config: enable Vault-backed host sudo and correct Titan-24 user

This commit is contained in:
codex 2026-10-04 00:45:34 -05:00
parent 53ad03aeaa
commit 41fd207f68
2 changed files with 10 additions and 2 deletions

View File

@ -29,7 +29,7 @@ ssh_node_hosts:
titan-22: 192.168.22.22 titan-22: 192.168.22.22
titan-24: 192.168.22.26 titan-24: 192.168.22.26
ssh_node_users: ssh_node_users:
titan-24: atlas titan-24: tethys
ssh_managed_nodes: ssh_managed_nodes:
- titan-db - titan-db
- titan-0a - titan-0a
@ -110,6 +110,10 @@ excluded_namespaces:
- postgres - postgres
- maintenance - maintenance
startup: startup:
# Existing Vault CSI synchronization supplies password-backed host actions.
host_sudo_secret_namespace: maintenance
host_sudo_secret_name_template: "ananke-sudo-{node}"
host_sudo_secret_password_key: password
api_wait_seconds: 1200 api_wait_seconds: 1200
api_poll_seconds: 2 api_poll_seconds: 2
shutdown_cooldown_seconds: 45 shutdown_cooldown_seconds: 45

View File

@ -29,7 +29,7 @@ ssh_node_hosts:
titan-22: 192.168.22.22 titan-22: 192.168.22.22
titan-24: 192.168.22.26 titan-24: 192.168.22.26
ssh_node_users: ssh_node_users:
titan-24: atlas titan-24: tethys
ssh_managed_nodes: ssh_managed_nodes:
- titan-db - titan-db
- titan-0a - titan-0a
@ -110,6 +110,10 @@ excluded_namespaces:
- postgres - postgres
- maintenance - maintenance
startup: startup:
# Existing Vault CSI synchronization supplies password-backed host actions.
host_sudo_secret_namespace: maintenance
host_sudo_secret_name_template: "ananke-sudo-{node}"
host_sudo_secret_password_key: password
api_wait_seconds: 1200 api_wait_seconds: 1200
api_poll_seconds: 2 api_poll_seconds: 2
shutdown_cooldown_seconds: 45 shutdown_cooldown_seconds: 45