Files
configpolicy/hosts
Dustin C. Hatch c300dc1b6c chrony: Add role/PB for chrony
I continually struggle with machines' (physical and virtual, even the
Roku devices!) clocks getting out of sync.  I have been putting off
fixing this because I wanted to set up a Windows-compatible NTP server
(i.e. on the domain controllers, with Kerberos signing), but there's
really no reason to wait for that to fix the clocks on all the
non-Windows machines, especially since there are exactly 0 Windows
machines on the network right now.

The *chrony* role and corresponding `chrony.yml` playbook are generic,
configured via the `chrony_pools`, `chrony_servers`, and `chrony_allow`
variables.  The values for these variables will configure the firewall
to act as an NTP server, synchronizing with the NTP pool on the
Internet, while all other machines will synchronize with it.  This
allows machines on networks without Internet access to keep their clocks
in sync.
2025-03-16 16:37:19 -05:00

250 lines
3.3 KiB
INI

# vim: set ft=dosini :
[all:vars]
ansible_python_interpreter=/usr/bin/python3
[aria2]
file0.pyrocufflink.blue
[bitwarden_rs]
[blackbox-exporter:children]
remote-blackbox
[btop]
chromie.pyrocufflink.blue
[btop:children]
kubelet
[burp-client]
cloud0.pyrocufflink.blue
file0.pyrocufflink.blue
git0.pyrocufflink.blue
[burp-server]
[certbot]
[chrony:children]
kubelet
pyrocufflink
[collectd]
[collectd:children]
kubelet
pyrocufflink
[collectd-prometheus:children]
collectd
[collectd-sensors:children]
raspberry-pi
vm-hosts
[collectd-sensors]
chromie.pyrocufflink.blue
nvr2.pyrocufflink.blue
[dch-proxy]
haproxy0.pyrocufflink.blue
[dch-vpn]
[dhcpcd:children]
vm-hosts
[dhcpd:children]
pyrocufflink-dhcp
[docker]
[docker:children]
bitwarden_rs
[file-servers]
file0.pyrocufflink.blue
[frigate:children]
frigate-prod
frigate-test
[frigate-prod]
nvr2.pyrocufflink.blue
[frigate-test]
[gitea]
git0.pyrocufflink.blue
[graylog]
[hassdb]
[home-assistant]
[jellyfin]
file0.pyrocufflink.blue
[jenkins-slave]
[journal2ntfy:children]
burp-server
[k8s-controller]
k8s-ctrl0.pyrocufflink.blue
[k8s-iot-net-ctrl]
node-474c83.k8s.pyrocufflink.black
[k8s-longhorn]
stor-alfalfa.k8s.pyrocufflink.black
stor-rentable.k8s.pyrocufflink.black
[k8s-node]
node-abreast.k8s.pyrocufflink.black
node-gleaming.k8s.pyrocufflink.black
node-hatbox.k8s.pyrocufflink.black
node-refrain.k8s.pyrocufflink.black
[k8s-node:children]
k8s-longhorn
k8s-iot-net-ctrl
[kubelet:children]
k8s-controller
k8s-node
[loki]
loki1.pyrocufflink.blue
[minio-backups]
chromie.pyrocufflink.blue
[minio:children]
burp-server
minio-backups
[motioneye]
[nfs-client:children]
k8s-node
[no-firewalld:children]
kubelet
[needproxy]
nvr2.pyrocufflink.blue
[networkd]
vmhost0.pyrocufflink.blue
vmhost1.pyrocufflink.blue
[nextcloud]
cloud0.pyrocufflink.blue
[nextcloud-db]
db0.pyrocufflink.blue
[ntpd]
[nut-monitor:children]
vm-hosts
[nut-monitor]
chromie.pyrocufflink.blue
nvr2.pyrocufflink.blue
[postgresql]
db0.pyrocufflink.blue
[public-web]
web0.pyrocufflink.blue
[pxe]
pxe0.pyrocufflink.blue
[pyrocufflink]
chromie.pyrocufflink.blue
cloud0.pyrocufflink.blue
db0.pyrocufflink.blue
dc-grumbly.pyrocufflink.blue
dc-headphone.pyrocufflink.blue
file0.pyrocufflink.blue
git0.pyrocufflink.blue
haproxy0.pyrocufflink.blue
k8s-ctrl0.pyrocufflink.blue
loki1.pyrocufflink.blue
nut1.pyrocufflink.blue
nvr2.pyrocufflink.blue
pxe0.pyrocufflink.blue
smtp1.pyrocufflink.blue
vmhost0.pyrocufflink.blue
vmhost1.pyrocufflink.blue
web0.pyrocufflink.blue
[pyrocufflink-dhcp]
[radius:children]
samba-dc
[raspberry-pi]
node-474c83.k8s.pyrocufflink.black
nut1.pyrocufflink.blue
[remote-blackbox]
vps-04485add.vps.ovh.us
[repohost]
file0.pyrocufflink.blue
[restic]
cloud0.pyrocufflink.blue
file0.pyrocufflink.blue
git0.pyrocufflink.blue
pxe0.pyrocufflink.blue
web0.pyrocufflink.blue
[rw-root]
[samba-dc]
dc-grumbly.pyrocufflink.blue
dc-headphone.pyrocufflink.blue
[serterm]
chromie.pyrocufflink.blue
[smtp-relay]
smtp1.pyrocufflink.blue
[squid]
[sudo:children]
pyrocufflink
vps
[synapse]
[unifi]
[vm-hosts]
vmhost0.pyrocufflink.blue
vmhost1.pyrocufflink.blue
[vmagent:children]
remote-blackbox
[vps]
vps-04485add.vps.ovh.us
[wheelhost]
file0.pyrocufflink.blue
[zezere]
[zigbee2mqtt:children]
home-assistant
[zwavejs2mqtt:children]
home-assistant