--- # noble_repo_root / noble_kubeconfig are set in playbooks (use **playbook_dir** magic var). # When kubeconfig points at the API VIP but this workstation cannot reach the lab LAN (VPN off, etc.), # set a reachable control-plane URL — same as: kubectl config set-cluster noble --server=https://:6443 # Example: ansible-playbook playbooks/noble.yml -e 'noble_k8s_api_server_override=https://192.168.50.20:6443' noble_k8s_api_server_override: "" # When /healthz fails with **network unreachable** to the VIP and **override** is empty, retry using this URL (neon). noble_k8s_api_server_auto_fallback: true noble_k8s_api_server_fallback: "https://192.168.50.20:6443" # Only if you must skip the kubectl /healthz preflight (not recommended). noble_skip_k8s_health_check: false # Pangolin / Newt — set true only after newt-pangolin-auth Secret exists (SOPS: clusters/noble/secrets/ or imperative — see clusters/noble/bootstrap/newt/README.md) noble_newt_install: true # cert-manager needs Secret cloudflare-dns-api-token in cert-manager namespace before ClusterIssuers work noble_cert_manager_require_cloudflare_secret: true # Velero — set **noble_velero_install: true** plus S3 bucket/URL (and credentials — see clusters/noble/bootstrap/velero/README.md) noble_velero_install: true # Bootstrap kustomize in Argo (**noble-bootstrap-root** → **clusters/noble/bootstrap**, includes **clusters/noble/apps**). Applied with manual sync; enable automation after **noble.yml** (see **clusters/noble/bootstrap/argocd/README.md** §5). noble_argocd_apply_bootstrap_root_application: true # Authentik (OIDC IdP) + oauth2-proxy ForwardAuth — set **true** after **.env** has NOBLE_AUTHENTIK_* (see ansible/roles/noble_authentik/README.md). noble_authentik_install: true # Optional: public (or extra) Authentik hostnames on the same IdP — list of FQDNs. Pangolin: CNAME + resource → Newt → Traefik (see noble_authentik README). noble_authentik_ingress_extra_hosts: - auth.nikflix.ca noble_authentik_blueprints_enabled: true