Some checks failed
CI / skip-ci-check (pull_request) Successful in 6s
CI / lint-and-test (pull_request) Failing after 9s
CI / ansible-validation (pull_request) Failing after 6s
CI / secret-scanning (pull_request) Successful in 5s
CI / dependency-scan (pull_request) Successful in 8s
CI / sast-scan (pull_request) Failing after 5s
CI / license-check (pull_request) Successful in 11s
CI / vault-check (pull_request) Failing after 6s
CI / playbook-test (pull_request) Failing after 6s
CI / container-scan (pull_request) Failing after 6s
CI / sonar-analysis (pull_request) Failing after 2s
CI / workflow-summary (pull_request) Successful in 4s
Document pve10 static IPs, monitoring stack, and site LXCs; add portfolio to inventory; Mailcow mailbox automation; vault import/export scripts; security audit guides and UniFi DHCP reference. Co-authored-by: Cursor <cursoragent@cursor.com>
38 lines
1.0 KiB
Plaintext
38 lines
1.0 KiB
Plaintext
# Copy to .env (gitignored): cp .env.example .env
|
|
#
|
|
# vault → .env: make vault-export-env
|
|
# .env → vault: make vault-import-env
|
|
# hosts → vault: make vault-pull-infra-secrets (SSH to monitoring/hermes, then import)
|
|
#
|
|
# Prefer vault for long-term storage; delete .env after export if you want.
|
|
|
|
# Mailcow (make mailcow-mailbox MAILBOX=alerts)
|
|
MAILCOW_API_KEY=
|
|
ALERTS_PASSWORD=
|
|
|
|
# Uptime Kuma @ 10.0.10.22:3001 (scripts/kuma-setup-smtp.sh)
|
|
KUMA_URL=http://10.0.10.22:3001
|
|
KUMA_USER=admin
|
|
KUMA_PASSWORD=
|
|
|
|
# Kuma SMTP notification (after alerts@ mailbox exists)
|
|
SMTP_HOST=mail.levkine.ca
|
|
SMTP_PORT=587
|
|
SMTP_USER=alerts@levkine.ca
|
|
SMTP_PASS=
|
|
SMTP_TO=idobkin@gmail.com
|
|
|
|
# Umami @ 10.0.10.22:3000 (admin UI password; DB pass is on LXC only)
|
|
UMAMI_ADMIN_PASSWORD=
|
|
|
|
# Hermes Mattermost (not Telegram)
|
|
MATTERMOST_URL=
|
|
MATTERMOST_TOKEN=
|
|
MATTERMOST_ALLOWED_USERS=
|
|
|
|
# Optional: same password on Proxmox / LXCs / caddy root (if you use one shared admin password)
|
|
# PROXMOX_PASSWORD=
|
|
# LXC_ROOT_PASSWORD=
|
|
|
|
# Per-mailbox: MAILBOX_notify_PASSWORD=
|