---
cs_vikunja_docker_image: "{{ cs_vm_artifact_registry_containers_home }}/vikunja"
cs_vikunja_docker_tag: "2.7.0"
cs_vikunja_container_name: "vikunja"

cs_vikunja_group: vikunja
cs_vikunja_user: vikunja
cs_vikunja_user_gid: 1990
cs_vikunja_user_uid: 1991
cs_vikunja_server_dns: "{{ __cs_cluster_dns_servers }}"
cs_vikunja_cluster: "{{ cs_cluster_name }}"
cs_vikunja_timezone: Asia/Kolkata

# Single root: everything Vikunja owns lives under here, so one restic call captures it all.
# cs_vikunja_files_dir / cs_vikunja_cert_dir are host-side paths under that root; they are bind
# mounted into the container at the fixed in-container paths /files and /certs.
cs_vikunja_container_root: "/app/vikunja-container-root"
cs_vikunja_files_dir: "{{ cs_vikunja_container_root }}/files"
cs_vikunja_cert_dir: "{{ cs_vikunja_container_root }}/certs"

cs_vikunja_public_uri: "https://vikunja-{{ inventory_hostname }}.{{ __cs_cluster_domain }}"
# Extra origins added to VIKUNJA_CORS_ORIGINS on top of cs_vikunja_public_uri and the per-host
# direct-IP origins (tasks/vikunja/main.yml). Needed when cs_vikunja_public_uri is overridden to
# an internal address (mirroring cs_nc_public_uri/cs_nc_extra_trusted_domains), so the real public
# reverse-proxy domain still passes CORS.
cs_vikunja_extra_cors_origins: []
# The shared SMTP endpoint uses implicit TLS, matching Nextcloud's 'mail_smtpsecure' => 'ssl'
# and qBittorrent's MailNotification\req_ssl. Set false if the endpoint is STARTTLS-only.
cs_vikunja_mailer_force_ssl: true

# CORS is enabled so the API answers both when reached directly (http://<host-ip>:<port>, no
# reverse proxy in front) and via cs_vikunja_public_uri through Nginx Proxy Manager. The actual
# origin list is completed at task-run time in tasks/vikunja/main.yml with the host's live
# addresses, since those aren't known statically here.
cs_vikunja_cors_maxage: 3600
# Trusted so Vikunja reads the real client IP from X-Forwarded-For when reached through the
# reverse proxy (which lives inside this range), while direct connections from outside these
# ranges still resolve to their own TCP address, mirroring cs_nc_trusted_proxies /
# cs_navidrome_local_subnets.
cs_vikunja_trusted_proxies:
    - "{{ __cs_cluster_cidr }}"
    - "{{ __cs_cluster_vpn_cidr }}"

cs_vikunja_db_cluster_name: "{{ cs_vikunja_cluster }}"
cs_vikunja_db_cluster_node: "{{ inventory_hostname }}"
cs_vikunja_db_database: vikunja-{{ inventory_hostname }}

cs_vikunja_restic_cluster_name: "{{ cs_vikunja_cluster }}"
cs_vikunja_restic_node_name: "{{ inventory_hostname }}"
cs_vikunja_restic_repo_name: "vikunja"
