---
################################ DevOps Server: Vault Keys ################################
__ds_scm_vault_keys: "{{ lookup('vault_lookup', __vault_host_prefix + '/apps/scm/config') }}"
__ds_scm_backup_password: "{{ __ds_scm_vault_keys.backup_password
    | ansible.builtin.mandatory(msg='backup_password is missing from the scm Vault secret.') }}"
__ds_scm_http_port: "{{ __ds_scm_vault_keys.http_port
    | ansible.builtin.mandatory(msg='http_port is missing from the scm Vault secret.')
    | ansible.builtin.int }}"
__ds_scm_ssh_port: "{{ __ds_scm_vault_keys.ssh_port
    | ansible.builtin.mandatory(msg='ssh_port is missing from the scm Vault secret.')
    | ansible.builtin.int }}"
__ds_scm_domain: "{{ ansible_host }}"
__ds_scm_ssh_domain: "{{ __ds_scm_vault_keys.ssh_domain
    | ansible.builtin.mandatory(msg='ssh_domain is missing from the scm Vault secret.') }}"
__ds_scm_root_url: "{{ __ds_scm_vault_keys.root_url
    | ansible.builtin.mandatory(msg='root_url is missing from the scm Vault secret.') }}"
__ds_scm_admin_service_user_username: "{{ __ds_scm_vault_keys.admin_service_user_username
    | ansible.builtin.mandatory(msg='admin_service_user_username is missing from the scm Vault secret.') }}"
__ds_scm_admin_service_user_password: "{{ __ds_scm_vault_keys.admin_service_user_password
    | ansible.builtin.mandatory(msg='admin_service_user_password is missing from the scm Vault secret.') }}"
__ds_scm_admin_service_user_email: "{{ __ds_scm_vault_keys.admin_service_user_email
    | ansible.builtin.mandatory(msg='admin_service_user_email is missing from the scm Vault secret.') }}"
__ds_scm_redis_master_password: "{{ __ds_scm_vault_keys.redis_master_password
    | ansible.builtin.mandatory(msg='redis_master_password is missing from the scm Vault secret.') }}"
__ds_scm_redis_app_password: "{{ __ds_scm_vault_keys.redis_app_password
    | ansible.builtin.mandatory(msg='redis_app_password is missing from the scm Vault secret.') }}"

################################ DevOps Server: Postgres ################################
# Postgres is managed externally; this deployer only ever connects to it as a client.
ds_postgres_app_database: devops-server-scm
__ds_postgres_maintenance_vault_keys: "{{ lookup('vault_lookup', __vault_host_prefix
    + '/apps/postgres/config') }}"
__ds_scm_postgres_maintenance_db: "{{ __ds_postgres_maintenance_vault_keys.maintenance_db
    | ansible.builtin.mandatory(msg='maintenance_db is missing from the postgres Vault secret.') }}"
__ds_scm_postgres_maintenance_user: "{{ __ds_postgres_maintenance_vault_keys.maintenance_user
    | ansible.builtin.mandatory(msg='maintenance_user is missing from the postgres Vault secret.') }}"
__ds_scm_postgres_maintenance_password: "{{ __ds_postgres_maintenance_vault_keys.maintenance_password
    | ansible.builtin.mandatory(msg='maintenance_password is missing from the postgres Vault secret.') }}"

__ds_postgres_user_db_vault_keys: "{{ lookup('vault_lookup', __vault_host_prefix
    + '/apps/postgres/generated-' + ds_postgres_app_database + '-db-credential') }}"
__ds_scm_postgres_host: "{{ __ds_postgres_user_db_vault_keys.host
    | ansible.builtin.mandatory(msg='host is missing from the scm-db-credential Vault secret.') }}"
__ds_scm_postgres_port: "{{ __ds_postgres_user_db_vault_keys.port
    | ansible.builtin.mandatory(msg='port is missing from the scm-db-credential Vault secret.')
    | ansible.builtin.int }}"
__ds_scm_postgres_app_user: "{{ __ds_postgres_user_db_vault_keys.user
    | ansible.builtin.mandatory(msg='user is missing from the scm-db-credential Vault secret.') }}"
__ds_scm_postgres_app_password: "{{ __ds_postgres_user_db_vault_keys.password
    | ansible.builtin.mandatory(msg='password is missing from the scm-db-credential Vault secret.') }}"
__ds_scm_postgres_schema: devops-server-scm-schema

################################ DevOps Server: Internal ################################
__ds_scm_docker_network: devops-server-scm
__ds_scm_app_container_name: devops-server-scm
# https://hub.docker.com/layers/gitea/gitea/28.1.0/images/sha256-f505a0d3a41323b786e05942fc7a4075e07ae7c169fd9485649aa55ee543a21a
__ds_scm_docker_image_reference: "docker.io/gitea\
    /gitea@sha256:f505a0d3a41323b786e05942fc7a4075e07ae7c169fd9485649aa55ee543a21a"
__ds_scm_local_image_tag: localbuild
__ds_scm_app_image_name: devops-server-scm
__ds_scm_app_local_image: "{{ __ds_scm_app_image_name }}:{{ __ds_scm_local_image_tag }}"
__ds_scm_app_container_group: devops-server-scm
__ds_scm_app_container_user: "{{ __ds_scm_app_container_group }}"
__ds_scm_app_container_gid: 2700
__ds_scm_app_container_uid: 2701
__ds_scm_install_directory: /app/devops-server-scm
__ds_scm_cicd_runner_directory: /app/devops-server-scm-cicd-runner

__ds_scm_backup_data_dir: /app/devops-server-scm-backup
__ds_scm_backup_cache_dir: /tmp/devops-server-scm-restic-cache
__ds_scm_backup_systemd_name: devops-server-scm-backup
################################ DevOps Server: Redis ################################
__ds_scm_redis_port: 3660
__ds_scm_redis_app_user: devops_server
__ds_scm_redis_cache_db_index: 13
__ds_scm_redis_session_db_index: 14
# https://hub.docker.com/layers/library/redis/8.10.0-trixie/images/sha256-344e3945a0b431c8ff1eecd58c5573538126bd756f02fc7e218ddf1fc2546366
__ds_scm_redis_image_reference: "docker.io/library/redis@sha256:\
    344e3945a0b431c8ff1eecd58c5573538126bd756f02fc7e218ddf1fc2546366"
__ds_scm_redis_data_dir: /app/devops-server-scm-redis
__ds_scm_redis_container_name: "{{ __ds_scm_app_container_name }}-redis"

################################ DevOps Server: Generated ################################
__vault_ds_scm_generated_keys: "{{ lookup('vault_lookup', __vault_host_prefix
    + '/apps/scm/generated') }}"
__vault_ds_scm_generated_local_url: "{{ __vault_ds_scm_generated_keys.devops_server_local_url }}"
__vault_ds_scm_global_runner_token: "{{ __vault_ds_scm_generated_keys.\
    devops_server_global_runner_token }}"

################################ DevOps Server: CICD Runner ################################
ds_cicd_runner_new_registration: false

################################ DevOps Server: CICD Runner Container ################################
ds_cicd_runner_container_count: 3
ds_cicd_runner_container_cache_port: 44100
__ds_scm_cicd_runner_container_name_prefix: "{{ __ds_scm_app_container_name }}-cicd-runner"
__ds_scm_cicd_runner_image_name: devops-server-scm-cicd-runner
__ds_scm_cicd_runner_local_image: "{{ __ds_scm_cicd_runner_image_name }}:{{ __ds_scm_local_image_tag }}"
# https://hub.docker.com/layers/gitea/runner/5.0.0/images/sha256-328b8dad8de80a19dab6c5c61292c1d624cd3460c25a5c0067e95c11318657ca
__ds_scm_cicd_runner_docker_image_reference: "docker.io/gitea/runner@\
    sha256:328b8dad8de80a19dab6c5c61292c1d624cd3460c25a5c0067e95c11318657ca"

################################ DevOps Server: CICD Runner Systemd ################################
ds_cicd_runner_systemd_cache_port: 44200
__ds_scm_cicd_runner_systemd_name: devops-server-scm-cicd-runner
__ds_scm_cicd_runner_systemd_version: 5.0.0
__ds_scm_cicd_runner_systemd_group: devops-server-scm-cicd-runner
__ds_scm_cicd_runner_systemd_user: "{{ __ds_scm_cicd_runner_systemd_group }}"
__ds_scm_cicd_runner_systemd_user_uid: 2702
__ds_scm_cicd_runner_systemd_user_gid: 2703
__ds_scm_cicd_runner_systemd_home: "{{ __ds_scm_cicd_runner_directory }}/systemd-runner-home"
__ds_scm_cicd_runner_systemd_config_file: "{{ __ds_scm_cicd_runner_systemd_home }}\
    /.config/devops-server-scm-cicd-runner/config.yaml"
__ds_scm_cicd_runner_systemd_bin: "{{ __ds_scm_cicd_runner_systemd_home }}\
    /.local/.bin/devops-server-scm-cicd-runner"
__ds_scm_cicd_runner_systemd_arch_map:
    aarch64: arm64
    x86_64: amd64
__ds_scm_cicd_runner_systemd_checksum_map:
    aarch64: 50de585f1c557aa271b8ea1aad2e1ef31797e2b58c0223d89591c8dc17d900c9
    x86_64: 3201f520b48abd353261b723c1e6b9bb3a82a56cabd4063e58d1fa191bbc50b2
__ds_scm_cicd_runner_systemd_architecture: "{{ __ds_scm_cicd_runner_systemd_arch_map[\
    ansible_facts.architecture] }}"
__ds_scm_cicd_runner_systemd_checksum: "sha256:{{ __ds_scm_cicd_runner_systemd_checksum_map[\
    ansible_facts.architecture] }}"
__ds_scm_cicd_runner_systemd_download_url: "https://gitea.com/gitea/runner/releases/download\
    /v{{ __ds_scm_cicd_runner_systemd_version }}/gitea-runner\
    -{{ __ds_scm_cicd_runner_systemd_version }}\
    -linux-{{ __ds_scm_cicd_runner_systemd_architecture }}"
