Document and commit the production bootstrap state after the initial Hetzner and Ansible rollout. - switch Ansible prod runbooks to use the shared vault password file - record production admin CIDRs, SSH key path, encrypted group vault, and encrypted per-host vault files - add generated production inventory and the prod setup history notes from the first bootstrap - keep root password login disabled while preserving key-based root access for Ansible bootstrap continuity - document separate Hetzner projects and tokens for test/prod and commit the prod provider lock file - remove the private Redis firewall allowance from the prod Terraform firewall and matching setup docs
11 lines
743 B
YAML
11 lines
743 B
YAML
$ANSIBLE_VAULT;1.1;AES256
|
|
63323930326135303866313564613466653934323030376361623034393939633866336430376533
|
|
6462363534393332383738333239656539623531363131300a313938623030363363643964393464
|
|
34306537623534633464343138333637643834346433323036643963383438336138623933303765
|
|
3337313864633233320a626630646434323564363133303639356336633364633361333731353665
|
|
30313761323232343431636361316134343966636631336464353437656331343032643763333931
|
|
61373264653465373539383961333963383962326561336563326133613363636336366339316461
|
|
32386234383935313663306638613439323034386162646330333232303233393866323963313733
|
|
34356637326130666431333131396365333166666530643736303532303165346435306261386238
|
|
66376638353961326537306337363661366339346530346132666639306436313931
|