--- # primary interface is the WAN uplink; pin host identity to the dum0 loopback networking_loopback0_ip: 198.18.2.160 networking_loopback1_ip: 198.18.21.160 # dns: keep the local dnsmasq resolver profiles::dns::base::nameservers: - 127.0.0.1 profiles::dns::base::search: - main.unkin.net profiles::dns::base::primary_interface: dum0 profiles::dns::updater::deny_ranges: - 198.18.199.0/24 - 198.18.200.0/24 - 10.42.0.0/16 - 10.43.0.0/16 - 10.10.12.0/24 # wg0 - 103.216.190.0/23 # wan uplink profiles::consul::client::host_addr: "%{hiera('networking_loopback0_ip')}" # ssh: listen on localhost and dum0 only; knock out the common wan primary ip lookup_options: ssh::server::options: merge: strategy: deep knockout_prefix: '--' ssh::server::options: ListenAddress: - "--%{facts.networking.ip}" - 127.0.0.1 - "%{hiera('networking_loopback0_ip')}" profiles::ssh::sign::principals: - "%{hiera('networking_loopback0_ip')}" # frrouting frrouting::ospfd_router_id: "%{hiera('networking_loopback0_ip')}" frrouting::ospfd_interfaces: dum0: area: 0.0.0.0 dum1: area: 0.0.0.0 bond0.201: area: 0.0.0.0 frrouting::ospf_preferred_source_enable: true frrouting::ospf_preferred_source: "%{hiera('networking_loopback1_ip')}"