diff --git a/group_vars/all/web_services.yml b/group_vars/all/revers_proxy.yml similarity index 51% rename from group_vars/all/web_services.yml rename to group_vars/all/revers_proxy.yml index 0f1defe..de137b1 100644 --- a/group_vars/all/web_services.yml +++ b/group_vars/all/revers_proxy.yml @@ -1,10 +1,11 @@ --- reverse_proxy_sites: - - {from: wiki.pains-perdus.fr, to: "https://azerty.fil.sand.auro.re:2443"} - - {from: hindley.pains-perdus.fr, to: "http://127.0.0.1:5000"} - - {from: gitea.deso-palaiseau.fr, to: "https://azerty.fil.sand.auro.re:8443"} - - {from: openid.deso-palaiseau.fr, to: "https://azerty.fil.sand.auro.re:7443"} + - {from: wiki.pains-perdus.fr, to: "https://azerty.fil.sand.auro.re:2443"} + - {from: hindley.pains-perdus.fr, to: "http://127.0.0.1:5000"} + - {from: gitea.deso-palaiseau.fr, to: "https://azerty.fil.sand.auro.re:8443"} + - {from: openid.deso-palaiseau.fr, to: "https://azerty.fil.sand.auro.re:7443"} + - {from: "{{ grafana_domain_name }}", to: "http://127.0.0.1:3000"} sharing_sites: - {from: share.deso-palaiseau.fr, folder: "/home/histausse/www", user: histausse, group: histausse} diff --git a/group_vars/all/vars.yml b/group_vars/all/vars.yml index 533dc37..03536be 100644 --- a/group_vars/all/vars.yml +++ b/group_vars/all/vars.yml @@ -7,3 +7,4 @@ dns_resolve_server: 1.1.1.1 appointed_prometheus_server: hindley grafana_admin_password: "{{ vault_grafana_admin_password }}" +grafana_domain_name: monitoring.deso-palaiseau.fr diff --git a/roles/grafana/templates/grafana.ini b/roles/grafana/templates/grafana.ini index d779585..8acbf7e 100644 --- a/roles/grafana/templates/grafana.ini +++ b/roles/grafana/templates/grafana.ini @@ -40,7 +40,7 @@ http_addr = 127.0.0.1 ;http_port = 3000 # The public facing domain name used to access grafana from a browser -;domain = localhost +domain = {{ grafana_domain_name }} # Redirect to correct domain if host header does not match domain # Prevents DNS rebinding attacks @@ -48,7 +48,7 @@ http_addr = 127.0.0.1 # The full public facing url you use in browser, used for redirects and emails # If you use reverse proxy and sub path specify full url (with sub path) -;root_url = %(protocol)s://%(domain)s:%(http_port)s/ +root_url = %(protocol)s://%(domain)s/ # Serve Grafana from subpath specified in `root_url` setting. By default it is set to `false` for compatibility reasons. ;serve_from_sub_path = false @@ -60,7 +60,7 @@ router_logging = true ;static_root_path = public # enable gzip -;enable_gzip = false +enable_gzip = true # https certs & key file ;cert_file =