vault: cut over to GCE Raft HA cluster, retire nook.family media stack
- dns-neuralplatform.tf: add vault.neuralplatform.ai A record → 34.54.164.21 (GCP LB) DNS-only (not proxied) so GCP managed TLS cert can provision correctly - main.tf: remove vault.neuralplatform.ai from Cloudflare tunnel ingress (now served directly via GCP Global HTTPS LB) - main.tf: remove watch.nook.family, jellyfin.nook.family, bazarr.nook.family from tunnel ingress (nook.family media stack retired; infra is Neuron-focused) GCE Vault cluster already initialized and running (3-node Raft, active since 2026-05-04T16:05). Secrets migrated 48/48 from k3s vault. ESO ClusterSecretStore validated against new vault. k3s vault-0 is now superseded.
This commit is contained in:
@@ -23,3 +23,16 @@ resource "cloudflare_record" "np_web_stage" {
|
||||
proxied = true
|
||||
ttl = 1
|
||||
}
|
||||
|
||||
# vault.neuralplatform.ai — GCE Raft HA Vault cluster via GCP Global HTTPS LB.
|
||||
# DNS-only (not proxied) — GCP managed TLS cert terminates at the LB.
|
||||
# Vault nodes listen on plain HTTP 8200 internally; LB does TLS.
|
||||
# IP: terraform output vault_lb_ip from servers/gcp workspace = 34.54.164.21
|
||||
resource "cloudflare_record" "np_vault" {
|
||||
zone_id = local.zone_neuralplatform_ai
|
||||
name = "vault"
|
||||
type = "A"
|
||||
content = "34.54.164.21"
|
||||
proxied = false
|
||||
ttl = 60
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user