Document and commit the production bootstrap state after the initial Hetzner and Ansible rollout. - switch Ansible prod runbooks to use the shared vault password file - record production admin CIDRs, SSH key path, encrypted group vault, and encrypted per-host vault files - add generated production inventory and the prod setup history notes from the first bootstrap - keep root password login disabled while preserving key-based root access for Ansible bootstrap continuity - document separate Hetzner projects and tokens for test/prod and commit the prod provider lock file - remove the private Redis firewall allowance from the prod Terraform firewall and matching setup docs
11 lines
743 B
YAML
11 lines
743 B
YAML
$ANSIBLE_VAULT;1.1;AES256
|
|
38353632326532653638643432336139353565633734653664333531613539316338623764653166
|
|
6565353931643661633462346366376464636262383536640a613535613266653161313936643735
|
|
63316334383663383430353235373434636632613664653730663631643362303635316236383166
|
|
6637633631636232640a336135323636383131303831656362306663396134653132363964353266
|
|
37383137353430326233383562623361663463356238643334323965396430323337653133323063
|
|
37313133623934663537333532636164386263346166623330333164303031373063346164363466
|
|
64373438356430373465666331623930313534633238373330303266313165623364393837643138
|
|
37636138623337393230343363353765343664373230636231633031636363313761346234363865
|
|
38663832646236333263303034656539363339616635353961376439373766663136
|