You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Add a committed reference inventory file (ansible/inventory.example.yml) showing the exact structure an on-prem/data-centre operator must hand-maintain to run the ansible/{nginx,rke2,rancher-import,nfs,postgresql,activemq,rancher-keycloak-setup} playbooks without any Terraform involvement.
Why
The cloud/CI path generates its Ansible inventory dynamically at runtime (.github/scripts/generate-ansible-inventory.sh → $GITHUB_WORKSPACE/inventory.yml, ephemeral, never committed). The on-prem path was designed around a hand-maintained static inventory instead (per #273's "on-prem needs Ansible as the only tool" decision), but no example of that file exists anywhere in the repo — there's currently no reference for what group names, hostvars, or top-level vars an on-prem deployer needs to supply.
Acceptance Criteria
ansible/inventory.example.yml demonstrates the full shape every role consumes: all.vars (cluster_name, cluster_env_domain, k8s_infra_repo_url, k8s_infra_branch, certbot_email, nginx_type, deployment_type, k8s_node_ips_joined, public_domain_list, k8s_primary_control_plane_ip, ansible_user, ansible_ssh_private_key_file, ansible_ssh_common_args) and children groups (nginx, control_plane, etcd, workers, rke2_cluster)
Demonstrates omitting nginx_public_ip (not just leaving it empty) so the on-prem fallback in ansible/nginx/tasks/main.yml (falls back to ansible_default_ipv4.address) is exercised correctly
node_role values use the hyphenated convention (control-plane/etcd/worker) matching ansible/rke2's task logic
Every variable name cross-checked against each of the 7 roles' defaults/main.yml/tasks/main.yml to avoid drift from the generated (cloud) inventory shape
Part of #273
What
Add a committed reference inventory file (
ansible/inventory.example.yml) showing the exact structure an on-prem/data-centre operator must hand-maintain to run theansible/{nginx,rke2,rancher-import,nfs,postgresql,activemq,rancher-keycloak-setup}playbooks without any Terraform involvement.Why
The cloud/CI path generates its Ansible inventory dynamically at runtime (
.github/scripts/generate-ansible-inventory.sh→$GITHUB_WORKSPACE/inventory.yml, ephemeral, never committed). The on-prem path was designed around a hand-maintained static inventory instead (per #273's "on-prem needs Ansible as the only tool" decision), but no example of that file exists anywhere in the repo — there's currently no reference for what group names, hostvars, or top-level vars an on-prem deployer needs to supply.Acceptance Criteria
ansible/inventory.example.ymldemonstrates the full shape every role consumes:all.vars(cluster_name,cluster_env_domain,k8s_infra_repo_url,k8s_infra_branch,certbot_email,nginx_type,deployment_type,k8s_node_ips_joined,public_domain_list,k8s_primary_control_plane_ip,ansible_user,ansible_ssh_private_key_file,ansible_ssh_common_args) andchildrengroups (nginx,control_plane,etcd,workers,rke2_cluster)nginx_public_ip(not just leaving it empty) so the on-prem fallback inansible/nginx/tasks/main.yml(falls back toansible_default_ipv4.address) is exercised correctlynode_rolevalues use the hyphenated convention (control-plane/etcd/worker) matchingansible/rke2's task logicansible-inventory -i ansible/inventory.example.yml --listdefaults/main.yml/tasks/main.ymlto avoid drift from the generated (cloud) inventory shape