---
__vault_inventory_host_response: "{{ lookup('vault_kv_get',
    __cs_secrets_path_prefix + '/' + cs_cluster_name + '/hosts/' + inventory_hostname) }}"

cs_vm_dockerd_tcp_socket_port: "{{ __vault_inventory_host_response.dockerd_tcp_port }}"

cs_glances_docker_image: "{{ cs_vm_artifact_registry_containers_home }}/glances"
cs_glances_docker_tag: "ubuntu-4.5.7-full"

# Throwaway image used by the NVIDIA Container Toolkit GPU passthrough check.
cs_patch_nvidia_verify_docker_image: "{{ cs_vm_artifact_registry_containers_home }}/ubuntu"
cs_patch_nvidia_verify_docker_tag: "26.04"
cs_glances_container_name: "glances"
cs_glances_container_root: "/app/glances"
cs_glances_web_api_port: 61208
cs_glances_monitoring_password: "{{ __vault_inventory_host_response.glances_monitoring_password }}"

cs_vm_ssh_service_user_id: "cloudinit"
cs_vm_ssh_service_user_gid: 1996
cs_vm_ssh_service_user_uid: 1997

cs_vm_ssh_service_user_password: "{{ __vault_inventory_host_response.service_password }}"
cs_vm_ssh_service_keyfile: "{{ playbook_dir }}/.ansible/.ssh/id_rsa_home_lab-{{ inventory_hostname }}"
cs_vm_ssh_machine_known_hosts_file: "{{ playbook_dir }}/.ansible/.ssh/known_hosts-{{ inventory_hostname }}"
cs_vm_ssh_machine_public_keys: "{{ __vault_inventory_host_response.public_keys
    | ansible.builtin.default(default_value=[]) }}"

cs_vm_attached_luks_ext4_disks: []

cs_nfs_server_mount: []
cs_nfs_client_mount: []
cs_nfs_server_port: 2049
cs_nfs_server_rpc_port: 111
cs_nfs_server_mountd_port: 20048
cs_nfs_server_statd_port: 32765
cs_nfs_server_lockd_port: 32803
cs_nfs_server_udp: false
cs_nfs_server_tcp: true
cs_nfs_server_vers3: true
cs_nfs_server_vers4: true
cs_nfs_server_vers4_0: true
cs_nfs_server_vers4_1: true
cs_nfs_server_vers4_2: true

__devops_server_inventory_hostname: "{{ lookup('ansible.builtin.env', 'DEVOPS_SERVER_INVENTORY_HOSTNAME',
    errors='strict', default=undef(hint='DEVOPS_SERVER_INVENTORY_HOSTNAME environment variable is not set.'))
    | ansible.builtin.mandatory(msg='DEVOPS_SERVER_INVENTORY_HOSTNAME environment variable is not set.') }}"
__vault_devops_server_details_response: "{{ lookup('vault_kv_get', cs_project_code +
    '/devops-server/hosts/' + __devops_server_inventory_hostname + '/apps/scm/generated') }}"
__devops_server_local_url: "{{ __vault_devops_server_details_response.devops_server_local_url }}"
__devops_server_admin_token: "{{ __vault_devops_server_details_response.devops_server_admin_api_token }}"
__devops_server_user_details: "{{ lookup('ansible.builtin.url', __devops_server_local_url + '/api/v1/user',
    headers={'Authorization': 'token ' + __devops_server_admin_token}, split_lines=False)
    | ansible.builtin.from_json }}"

cs_vm_artifact_registry_schema: "{{ __devops_server_local_url | ansible.builtin.urlsplit(query='scheme') }}"
cs_vm_artifact_registry_netloc: "{{ __devops_server_local_url | ansible.builtin.urlsplit(query='netloc') }}"

cs_vm_artifact_registry_containers_home: "{{ cs_vm_artifact_registry_netloc }}\
    /{{ cs_project_code }}"
cs_vm_artifact_registry_generic_home:
    "{{ cs_vm_artifact_registry_schema }}://{{ cs_vm_artifact_registry_netloc }}/api/packages\
    /{{ cs_project_code }}/generic"

cs_vm_artifact_registry_user: "{{ __devops_server_user_details.username }}"
cs_vm_artifact_registry_password: "{{ __devops_server_admin_token }}"

# Ansible Variables
ansible_host: "{{ __vault_inventory_host_response.host }}"

####################### Check for first time patching #######################
ansible_user: "{{ cs_vm_ssh_service_user_id }}"
ansible_ssh_private_key_file: "{{ cs_vm_ssh_service_keyfile }}"
ansible_become_password: "{{ __vault_inventory_host_response.service_password }}"
ansible_become_method: "sudo"
ansible_ssh_common_args: -o UserKnownHostsFile="{{ cs_vm_ssh_machine_known_hosts_file }}"
####################### Check for first time patching #######################
# ansible_user: "arpan"
# ansible_become_password: "{{ __vault_inventory_host_response.root_password }}"
# ansible_become_method: "su"
# ansible_become_flags: "-"
####################### Check for first time patching #######################

# Why restic and mc is in all group_vars? because all the services needs backup and restore.
# So install restic client and minio client in all the servers. Only the restic client is installed
# right now: the minio client task (Patch | Minio MC) is commented out in playbook.yml.
cs_restic_version: "0.19.1"
cs_restic_bin: "/usr/local/bin/restic"
cs_restic_checksum_map:
    x86_64: sha256:f415415624dcc452f2a02b8c33641791a8c6d6d3b65bbb3543fcf9a25151585c
    aarch64: sha256:a5f64aaab53d51e311fa3829124c5b703f2d14cf187d8640b6be3b2b49376465
cs_restic_download_url: "{{ cs_vm_artifact_registry_generic_home }}/restic/v{{ cs_restic_version }}\
    /restic-v{{ cs_restic_version }}-linux-{{ ansible_facts.architecture }}.bz2"
cs_restic_download_dest: "/tmp/restic_{{ cs_restic_version }}_linux_{{ ansible_facts.architecture }}.bz2"
