aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorGravatar shtlrs <[email protected]>2024-05-14 19:33:33 +0200
committerGravatar jchristgit <[email protected]>2024-05-14 19:40:59 +0200
commit74a2f65514b253764e8dacc22d245f6fdac8a7fe (patch)
tree959eb825b6645d137a4682ae2472d108b4b38fa5
parentadd a handler to reload postgres (diff)
add the db_passwords secrets file
This contains the encrypted passwords for all database users This also moves variables under the /vars/main folder to allow ansible to load all variable folders automatically
-rw-r--r--ansible/roles/postgres/vars/main.yml7
-rw-r--r--ansible/roles/postgres/vars/main/db_passwords.yml12
-rw-r--r--ansible/roles/postgres/vars/main/main.yml12
3 files changed, 24 insertions, 7 deletions
diff --git a/ansible/roles/postgres/vars/main.yml b/ansible/roles/postgres/vars/main.yml
deleted file mode 100644
index 7f482b0..0000000
--- a/ansible/roles/postgres/vars/main.yml
+++ /dev/null
@@ -1,7 +0,0 @@
-postgres_version: "15"
-postgres_daemon: "postgresql@{{ postgres_version }}-main"
-postgres_user: "postgres"
-
-postgres_users: []
-
-postgres_databases: []
diff --git a/ansible/roles/postgres/vars/main/db_passwords.yml b/ansible/roles/postgres/vars/main/db_passwords.yml
new file mode 100644
index 0000000..3c24073
--- /dev/null
+++ b/ansible/roles/postgres/vars/main/db_passwords.yml
@@ -0,0 +1,12 @@
+$ANSIBLE_VAULT;1.1;AES256
+39333066353561633762383262376164306238626636643162643639383233353131663063343062
+3138303730363062326431626536663633663633616537320a306361356639323761666339373834
+64383531613838343931616139636233636466656436656630393634656165323630663930343537
+3437653633386335370a653965656231616632353966383562623261323839353134386562313233
+33353561373866376362356563643265663038303364663164643561313238633435373865373234
+32303439666665333038343236366139353031623934346663363162396330616234383666623938
+38313361613465363539313331306531353766386431373132373465656132613262386639356563
+65346535353734616665663037386363616233666437623466646137663634313666326130623031
+33323933323034396431373638363638663733393836396634393535326635646232396437663362
+36386335386162383866303763346331363737366331663133343164646639343764643033666132
+396532326162303564353831636336323061
diff --git a/ansible/roles/postgres/vars/main/main.yml b/ansible/roles/postgres/vars/main/main.yml
new file mode 100644
index 0000000..8611950
--- /dev/null
+++ b/ansible/roles/postgres/vars/main/main.yml
@@ -0,0 +1,12 @@
+postgres_version: "15"
+postgres_daemon: "postgresql@{{ postgres_version }}-main"
+postgres_user: "postgres"
+
+postgres_users:
+ - name: pinnwand
+ password: "{{ vault_postgres_user_passwords.pinnwand }}"
+
+
+postgres_databases:
+ - name: pinnwand
+ owner: pinnwand