setup internal CA

This commit is contained in:
Romain Paquet 2026-01-05 21:42:17 +01:00
parent dda8ca5d0f
commit 2063550f93

View file

@ -33,16 +33,17 @@
}; };
}; };
# clan.inventory.instances.certificates = { clan.inventory.instances.certificates = {
# module.name = "certificates"; module.name = "certificates";
# module.input = "clan-core"; module.input = "clan-core";
# roles.ca.machines.verbena = { roles.ca.machines.verbena = {
# settings.acmeEmail = "admin@rpqt.fr"; settings.acmeEmail = "admin@rpqt.fr";
# }; settings.tlds = [ "val" ];
# roles.default.tags.all = { }; };
# roles.default.settings.acmeEmail = "admin@rpqt.fr"; roles.default.tags.all = { };
# }; roles.default.settings.acmeEmail = "admin@rpqt.fr";
};
# Temporarily patched version of clan-core/coredns for AAAA records support # Temporarily patched version of clan-core/coredns for AAAA records support
clan.inventory.instances.coredns = { clan.inventory.instances.coredns = {
@ -57,7 +58,14 @@
settings.ip = "fd28:387a:90:c400:6db2:dfc3:c376:9956"; settings.ip = "fd28:387a:90:c400:6db2:dfc3:c376:9956";
}; };
roles.server.settings = { roles.server.settings = {
tld = "home.rpqt.fr"; tld = "val";
};
roles.default.machines.verbena.settings = {
ip = "fd28:387a:90:c400::1";
services = [
"ca"
];
}; };
roles.default.machines.genepi.settings = { roles.default.machines.genepi.settings = {