531373330323639643635393665633564303237
|
|
333866366330316466636164326130303031
|
|
forgejo_ssl_mode: disable
|
|
|
|
forgejo_server_domain: git.dev.cuqmbr.xyz
|
|
forgejo_server_root_url: http://git.dev.cuqmbr.xyz
|
|
forgejo_server_http_address: 0.0.0.0
|
|
forgejo_server_http_port: 3000
|
|
forgejo_server_ssh_port: 22
|
|
forgejo_server_lfs_secret: !vault |
|
|
$ANSIBLE_VAULT;1.1;AES256
|
|
65316236393837386464643938366564623532303139383765306631643864643363356561643666
|
|
6335343266313432366136323932306536623261643236640a363738366366303030383537633033
|
|
62356465313061376464633634333238316466633464626134363932373963373963383262666534
|
|
3134343137323734660a326638636162636539636663386437643034313661323266633361646461
|
|
31653534326664393138666237353438393739613565643137653438626462653165366136353039
|
|
3538653438613964653965303932643062306230383832633639
|
|
|
|
forgejo_mailer_from: "\"cuqmbr's Forgejo\" <no-reply@cuqmbr.xyz>"
|
|
forgejo_mailer_protocol: smtps
|
|
forgejo_mailer_address: mail.cuqmbr.xyz
|
|
forgejo_mailer_port: 465
|
|
forgejo_mailer_user: no-reply@cuqmbr.xyz
|
|
forgejo_mailer_password: !vault |
|
|
$ANSIBLE_VAULT;1.1;AES256
|
|
31356466316634336162653164316232653865393539656336356130353764316537633535396433
|
|
3862343463633864336633373036323364373863613439310a663461636136366532633639313139
|
|
32336632623631346236336263306633326261393238346632653733343163643737383537393939
|
|
6263326538363633350a316666323566646638316535333934626638356434353864373566653338
|
|
37303436626261333863313961386465353831633537636537343166666438326138
|
|
|
|
forgejo_security_install_lock: true
|
|
forgejo_security_internal_token: !vault |
|
|
$ANSIBLE_VAULT;1.1;AES256
|
|
37396532353265376134316465336263616562373030663762333165363362313135653434383961
|
|
6334363937636138383865353639333261376437393839320a333834643939373231623134393865
|
|
31646263626533326533306136323735313237343437653265393534313739353930316462313765
|
|
3933643737663934320a363661353761646133366133366539306331396634626162306430346364
|
|
39313833336264666634393765336232643961393364646664643538396336316364623430343034
|
|
64643932613961613931336339353462373438333631633533363633656638383235353939313831
|
|
31313165623130633034613566343461663661323834303930323832343766313661643033626238
|
|
32613830383031346361343735393535623931356438383539303038343562373264343666373165
|
|
65333632303535626237373835353665623237353734383436346664663036376538
|
|
|
|
forgejo_oauth2_jwt_secret: !vault |
|
|
$ANSIBLE_VAULT;1.1;AES256
|
|
62663534346334366537303037613331396164323637643033383961383165333239313934316661
|
|
6461323764383861663237323066333132393434386137330a343239346561373139386164626562
|
|
35653437653762663231643439346139373133303738366139663332376461323531333065333732
|
|
6466373034346231650a363164373264633432393639323232633565656436663761343634616366
|
|
37643964383837376630303036363737343464666461336533393362313830376335326530306139
|
|
6331323465376131656666306361623637643864616665333436
|
|
|
|
|
|
fluentbit_settings:
|
|
service:
|
|
flush: 1
|
|
daemon: false
|
|
log_level: info
|
|
http_server: false
|
|
pipeline:
|
|
inputs:
|
|
- name: systemd
|
|
tag: systemd_input
|
|
filters:
|
|
- name: rewrite_tag
|
|
match: systemd_input
|
|
rule: $_SYSTEMD_UNIT ^(forgejo.service)$ forgejo false
|
|
- name: rewrite_tag
|
|
match: systemd_input
|
|
rule: $_SYSTEMD_UNIT ^(forgejo.service.+|(?!forgejo.service).*)$ systemd false
|
|
- name: record_modifier
|
|
match: forgejo
|
|
allowlist_key:
|
|
- MESSAGE
|
|
outputs:
|
|
- name: loki
|
|
host: 192.168.0.252
|
|
labels: "env=dev,hostname=forgejo,service_name=forgejo"
|
|
match: forgejo
|
|
- name: loki
|
|
host: 192.168.0.252
|
|
labels: "env=dev,hostname=forgejo,service_name=systemd"
|
|
match: systemd
|