hosts.yml repeated the same authentication block for 13 LXC hosts and carried 13 byte-identical copies of the ru-vps ProxyCommand. Describe the transport once in ansible/ssh_config instead: jump host, per-host users, keys, and the fact that pbs and ovpn-mini are reached directly rather than through ru-vps. Ansible loads that file through ansible_ssh_common_args in group_vars/all/main.yml, where the path is derived from inventory_dir so it depends on neither the current directory nor the clone location. The same file makes `ssh gitea` work from a plain terminal once ~/.ssh/config includes it. hosts.yml drops from 209 to 137 lines and now holds only addresses and per-host facts. Verified equivalent: ansible-inventory --list before and after differ only by the removed ansible_ssh_common_args, with group membership and ordering byte-identical. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GTocXkGUUazHdKKd3r9k71
138 lines
3.4 KiB
YAML
138 lines
3.4 KiB
YAML
# Каноничный список хостов HomeLab.
|
|
#
|
|
# Общие переменные: inventory/group_vars/all/main.yml
|
|
# Переменные LXC: inventory/group_vars/lxc_infra/main.yml
|
|
# SSH-транспорт: ../ssh_config (подключён через ssh_args в ansible.cfg)
|
|
#
|
|
# Здесь у хоста остаются только адрес и его индивидуальные факты.
|
|
all:
|
|
children:
|
|
homelab:
|
|
hosts:
|
|
ru-vps:
|
|
ansible_host: vps
|
|
monitoring_exporter_node_listen_address: 127.0.0.1:9100
|
|
openvpn_local_ip: 10.78.0.1
|
|
openvpn_peer_ip: 10.78.0.2
|
|
openvpn_role: server
|
|
|
|
pve_nodes:
|
|
hosts:
|
|
cloud-pc:
|
|
ansible_host: 192.168.1.5
|
|
expected_lan_ip: 192.168.1.5
|
|
storage_mounts:
|
|
- src: UUID=ae278333-4116-4225-9b95-595496fadd26
|
|
path: /opt/data
|
|
fstype: ext4
|
|
- src: UUID=940a9a4e-10cf-4380-9d22-a71549066561
|
|
path: /mnt/backup
|
|
fstype: ext4
|
|
|
|
mini-pc:
|
|
ansible_host: 192.168.1.10
|
|
expected_lan_ip: 192.168.1.10
|
|
|
|
lxc_infra:
|
|
hosts:
|
|
# Доступны напрямую по LAN (без ProxyJump через ru-vps)
|
|
pbs:
|
|
ansible_host: 192.168.1.20
|
|
expected_lan_ip: 192.168.1.20
|
|
|
|
ovpn-mini:
|
|
ansible_host: 192.168.1.23
|
|
expected_lan_ip: 192.168.1.23
|
|
openvpn_local_ip: 10.78.0.2
|
|
openvpn_peer_ip: 10.78.0.1
|
|
openvpn_role: gateway
|
|
|
|
# Остальные LXC — через ru-vps (см. ssh_config)
|
|
adguard:
|
|
ansible_host: 192.168.1.28
|
|
expected_lan_ip: 192.168.1.28
|
|
|
|
docker-test:
|
|
ansible_host: 192.168.1.29
|
|
expected_lan_ip: 192.168.1.29
|
|
|
|
vaultwarden:
|
|
ansible_host: 192.168.1.24
|
|
expected_lan_ip: 192.168.1.24
|
|
|
|
gitea:
|
|
ansible_host: 192.168.1.25
|
|
expected_lan_ip: 192.168.1.25
|
|
|
|
memoir-bot:
|
|
ansible_host: 192.168.1.26
|
|
expected_lan_ip: 192.168.1.26
|
|
|
|
mihomo:
|
|
ansible_host: 192.168.1.27
|
|
expected_lan_ip: 192.168.1.27
|
|
|
|
monitoring:
|
|
ansible_host: 192.168.1.30
|
|
expected_lan_ip: 192.168.1.30
|
|
|
|
hermes-ai:
|
|
ansible_host: 192.168.1.31
|
|
expected_lan_ip: 192.168.1.31
|
|
bash_config_proxy_http_url: http://192.168.1.27:7890
|
|
bash_config_proxy_socks_url: socks5h://192.168.1.27:7890
|
|
|
|
emergency-bot:
|
|
ansible_host: 192.168.1.32
|
|
expected_lan_ip: 192.168.1.32
|
|
|
|
grimmory:
|
|
ansible_host: 192.168.1.34
|
|
expected_lan_ip: 192.168.1.34
|
|
|
|
gyro:
|
|
ansible_host: 192.168.1.35
|
|
expected_lan_ip: 192.168.1.35
|
|
|
|
monitoring_exporters:
|
|
hosts:
|
|
ru-vps:
|
|
cloud-pc:
|
|
mini-pc:
|
|
pbs:
|
|
ovpn-mini:
|
|
vaultwarden:
|
|
gitea:
|
|
memoir-bot:
|
|
mihomo:
|
|
adguard:
|
|
monitoring:
|
|
grimmory:
|
|
|
|
monitoring_smart_exporters:
|
|
hosts:
|
|
cloud-pc:
|
|
mini-pc:
|
|
|
|
monitoring_server:
|
|
hosts:
|
|
monitoring:
|
|
|
|
vpn_openvpn:
|
|
hosts:
|
|
ru-vps:
|
|
ovpn-mini:
|
|
|
|
shell_hosts:
|
|
hosts:
|
|
ru-vps:
|
|
cloud-pc:
|
|
mini-pc:
|
|
hermes-ai:
|
|
|
|
servers:
|
|
children:
|
|
homelab:
|
|
pve_nodes:
|
|
lxc_infra:
|