ansible-taler-exchange

Ansible playbook to deploy a production Taler Exchange
Log | Files | Refs | README | LICENSE

commit 36f239d6983a825c2d7a8cd49e4a4d1087953e3f
parent a957b75b5a36f4fde172a93a317442b70a3c6adb
Author: Florian Dold <dold@taler.net>
Date:   Fri, 31 Jul 2026 16:29:19 +0200

use lower_case for all ansible variable names

This matches the ansible conventions and avoids mixing naming
conventions.

Diffstat:
Minventories/group_vars/all/defaults.yml | 4++--
Minventories/group_vars/testing/test-public.yml | 52++++++++++++++++++++++++++--------------------------
Minventories/group_vars/testing/test-secrets.yml | 28++++++++++++++--------------
Minventories/host_vars/fdold-acai-tops/test-public.yml | 58+++++++++++++++++++++++++++++-----------------------------
Minventories/host_vars/fdold-acai-tops/test-secrets.yml | 28++++++++++++++--------------
Minventories/host_vars/podman-localhost/test-public.yml | 54+++++++++++++++++++++++++++---------------------------
Minventories/host_vars/podman-localhost/test-secrets.yml | 28++++++++++++++--------------
Minventories/host_vars/rusty/vars.yml | 86++++++++++++++++++++++++++++++++++++++++----------------------------------------
Minventories/host_vars/spec/vars.yml | 86++++++++++++++++++++++++++++++++++++++++----------------------------------------
Mplaybooks/borg-ssh-export.yml | 2+-
Mplaybooks/borg-start.yml | 4++--
Mplaybooks/setup.yml | 36++++++++++++++++++------------------
Mroles/auditor/templates/etc/nginx/sites-available/auditor-nginx.conf.j2 | 2+-
Mroles/auditor/templates/etc/taler-auditor/conf.d/taler-auditor-master.conf.j2 | 18+++++++++---------
Mroles/borg-start/tasks/main.yml | 4++--
Mroles/borg-start/templates/root/.ssh/config | 4++--
Mroles/borg-start/templates/root/bin/borg-backup.sh | 4++--
Mroles/challenger/tasks/pre-exchange.yml | 6+++---
Mroles/challenger/templates/etc/challenger/challenger-postal.conf.j2 | 4++--
Mroles/challenger/templates/etc/challenger/challenger-sms.conf.j2 | 4++--
Mroles/challenger/templates/etc/challenger/postal-challenger.env.j2 | 6+++---
Mroles/challenger/templates/etc/challenger/sms-challenger.env.j2 | 4++--
Mroles/challenger/templates/etc/taler-exchange/secrets/challenger-email.secret.conf.j2 | 2+-
Mroles/challenger/templates/etc/taler-exchange/secrets/challenger-postal.secret.conf.j2 | 2+-
Mroles/challenger/templates/etc/taler-exchange/secrets/challenger-sms.secret.conf.j2 | 2+-
Mroles/common_packages/tasks/main.yml | 6+++---
Mroles/database/tasks/main.yml | 10+++++-----
Mroles/exchange-sanctionlist-import/tasks/main.yml | 4++--
Mroles/exchange/handlers/main.yml | 4++--
Mroles/exchange/tasks/main.yml | 20++++++++++----------
Mroles/exchange/templates/etc/taler-exchange/conf.d/exchange-business.conf.j2 | 34+++++++++++++++++-----------------
Mroles/exchange/templates/etc/taler-exchange/secrets/exchange-accountcredentials-primary.secret.conf.j2 | 2+-
Mroles/exchange_tops/tasks/main.yml | 2+-
Mroles/exchange_tops/templates/etc/taler-exchange/conf.d/denominations.conf.j2 | 190++++++++++++++++++++++++++++++++++++++++----------------------------------------
Mroles/exchange_tops/templates/etc/taler-exchange/conf.d/kyc-rules.conf.j2 | 2+-
Mroles/exchange_tops/templates/etc/taler-exchange/secrets/exchange-kyc-provider-business.secret.conf.j2 | 6+++---
Mroles/exchange_tops/templates/etc/taler-exchange/secrets/exchange-kyc-provider-individual.secret.conf.j2 | 6+++---
Mroles/exchange_tops/templates/etc/taler-exchange/taler-exchange.env.j2 | 6+++---
Mroles/libeufin-nexus/templates/etc/libeufin/libeufin-nexus-ebics.conf.j2 | 10+++++-----
Mroles/libeufin-nexus/templates/etc/libeufin/libeufin-nexus.conf.j2 | 14+++++++-------
Mroles/libeufin-nexus/templates/etc/nginx/sites-available/nexus-nginx.conf.j2 | 2+-
Mroles/monitoring/templates/etc/alloy/config.alloy | 14+++++++-------
Mroles/monitoring/templates/etc/nginx/sites-available/monitoring-nginx.conf.j2 | 14+++++++-------
Mroles/pixel_borg/tasks/main.yml | 4++--
Msanction-check.sh | 2+-
Msetup-pixel-borg.sh | 2+-
Mstart-borg-backups.sh | 2+-
47 files changed, 442 insertions(+), 442 deletions(-)

diff --git a/inventories/group_vars/all/defaults.yml b/inventories/group_vars/all/defaults.yml @@ -45,7 +45,7 @@ nexus_domain: "nexus.{{ domain_name }}" taler_repo_suites: "{{ ansible_facts['distribution_release'] }}" # Name identifying this host towards the monitoring backends. -TARGET_HOST_NAME: "{{ inventory_hostname }}" +target_host_name: "{{ inventory_hostname }}" # Use letsencrypt by default exchange_use_letsencrypt: true @@ -58,4 +58,4 @@ nexus_use_letsencrypt: true # If no database exists on the target system and this option is 'true', # then a backup must have been provided at the originating host # (you get get it using the 'restore.sh' script). -ENABLE_RESTORE_BACKUP: false +enable_restore_backup: false diff --git a/inventories/group_vars/testing/test-public.yml b/inventories/group_vars/testing/test-public.yml @@ -10,54 +10,54 @@ USE_NIGHTLY: true # Deploy EBICS configuration (true/false). use_ebics: false # Our currency. -CURRENCY: CHF +currency: CHF # Smallest unit of the currency for wire transfers. -CURRENCY_ROUND_UNIT: "CHF:0.01" +currency_round_unit: "CHF:0.01" # Base URL of the exchange REST API -EXCHANGE_BASE_URL: "https://{{ exchange_domain }}/" +exchange_base_url: "https://{{ exchange_domain }}/" # Base URL of the auditor REST API -AUDITOR_BASE_URL: "https://auditor.{{ domain_name }}/" +auditor_base_url: "https://auditor.{{ domain_name }}/" # Exchange offline master public key. -EXCHANGE_MASTER_PUB: GT1ZRF6DT4RAETDEGW3KTWRH15RAKH9T0TK6ZJEYFGRX18B54AK0 +exchange_master_pub: GT1ZRF6DT4RAETDEGW3KTWRH15RAKH9T0TK6ZJEYFGRX18B54AK0 # Auditor offline public key. -AUDITOR_PUB: P6B7ZS7Y1Y12S0VP0PAJ1GQGSHW8RE4NSBTP8PR254J18SK24MH0 +auditor_pub: P6B7ZS7Y1Y12S0VP0PAJ1GQGSHW8RE4NSBTP8PR254J18SK24MH0 # URL with merchants accepting this exchange. -EXCHANGE_SHOPPING_URL: "https://shops.taler-ops.ch/" +exchange_shopping_url: "https://shops.taler-ops.ch/" # Name of Terms of service resource file -EXCHANGE_TERMS_ETAG: "exchange-tos-v0" +exchange_terms_etag: "exchange-tos-v0" # Name of Privacy policy resource file -EXCHANGE_PP_ETAG: "exchange-pp-v0" +exchange_pp_etag: "exchange-pp-v0" # Full BIC of exchange account -EXCHANGE_BANK_ACCOUNT_BIC: "MAEBCHZZ" +exchange_bank_account_bic: "MAEBCHZZ" # Full Payto URI of exchange account (for credit and debit) -EXCHANGE_BANK_ACCOUNT_IBAN: "CH6808573105529100001" +exchange_bank_account_iban: "CH6808573105529100001" # Full Payto URI of exchange account (for credit and debit) -EXCHANGE_BANK_ACCOUNT_PAYTO: "payto://iban/{{ EXCHANGE_BANK_ACCOUNT_IBAN }}?receiver-name=Taler+Operations+AG" +exchange_bank_account_payto: "payto://iban/{{ exchange_bank_account_iban }}?receiver-name=Taler+Operations+AG" # Port to be used by libeufin-nexus for the taler-exchange-wire-gateway -LIBEUFIN_PORT: 8082 +libeufin_port: 8082 # Name of the exchange account at libeufin-nexus LIBEUFIN_EXCHANGE_ACCOUNT: "exchange" # Name of the bank dialect -LIBEUFIN_NEXUS_BANK_DIALECT: "maerki_baumann" +libeufin_nexus_bank_dialect: "maerki_baumann" # SPA dialect (tops, gls, magnet, ...) -EXCHANGE_SPA_DIALECT: "tops" +exchange_spa_dialect: "tops" # Business name of the exchange operator -EXCHANGE_OPERATOR_LEGAL_NAME: "Taler Operations AG" +exchange_operator_legal_name: "Taler Operations AG" # Where to send people after they passed KYC. -KYC_THANK_YOU_URL: https://taler-ops.ch/thank-you-kyc.html +kyc_thank_you_url: https://taler-ops.ch/thank-you-kyc.html # Template to use for identification of individuals with KYCAID -KYCAID_TEMPLATE_INDIVIDUAL: tmpl_xxx +kycaid_template_individual: tmpl_xxx # Template to use for identification of businesses with KYCAID -KYCAID_TEMPLATE_BUSINESS: tmpl_xxx +kycaid_template_business: tmpl_xxx # Regex specifying allowed phone numbers for the SMS check -EXCHANGE_AML_PROGRAM_TOPS_SMS_HINT: "Swiss number required" -EXCHANGE_AML_PROGRAM_TOPS_SMS_EXAMPLE: "+41948224521" -EXCHANGE_AML_PROGRAM_TOPS_SMS_REGEX: "\\\\+41[0-9]+" +exchange_aml_program_tops_sms_hint: "Swiss number required" +exchange_aml_program_tops_sms_example: "+41948224521" +exchange_aml_program_tops_sms_regex: "\\\\+41[0-9]+" # Regex specifying allowed country names for the postal address check -EXCHANGE_AML_PROGRAM_TOPS_POSTAL_COUNTRY_HINT: "Swiss address required" -EXCHANGE_AML_PROGRAM_TOPS_POSTAL_EXAMPLE: "Max Mustermann\\nBahnhofsplatz 1\\n4201 Biel/Bienne" -EXCHANGE_AML_PROGRAM_TOPS_POSTAL_COUNTRY_REGEX: "CH|Ch|ch" +exchange_aml_program_tops_postal_country_hint: "Swiss address required" +exchange_aml_program_tops_postal_example: "Max Mustermann\\nBahnhofsplatz 1\\n4201 Biel/Bienne" +exchange_aml_program_tops_postal_country_regex: "CH|Ch|ch" # Let exchange error messages include the full challenger response. challenger_oauth2_debug_mode: "YES" # Tool to use for sanction list checking -EXCHANGE_SANCTION_HELPER: taler-exchange-helper-sanctions-dummy +exchange_sanction_helper: taler-exchange-helper-sanctions-dummy diff --git a/inventories/group_vars/testing/test-secrets.yml b/inventories/group_vars/testing/test-secrets.yml @@ -1,31 +1,31 @@ --- # Symmetric encryption secret for KYC attribute encryption. -EXCHANGE_ATTRIBUTE_ENCRYPTION_KEY: SECRET2 +exchange_attribute_encryption_key: SECRET2 # EBICS access details -LIBEUFIN_NEXUS_EBICS_HOST_BASE_URL: https://isotest.postfinance.ch/ebicsweb/ebicsweb -LIBEUFIN_NEXUS_EBICS_HOST_ID: PFEBICS -LIBEUFIN_NEXUS_EBICS_USER_ID: PFC00664 -LIBEUFIN_NEXUS_EBICS_PARTNER_ID: PFC00664 -LIBEUFIN_NEXUS_EBICS_SYSTEM_ID: PFC00664 +libeufin_nexus_ebics_host_base_url: https://isotest.postfinance.ch/ebicsweb/ebicsweb +libeufin_nexus_ebics_host_id: PFEBICS +libeufin_nexus_ebics_user_id: PFC00664 +libeufin_nexus_ebics_partner_id: PFC00664 +libeufin_nexus_ebics_system_id: PFC00664 # Authorization token for the telesign SMS service -SMS_CHALLENGER_TELESIGN_AUTH_TOKEN: my-auth-token +sms_challenger_telesign_auth_token: my-auth-token sms_challenger_clicksend_api_key: my-auth-token sms_challenger_clicksend_username: my-clicksend-user # Authorization data for the pingen postal service -POSTAL_CHALLENGER_PINGEN_CLIENT_ID: myid -POSTAL_CHALLENGER_PINGEN_CLIENT_SECRET: mysecret -POSTAL_CHALLENGER_PINGEN_ORG_ID: orgid +postal_challenger_pingen_client_id: myid +postal_challenger_pingen_client_secret: mysecret +postal_challenger_pingen_org_id: orgid # KYCaid access token -EXCHANGE_KYCAID_ACCESS_TOKEN: FIXME +exchange_kycaid_access_token: FIXME # Bearer access token for the auditor -AUDITOR_ACCESS_TOKEN: secret-token:FIXME +auditor_access_token: secret-token:FIXME # Bearer access token for monitoring -PROMETHEUS_ACCESS_TOKEN: secret-token:FIXME +prometheus_access_token: secret-token:FIXME # Bearer access token for loki.taler-systems.com -LOKI_ACCESS_TOKEN: secret-token:FIXME +loki_access_token: secret-token:FIXME diff --git a/inventories/host_vars/fdold-acai-tops/test-public.yml b/inventories/host_vars/fdold-acai-tops/test-public.yml @@ -1,70 +1,70 @@ --- # Pregenerated dhparam.pem is less secure but significantly faster. -USE_PREGENERATED_DHPARAM: true +use_pregenerated_dhparam: true # Deploy challenger? deploy_challenger: true # High-level kind of deployment. # Other customizations depend on this. # Can be "gls" or "tops" (later: "magnet") -DEPLOYMENT_KIND: "tops" +deployment_kind: "tops" # Main domain name. domain_name: "topstest.fdold.eu" exchange_domain: "exchange.{{ domain_name }}" # Our internal hostname -TARGET_HOST_NAME: "acai.box.fdold.eu" +target_host_name: "acai.box.fdold.eu" # Use nightly Taler distro (true/false). USE_NIGHTLY: true # Deploy EBICS configuration (true/false). use_ebics: false # Our currency. -CURRENCY: CHF +currency: CHF # Smallest unit of the currency for wire transfers. -CURRENCY_ROUND_UNIT: "CHF:0.01" +currency_round_unit: "CHF:0.01" # Base URL of the exchange REST API -EXCHANGE_BASE_URL: "https://exchange.{{ domain_name }}/" +exchange_base_url: "https://exchange.{{ domain_name }}/" # Base URL of the auditor REST API -AUDITOR_BASE_URL: "https://auditor.{{ domain_name }}/" +auditor_base_url: "https://auditor.{{ domain_name }}/" # Exchange offline master public key. -EXCHANGE_MASTER_PUB: GT1ZRF6DT4RAETDEGW3KTWRH15RAKH9T0TK6ZJEYFGRX18B54AK0 +exchange_master_pub: GT1ZRF6DT4RAETDEGW3KTWRH15RAKH9T0TK6ZJEYFGRX18B54AK0 # Auditor offline public key. -AUDITOR_PUB: P6B7ZS7Y1Y12S0VP0PAJ1GQGSHW8RE4NSBTP8PR254J18SK24MH0 +auditor_pub: P6B7ZS7Y1Y12S0VP0PAJ1GQGSHW8RE4NSBTP8PR254J18SK24MH0 # URL with merchants accepting this exchange. -EXCHANGE_SHOPPING_URL: "https://shops.taler-ops.ch/" +exchange_shopping_url: "https://shops.taler-ops.ch/" # Name of Terms of service resource file -EXCHANGE_TERMS_ETAG: "exchange-tos-v0" +exchange_terms_etag: "exchange-tos-v0" # Name of Privacy policy resource file -EXCHANGE_PP_ETAG: "exchange-pp-v0" +exchange_pp_etag: "exchange-pp-v0" # Full BIC of exchange account -EXCHANGE_BANK_ACCOUNT_BIC: "MAEBCHZZ" +exchange_bank_account_bic: "MAEBCHZZ" # Full Payto URI of exchange account (for credit and debit) -EXCHANGE_BANK_ACCOUNT_IBAN: "CH6808573105529100001" +exchange_bank_account_iban: "CH6808573105529100001" # Full Payto URI of exchange account (for credit and debit) -EXCHANGE_BANK_ACCOUNT_PAYTO: "payto://iban/{{ EXCHANGE_BANK_ACCOUNT_IBAN }}?receiver-name=Taler+Operations+AG" +exchange_bank_account_payto: "payto://iban/{{ exchange_bank_account_iban }}?receiver-name=Taler+Operations+AG" # Port to be used by libeufin-nexus for the taler-exchange-wire-gateway -LIBEUFIN_PORT: 8082 +libeufin_port: 8082 # Name of the exchange account at libeufin-nexus LIBEUFIN_EXCHANGE_ACCOUNT: "exchange" # Name of the bank dialect -LIBEUFIN_NEXUS_BANK_DIALECT: "maerki_baumann" +libeufin_nexus_bank_dialect: "maerki_baumann" # SPA dialect (tops, gls, magnet, ...) -EXCHANGE_SPA_DIALECT: "tops" +exchange_spa_dialect: "tops" # Business name of the exchange operator -EXCHANGE_OPERATOR_LEGAL_NAME: "Taler Operations AG" +exchange_operator_legal_name: "Taler Operations AG" # Where to send people after they passed KYC. -KYC_THANK_YOU_URL: https://taler-ops.ch/thank-you-kyc.html +kyc_thank_you_url: https://taler-ops.ch/thank-you-kyc.html # Template to use for identification of individuals with KYCAID -KYCAID_TEMPLATE_INDIVIDUAL: tmpl_xxx +kycaid_template_individual: tmpl_xxx # Template to use for identification of businesses with KYCAID -KYCAID_TEMPLATE_BUSINESS: tmpl_xxx +kycaid_template_business: tmpl_xxx # Regex specifying allowed phone numbers for the SMS check -EXCHANGE_AML_PROGRAM_TOPS_SMS_HINT: "Swiss number required" -EXCHANGE_AML_PROGRAM_TOPS_SMS_EXAMPLE: "+41948224521" -EXCHANGE_AML_PROGRAM_TOPS_SMS_REGEX: "\\\\+41[0-9]+" +exchange_aml_program_tops_sms_hint: "Swiss number required" +exchange_aml_program_tops_sms_example: "+41948224521" +exchange_aml_program_tops_sms_regex: "\\\\+41[0-9]+" # Regex specifying allowed country names for the postal address check -EXCHANGE_AML_PROGRAM_TOPS_POSTAL_COUNTRY_HINT: "Swiss address required" -EXCHANGE_AML_PROGRAM_TOPS_POSTAL_EXAMPLE: "Max Mustermann\\nBahnhofsplatz 1\\n4201 Biel/Bienne" -EXCHANGE_AML_PROGRAM_TOPS_POSTAL_COUNTRY_REGEX: "CH|Ch|ch" +exchange_aml_program_tops_postal_country_hint: "Swiss address required" +exchange_aml_program_tops_postal_example: "Max Mustermann\\nBahnhofsplatz 1\\n4201 Biel/Bienne" +exchange_aml_program_tops_postal_country_regex: "CH|Ch|ch" # Let exchange error messages include the full challenger response. challenger_oauth2_debug_mode: "YES" # Tool to use for sanction list checking -EXCHANGE_SANCTION_HELPER: taler-exchange-helper-sanctions-dummy +exchange_sanction_helper: taler-exchange-helper-sanctions-dummy diff --git a/inventories/host_vars/fdold-acai-tops/test-secrets.yml b/inventories/host_vars/fdold-acai-tops/test-secrets.yml @@ -1,30 +1,30 @@ --- # We're the secrets file! # Symmetric encryption secret for KYC attribute encryption. -EXCHANGE_ATTRIBUTE_ENCRYPTION_KEY: SECRET2 +exchange_attribute_encryption_key: SECRET2 # EBICS access details -LIBEUFIN_NEXUS_EBICS_HOST_BASE_URL: https://isotest.postfinance.ch/ebicsweb/ebicsweb -LIBEUFIN_NEXUS_EBICS_HOST_ID: PFEBICS -LIBEUFIN_NEXUS_EBICS_USER_ID: PFC00664 -LIBEUFIN_NEXUS_EBICS_PARTNER_ID: PFC00664 -LIBEUFIN_NEXUS_EBICS_SYSTEM_ID: PFC00664 +libeufin_nexus_ebics_host_base_url: https://isotest.postfinance.ch/ebicsweb/ebicsweb +libeufin_nexus_ebics_host_id: PFEBICS +libeufin_nexus_ebics_user_id: PFC00664 +libeufin_nexus_ebics_partner_id: PFC00664 +libeufin_nexus_ebics_system_id: PFC00664 # Authorization token for the telesign SMS service -SMS_CHALLENGER_TELESIGN_AUTH_TOKEN: my-auth-token +sms_challenger_telesign_auth_token: my-auth-token # Authorization data for the pingen postal service -POSTAL_CHALLENGER_PINGEN_CLIENT_ID: myid -POSTAL_CHALLENGER_PINGEN_CLIENT_SECRET: mysecret -POSTAL_CHALLENGER_PINGEN_ORG_ID: orgid +postal_challenger_pingen_client_id: myid +postal_challenger_pingen_client_secret: mysecret +postal_challenger_pingen_org_id: orgid # KYCaid access token -EXCHANGE_KYCAID_ACCESS_TOKEN: FIXME +exchange_kycaid_access_token: FIXME # Bearer access token for the auditor -AUDITOR_ACCESS_TOKEN: secret-token:FIXME +auditor_access_token: secret-token:FIXME # Bearer access token for monitoring -PROMETHEUS_ACCESS_TOKEN: secret-token:FIXME +prometheus_access_token: secret-token:FIXME # Bearer access token for loki.taler-systems.com -LOKI_ACCESS_TOKEN: secret-token:FIXME +loki_access_token: secret-token:FIXME diff --git a/inventories/host_vars/podman-localhost/test-public.yml b/inventories/host_vars/podman-localhost/test-public.yml @@ -3,7 +3,7 @@ # High-level kind of deployment. # Other customizations depend on this. # Can be "gls" or "tops" (later: "magnet") -DEPLOYMENT_KIND: "tops" +deployment_kind: "tops" # Main domain name. domain_name: "topstest.fdold.eu" exchange_domain: "exchange.{{ domain_name }}" @@ -12,52 +12,52 @@ USE_NIGHTLY: true # Deploy EBICS configuration (true/false). use_ebics: false # Our currency. -CURRENCY: CHF +currency: CHF # Smallest unit of the currency for wire transfers. -CURRENCY_ROUND_UNIT: "CHF:0.01" +currency_round_unit: "CHF:0.01" # Base URL of the exchange REST API -EXCHANGE_BASE_URL: "https://exchange.{{ domain_name }}/" +exchange_base_url: "https://exchange.{{ domain_name }}/" # Base URL of the auditor REST API -AUDITOR_BASE_URL: "https://auditor.{{ domain_name }}/" +auditor_base_url: "https://auditor.{{ domain_name }}/" # Exchange offline master public key. -EXCHANGE_MASTER_PUB: GT1ZRF6DT4RAETDEGW3KTWRH15RAKH9T0TK6ZJEYFGRX18B54AK0 +exchange_master_pub: GT1ZRF6DT4RAETDEGW3KTWRH15RAKH9T0TK6ZJEYFGRX18B54AK0 # Auditor offline public key. -AUDITOR_PUB: P6B7ZS7Y1Y12S0VP0PAJ1GQGSHW8RE4NSBTP8PR254J18SK24MH0 +auditor_pub: P6B7ZS7Y1Y12S0VP0PAJ1GQGSHW8RE4NSBTP8PR254J18SK24MH0 # URL with merchants accepting this exchange. -EXCHANGE_SHOPPING_URL: "https://shops.taler-ops.ch/" +exchange_shopping_url: "https://shops.taler-ops.ch/" # Name of Terms of service resource file -EXCHANGE_TERMS_ETAG: "exchange-tos-v0" +exchange_terms_etag: "exchange-tos-v0" # Name of Privacy policy resource file -EXCHANGE_PP_ETAG: "exchange-pp-v0" +exchange_pp_etag: "exchange-pp-v0" # Full BIC of exchange account -EXCHANGE_BANK_ACCOUNT_BIC: "MAEBCHZZ" +exchange_bank_account_bic: "MAEBCHZZ" # Full Payto URI of exchange account (for credit and debit) -EXCHANGE_BANK_ACCOUNT_IBAN: "CH6808573105529100001" +exchange_bank_account_iban: "CH6808573105529100001" # Full Payto URI of exchange account (for credit and debit) -EXCHANGE_BANK_ACCOUNT_PAYTO: "payto://iban/{{ EXCHANGE_BANK_ACCOUNT_IBAN }}?receiver-name=Taler+Operations+AG" +exchange_bank_account_payto: "payto://iban/{{ exchange_bank_account_iban }}?receiver-name=Taler+Operations+AG" # Port to be used by libeufin-nexus for the taler-exchange-wire-gateway -LIBEUFIN_PORT: 8082 +libeufin_port: 8082 # Name of the exchange account at libeufin-nexus LIBEUFIN_EXCHANGE_ACCOUNT: "exchange" # Name of the bank dialect -LIBEUFIN_NEXUS_BANK_DIALECT: "maerki_baumann" +libeufin_nexus_bank_dialect: "maerki_baumann" # SPA dialect (tops, gls, magnet, ...) -EXCHANGE_SPA_DIALECT: "tops" +exchange_spa_dialect: "tops" # Business name of the exchange operator -EXCHANGE_OPERATOR_LEGAL_NAME: "Taler Operations AG" +exchange_operator_legal_name: "Taler Operations AG" # Where to send people after they passed KYC. -KYC_THANK_YOU_URL: https://taler-ops.ch/thank-you-kyc.html +kyc_thank_you_url: https://taler-ops.ch/thank-you-kyc.html # Template to use for identification of individuals with KYCAID -KYCAID_TEMPLATE_INDIVIDUAL: tmpl_xxx +kycaid_template_individual: tmpl_xxx # Template to use for identification of businesses with KYCAID -KYCAID_TEMPLATE_BUSINESS: tmpl_xxx +kycaid_template_business: tmpl_xxx # Regex specifying allowed phone numbers for the SMS check -EXCHANGE_AML_PROGRAM_TOPS_SMS_HINT: "Swiss number required" -EXCHANGE_AML_PROGRAM_TOPS_SMS_EXAMPLE: "+41948224521" -EXCHANGE_AML_PROGRAM_TOPS_SMS_REGEX: "\\\\+41[0-9]+" +exchange_aml_program_tops_sms_hint: "Swiss number required" +exchange_aml_program_tops_sms_example: "+41948224521" +exchange_aml_program_tops_sms_regex: "\\\\+41[0-9]+" # Regex specifying allowed country names for the postal address check -EXCHANGE_AML_PROGRAM_TOPS_POSTAL_COUNTRY_HINT: "Swiss address required" -EXCHANGE_AML_PROGRAM_TOPS_POSTAL_EXAMPLE: "Max Mustermann\\nBahnhofsplatz 1\\n4201 Biel/Bienne" -EXCHANGE_AML_PROGRAM_TOPS_POSTAL_COUNTRY_REGEX: "CH|Ch|ch" +exchange_aml_program_tops_postal_country_hint: "Swiss address required" +exchange_aml_program_tops_postal_example: "Max Mustermann\\nBahnhofsplatz 1\\n4201 Biel/Bienne" +exchange_aml_program_tops_postal_country_regex: "CH|Ch|ch" # Tool to use for sanction list checking -EXCHANGE_SANCTION_HELPER: taler-exchange-helper-sanctions-dummy +exchange_sanction_helper: taler-exchange-helper-sanctions-dummy diff --git a/inventories/host_vars/podman-localhost/test-secrets.yml b/inventories/host_vars/podman-localhost/test-secrets.yml @@ -1,30 +1,30 @@ --- # We are the secrets file! # Symmetric encryption secret for KYC attribute encryption. -EXCHANGE_ATTRIBUTE_ENCRYPTION_KEY: SECRET2 +exchange_attribute_encryption_key: SECRET2 # EBICS access details -LIBEUFIN_NEXUS_EBICS_HOST_BASE_URL: https://isotest.postfinance.ch/ebicsweb/ebicsweb -LIBEUFIN_NEXUS_EBICS_HOST_ID: PFEBICS -LIBEUFIN_NEXUS_EBICS_USER_ID: PFC00664 -LIBEUFIN_NEXUS_EBICS_PARTNER_ID: PFC00664 -LIBEUFIN_NEXUS_EBICS_SYSTEM_ID: PFC00664 +libeufin_nexus_ebics_host_base_url: https://isotest.postfinance.ch/ebicsweb/ebicsweb +libeufin_nexus_ebics_host_id: PFEBICS +libeufin_nexus_ebics_user_id: PFC00664 +libeufin_nexus_ebics_partner_id: PFC00664 +libeufin_nexus_ebics_system_id: PFC00664 # Authorization token for the telesign SMS service -SMS_CHALLENGER_TELESIGN_AUTH_TOKEN: my-auth-token +sms_challenger_telesign_auth_token: my-auth-token # Authorization data for the pingen postal service -POSTAL_CHALLENGER_PINGEN_CLIENT_ID: myid -POSTAL_CHALLENGER_PINGEN_CLIENT_SECRET: mysecret -POSTAL_CHALLENGER_PINGEN_ORG_ID: orgid +postal_challenger_pingen_client_id: myid +postal_challenger_pingen_client_secret: mysecret +postal_challenger_pingen_org_id: orgid # KYCaid access token -EXCHANGE_KYCAID_ACCESS_TOKEN: FIXME +exchange_kycaid_access_token: FIXME # Bearer access token for the auditor -AUDITOR_ACCESS_TOKEN: secret-token:FIXME +auditor_access_token: secret-token:FIXME # Bearer access token for monitoring -PROMETHEUS_ACCESS_TOKEN: secret-token:FIXME +prometheus_access_token: secret-token:FIXME # Bearer access token for loki.taler-systems.com -LOKI_ACCESS_TOKEN: secret-token:FIXME +loki_access_token: secret-token:FIXME diff --git a/inventories/host_vars/rusty/vars.yml b/inventories/host_vars/rusty/vars.yml @@ -1,70 +1,70 @@ # What environment are we deploying? -DEPLOYMENT_KIND: "tops" +deployment_kind: "tops" # Public variables for a "test" deployment # Deploy challenger? deploy_challenger: true # Main external domain name. domain_name: "stage.taler-ops.ch" # Our internal hostname -TARGET_HOST_NAME: "rusty.taler-ops.ch" +target_host_name: "rusty.taler-ops.ch" # Suite for taler packages. taler_repo_suites: trixie-testing # Deploy EBICS configuration (true/false). use_ebics: false # Our currency. -CURRENCY: CHF +currency: CHF # Smallest unit of the currency for wire transfers. -CURRENCY_ROUND_UNIT: "CHF:0.01" +currency_round_unit: "CHF:0.01" # Sanction list to use, comment out to disable -SANCTION_LIST: sanctions-swiss.json +sanction_list: sanctions-swiss.json # Base URL of the exchange REST API -EXCHANGE_BASE_URL: "https://exchange.{{ domain_name }}/" +exchange_base_url: "https://exchange.{{ domain_name }}/" # Base URL of the auditor REST API -AUDITOR_BASE_URL: "https://auditor.{{ domain_name }}/" +auditor_base_url: "https://auditor.{{ domain_name }}/" # Exchange offline master public key. -EXCHANGE_MASTER_PUB: GT1ZRF6DT4RAETDEGW3KTWRH15RAKH9T0TK6ZJEYFGRX18B54AK0 +exchange_master_pub: GT1ZRF6DT4RAETDEGW3KTWRH15RAKH9T0TK6ZJEYFGRX18B54AK0 # Auditor offline public key. -AUDITOR_PUB: P6B7ZS7Y1Y12S0VP0PAJ1GQGSHW8RE4NSBTP8PR254J18SK24MH0 +auditor_pub: P6B7ZS7Y1Y12S0VP0PAJ1GQGSHW8RE4NSBTP8PR254J18SK24MH0 # URL with merchants accepting this exchange. -EXCHANGE_SHOPPING_URL: "https://shops.taler-ops.ch/" +exchange_shopping_url: "https://shops.taler-ops.ch/" # Name of Terms of service resource file -EXCHANGE_TERMS_ETAG: "exchange-tos-v0" +exchange_terms_etag: "exchange-tos-v0" # Name of Privacy policy resource file -EXCHANGE_PP_ETAG: "exchange-pp-v0" +exchange_pp_etag: "exchange-pp-v0" # Full BIC of exchange account -EXCHANGE_BANK_ACCOUNT_BIC: "MAEBCHZZ" +exchange_bank_account_bic: "MAEBCHZZ" # Full Payto URI of exchange account (for credit and debit) -EXCHANGE_BANK_ACCOUNT_IBAN: "CH6808573105529100001" +exchange_bank_account_iban: "CH6808573105529100001" # QR IBAN for prepared transfers exchange_qr_iban: "CH1130000001166556117" # Full Payto URI of exchange account (for credit and debit) -EXCHANGE_BANK_ACCOUNT_PAYTO: "payto://iban/{{ EXCHANGE_BANK_ACCOUNT_IBAN }}?receiver-name=Taler+Operations+AG" +exchange_bank_account_payto: "payto://iban/{{ exchange_bank_account_iban }}?receiver-name=Taler+Operations+AG" # Port to be used by libeufin-nexus for the taler-exchange-wire-gateway -LIBEUFIN_PORT: 8082 +libeufin_port: 8082 # Name of the exchange account at libeufin-nexus LIBEUFIN_EXCHANGE_ACCOUNT: "exchange" # Name of the bank dialect -LIBEUFIN_NEXUS_BANK_DIALECT: "maerki_baumann" +libeufin_nexus_bank_dialect: "maerki_baumann" # SPA dialect (tops, gls, magnet, ...) -EXCHANGE_SPA_DIALECT: "tops" +exchange_spa_dialect: "tops" # Business name of the exchange operator -EXCHANGE_OPERATOR_LEGAL_NAME: "Taler Operations AG" +exchange_operator_legal_name: "Taler Operations AG" # Where to send people after they passed KYC. -KYC_THANK_YOU_URL: https://taler-ops.ch/thank-you-kyc.html +kyc_thank_you_url: https://taler-ops.ch/thank-you-kyc.html # Template to use for identification of individuals with KYCAID -KYCAID_TEMPLATE_INDIVIDUAL: tmpl_xxx +kycaid_template_individual: tmpl_xxx # Template to use for identification of businesses with KYCAID -KYCAID_TEMPLATE_BUSINESS: tmpl_xxx +kycaid_template_business: tmpl_xxx # Regex specifying allowed phone numbers for the SMS check -EXCHANGE_AML_PROGRAM_TOPS_SMS_HINT: "Swiss number required" -EXCHANGE_AML_PROGRAM_TOPS_SMS_EXAMPLE: "+41948224521" -EXCHANGE_AML_PROGRAM_TOPS_SMS_REGEX: "\\\\+41[0-9]+" +exchange_aml_program_tops_sms_hint: "Swiss number required" +exchange_aml_program_tops_sms_example: "+41948224521" +exchange_aml_program_tops_sms_regex: "\\\\+41[0-9]+" # Regex specifying allowed country names for the postal address check -EXCHANGE_AML_PROGRAM_TOPS_POSTAL_COUNTRY_HINT: "Swiss address required" -EXCHANGE_AML_PROGRAM_TOPS_POSTAL_EXAMPLE: "Max Mustermann\\nBahnhofsplatz 1\\n4201 Biel/Bienne" -EXCHANGE_AML_PROGRAM_TOPS_POSTAL_COUNTRY_REGEX: "CH|Ch|ch" +exchange_aml_program_tops_postal_country_hint: "Swiss address required" +exchange_aml_program_tops_postal_example: "Max Mustermann\\nBahnhofsplatz 1\\n4201 Biel/Bienne" +exchange_aml_program_tops_postal_country_regex: "CH|Ch|ch" # Tool to use for sanction list checking -EXCHANGE_SANCTION_HELPER: taler-exchange-helper-sanctions-dummy +exchange_sanction_helper: taler-exchange-helper-sanctions-dummy # If set to true, set up an additional user to allow faking wire transfers and # inspecting challenger auth codes. @@ -89,34 +89,34 @@ devtesting_ssh_keys: # $ ansible-vault edit inventories/host_vars/rusty/vault.yml # to decrease the likelihood of unencrypted secrets ending up in git. # Symmetric encryption secret for KYC attribute encryption. -EXCHANGE_ATTRIBUTE_ENCRYPTION_KEY: "{{ vault_exchange_attribute_encryption_key }}" +exchange_attribute_encryption_key: "{{ vault_exchange_attribute_encryption_key }}" # EBICS access details -LIBEUFIN_NEXUS_EBICS_HOST_BASE_URL: https://ebics.postfinance.ch/ebics/ebics.aspx -LIBEUFIN_NEXUS_EBICS_HOST_ID: PFEBICS -LIBEUFIN_NEXUS_EBICS_USER_ID: "{{ vault_libeufin_nexus_ebics_user_id }}" -LIBEUFIN_NEXUS_EBICS_PARTNER_ID: "{{ vault_libeufin_nexus_ebics_partner_id }}" -LIBEUFIN_NEXUS_EBICS_SYSTEM_ID: "{{ vault_libeufin_nexus_ebics_system_id }}" +libeufin_nexus_ebics_host_base_url: https://ebics.postfinance.ch/ebics/ebics.aspx +libeufin_nexus_ebics_host_id: PFEBICS +libeufin_nexus_ebics_user_id: "{{ vault_libeufin_nexus_ebics_user_id }}" +libeufin_nexus_ebics_partner_id: "{{ vault_libeufin_nexus_ebics_partner_id }}" +libeufin_nexus_ebics_system_id: "{{ vault_libeufin_nexus_ebics_system_id }}" # Authorization token for the telesign SMS service # "Basic" is pre-pended by the shell script -SMS_CHALLENGER_TELESIGN_AUTH_TOKEN: "{{ vault_sms_challenger_telesign_auth_token }}" +sms_challenger_telesign_auth_token: "{{ vault_sms_challenger_telesign_auth_token }}" sms_challenger_clicksend_username: "{{ vault_sms_challenger_clicksend_username }}" sms_challenger_clicksend_api_key: "{{ vault_sms_challenger_clicksend_api_key }}" # Authorization data for the pingen postal service -POSTAL_CHALLENGER_PINGEN_CLIENT_ID: "{{ vault_postal_challenger_pingen_client_id }}" -POSTAL_CHALLENGER_PINGEN_CLIENT_SECRET: "{{ vault_postal_challenger_pingen_client_secret }}" -POSTAL_CHALLENGER_PINGEN_ORG_ID: "{{ vault_postal_challenger_pingen_org_id }}" +postal_challenger_pingen_client_id: "{{ vault_postal_challenger_pingen_client_id }}" +postal_challenger_pingen_client_secret: "{{ vault_postal_challenger_pingen_client_secret }}" +postal_challenger_pingen_org_id: "{{ vault_postal_challenger_pingen_org_id }}" # KYCaid access token -EXCHANGE_KYCAID_ACCESS_TOKEN: "{{ vault_exchange_kycaid_access_token }}" +exchange_kycaid_access_token: "{{ vault_exchange_kycaid_access_token }}" # Bearer access token for the auditor SPA (set via browser extension to set Authorization HTTP header on auditor.$DOMAIN!) -AUDITOR_ACCESS_TOKEN: "{{ vault_auditor_access_token }}" +auditor_access_token: "{{ vault_auditor_access_token }}" # Bearer access token for monitoring.$DOMAIN (must be given to grafana) -PROMETHEUS_ACCESS_TOKEN: "{{ vault_prometheus_access_token }}" +prometheus_access_token: "{{ vault_prometheus_access_token }}" # Bearer access token for loki.taler-systems.com (see that nginx config) -LOKI_ACCESS_TOKEN: "{{ vault_loki_access_token }}" +loki_access_token: "{{ vault_loki_access_token }}" diff --git a/inventories/host_vars/spec/vars.yml b/inventories/host_vars/spec/vars.yml @@ -2,70 +2,70 @@ # Deploy challenger? deploy_challenger: true # What kind of environment are we deploying? -DEPLOYMENT_KIND: "tops" +deployment_kind: "tops" # Write EBICS configuration (with values in secret config) configure_ebics: true # Main domain name. domain_name: "taler-ops.ch" exchange_domain: "exchange.{{ domain_name }}" # Our internal hostname -TARGET_HOST_NAME: "spec.taler-ops.ch" +target_host_name: "spec.taler-ops.ch" # Suite for taler packages. taler_repo_suites: trixie # Deploy EBICS configuration (true/false). use_ebics: false # Our currency. -CURRENCY: CHF +currency: CHF # Smallest unit of the currency for wire transfers. -CURRENCY_ROUND_UNIT: "CHF:0.01" +currency_round_unit: "CHF:0.01" # Sanction list to use, comment out to disable -# SANCTION_LIST: sanctions-swiss.json +# sanction_list: sanctions-swiss.json # Base URL of the exchange REST API -EXCHANGE_BASE_URL: "https://exchange.{{ domain_name }}/" +exchange_base_url: "https://exchange.{{ domain_name }}/" # Base URL of the auditor REST API -AUDITOR_BASE_URL: "https://auditor.{{ domain_name }}/" +auditor_base_url: "https://auditor.{{ domain_name }}/" # Exchange offline master public key. -EXCHANGE_MASTER_PUB: 9V0G82S7JQW2ZRYF7BMGKKQ1TNR1VNVXZJSNQ2VSDGWC80D9W0YG +exchange_master_pub: 9V0G82S7JQW2ZRYF7BMGKKQ1TNR1VNVXZJSNQ2VSDGWC80D9W0YG # Auditor offline public key. -AUDITOR_PUB: P6B7ZS7Y1Y12S0VP0PAJ1GQGSHW8RE4NSBTP8PR254J18SK24MH0 +auditor_pub: P6B7ZS7Y1Y12S0VP0PAJ1GQGSHW8RE4NSBTP8PR254J18SK24MH0 # URL with merchants accepting this exchange. -EXCHANGE_SHOPPING_URL: "https://map.taler-ops.ch/" +exchange_shopping_url: "https://map.taler-ops.ch/" # Name of Terms of service resource file -EXCHANGE_TERMS_ETAG: "exchange-tos-tops-v0" +exchange_terms_etag: "exchange-tos-tops-v0" # Name of Privacy policy resource file -EXCHANGE_PP_ETAG: "exchange-pp-v0" +exchange_pp_etag: "exchange-pp-v0" # Full BIC of exchange account -EXCHANGE_BANK_ACCOUNT_BIC: "POFICHBEXXX" +exchange_bank_account_bic: "POFICHBEXXX" # Full Payto URI of exchange account (for credit and debit) -EXCHANGE_BANK_ACCOUNT_IBAN: "CH9709000000166556130" +exchange_bank_account_iban: "CH9709000000166556130" # Full Payto URI of exchange account (for credit and debit) -EXCHANGE_BANK_ACCOUNT_PAYTO: "payto://iban/{{ EXCHANGE_BANK_ACCOUNT_IBAN }}?receiver-name=Taler+Operations+AG" +exchange_bank_account_payto: "payto://iban/{{ exchange_bank_account_iban }}?receiver-name=Taler+Operations+AG" # Port to be used by libeufin-nexus for the taler-exchange-wire-gateway -LIBEUFIN_PORT: 8082 +libeufin_port: 8082 # Name of the exchange account at libeufin-nexus LIBEUFIN_EXCHANGE_ACCOUNT: "exchange" # Name of the bank dialect -LIBEUFIN_NEXUS_BANK_DIALECT: "postfinance" +libeufin_nexus_bank_dialect: "postfinance" # SPA dialect (tops, gls, magnet, ...) -EXCHANGE_SPA_DIALECT: "tops" +exchange_spa_dialect: "tops" # Business name of the exchange operator -EXCHANGE_OPERATOR_LEGAL_NAME: "Taler Operations AG" +exchange_operator_legal_name: "Taler Operations AG" # Where to send people after they passed KYC. -KYC_THANK_YOU_URL: https://taler-ops.ch/en/thank-you-kyc.html +kyc_thank_you_url: https://taler-ops.ch/en/thank-you-kyc.html # Template to use for identification of individuals with KYCAID -KYCAID_TEMPLATE_INDIVIDUAL: tmpl_xxx +kycaid_template_individual: tmpl_xxx # Template to use for identification of businesses with KYCAID -KYCAID_TEMPLATE_BUSINESS: tmpl_xxx +kycaid_template_business: tmpl_xxx # Regex specifying allowed phone numbers for the SMS check -EXCHANGE_AML_PROGRAM_TOPS_SMS_HINT: "Swiss mobile number (+417...) required" -EXCHANGE_AML_PROGRAM_TOPS_SMS_EXAMPLE: "+41748224521" -EXCHANGE_AML_PROGRAM_TOPS_SMS_REGEX: "\\\\+417[0-9]+" +exchange_aml_program_tops_sms_hint: "Swiss mobile number (+417...) required" +exchange_aml_program_tops_sms_example: "+41748224521" +exchange_aml_program_tops_sms_regex: "\\\\+417[0-9]+" # Regex specifying allowed country names for the postal address check -EXCHANGE_AML_PROGRAM_TOPS_POSTAL_COUNTRY_HINT: "Swiss address required" -EXCHANGE_AML_PROGRAM_TOPS_POSTAL_EXAMPLE: "Max Mustermann\\nBahnhofsplatz 1\\n4201 Biel/Bienne" -EXCHANGE_AML_PROGRAM_TOPS_POSTAL_COUNTRY_REGEX: "CH|Ch|ch" +exchange_aml_program_tops_postal_country_hint: "Swiss address required" +exchange_aml_program_tops_postal_example: "Max Mustermann\\nBahnhofsplatz 1\\n4201 Biel/Bienne" +exchange_aml_program_tops_postal_country_regex: "CH|Ch|ch" # Tool to use for sanction list checking -EXCHANGE_SANCTION_HELPER: taler-exchange-helper-sanctions-dummy +exchange_sanction_helper: taler-exchange-helper-sanctions-dummy # Secrets are taken from the vault file and substituted via # the vault_* variables. @@ -74,34 +74,34 @@ EXCHANGE_SANCTION_HELPER: taler-exchange-helper-sanctions-dummy # $ ansible-vault edit inventories/host_vars/spec/vault.yml # to decrease the likelihood of unencrypted secrets ending up in git. # Symmetric encryption secret for KYC attribute encryption. -EXCHANGE_ATTRIBUTE_ENCRYPTION_KEY: "{{ vault_exchange_attribute_encryption_key }}" +exchange_attribute_encryption_key: "{{ vault_exchange_attribute_encryption_key }}" # EBICS access details -LIBEUFIN_NEXUS_EBICS_HOST_BASE_URL: https://ebics.postfinance.ch/ebics/ebics.aspx -LIBEUFIN_NEXUS_EBICS_HOST_ID: PFEBICS -LIBEUFIN_NEXUS_EBICS_USER_ID: "{{ vault_libeufin_nexus_ebics_user_id }}" -LIBEUFIN_NEXUS_EBICS_PARTNER_ID: "{{ vault_libeufin_nexus_ebics_partner_id }}" -LIBEUFIN_NEXUS_EBICS_SYSTEM_ID: "{{ vault_libeufin_nexus_ebics_system_id }}" +libeufin_nexus_ebics_host_base_url: https://ebics.postfinance.ch/ebics/ebics.aspx +libeufin_nexus_ebics_host_id: PFEBICS +libeufin_nexus_ebics_user_id: "{{ vault_libeufin_nexus_ebics_user_id }}" +libeufin_nexus_ebics_partner_id: "{{ vault_libeufin_nexus_ebics_partner_id }}" +libeufin_nexus_ebics_system_id: "{{ vault_libeufin_nexus_ebics_system_id }}" # Authorization token for the telesign SMS service # "Basic" is pre-pended by the shell script -SMS_CHALLENGER_TELESIGN_AUTH_TOKEN: "{{ vault_sms_challenger_telesign_auth_token }}" +sms_challenger_telesign_auth_token: "{{ vault_sms_challenger_telesign_auth_token }}" sms_challenger_clicksend_username: "{{ vault_sms_challenger_clicksend_username }}" sms_challenger_clicksend_api_key: "{{ vault_sms_challenger_clicksend_api_key }}" # Authorization data for the pingen postal service -POSTAL_CHALLENGER_PINGEN_CLIENT_ID: "{{ vault_postal_challenger_pingen_client_id }}" -POSTAL_CHALLENGER_PINGEN_CLIENT_SECRET: "{{ vault_postal_challenger_pingen_client_secret }}" -POSTAL_CHALLENGER_PINGEN_ORG_ID: "{{ vault_postal_challenger_pingen_org_id }}" +postal_challenger_pingen_client_id: "{{ vault_postal_challenger_pingen_client_id }}" +postal_challenger_pingen_client_secret: "{{ vault_postal_challenger_pingen_client_secret }}" +postal_challenger_pingen_org_id: "{{ vault_postal_challenger_pingen_org_id }}" # KYCaid access token -EXCHANGE_KYCAID_ACCESS_TOKEN: "{{ vault_exchange_kycaid_access_token }}" +exchange_kycaid_access_token: "{{ vault_exchange_kycaid_access_token }}" # Bearer access token for the auditor SPA (set via browser extension to set Authorization HTTP header on auditor.$DOMAIN!) -AUDITOR_ACCESS_TOKEN: "{{ vault_auditor_access_token }}" +auditor_access_token: "{{ vault_auditor_access_token }}" # Bearer access token for monitoring.$DOMAIN (must be given to grafana) -PROMETHEUS_ACCESS_TOKEN: "{{ vault_prometheus_access_token }}" +prometheus_access_token: "{{ vault_prometheus_access_token }}" # Bearer access token for loki.taler-systems.com (see that nginx config) -LOKI_ACCESS_TOKEN: "{{ vault_loki_access_token }}" +loki_access_token: "{{ vault_loki_access_token }}" diff --git a/playbooks/borg-ssh-export.yml b/playbooks/borg-ssh-export.yml @@ -5,4 +5,4 @@ - borg-ssh-export vars: # Hostname where we will store backups - BORG_HOST: pixel.taler-systems.com + borg_host: pixel.taler-systems.com diff --git a/playbooks/borg-start.yml b/playbooks/borg-start.yml @@ -6,6 +6,6 @@ - borg-start vars: # Hostname where we will store backups - BORG_HOST: pixel.taler-systems.com + borg_host: pixel.taler-systems.com # Target for the backup (repo must exist and we must have SSH access). - BORG_REPO: "ssh://borg@{{ BORG_HOST }}/~/spec-backup" + borg_repo: "ssh://borg@{{ borg_host }}/~/spec-backup" diff --git a/playbooks/setup.yml b/playbooks/setup.yml @@ -1,57 +1,57 @@ --- -- name: Deploy GNU Taler +- name: Deploy gnu Taler hosts: all any_errors_fatal: true pre_tasks: - name: "Fail if the deployment kind is not defined" ansible.builtin.fail: - msg: "DEPLOYMENT_KIND is not set; it selects the exchange_$KIND role" - when: DEPLOYMENT_KIND is undefined + msg: "deployment_kind is not set; it selects the exchange_$KIND role" + when: deployment_kind is undefined - name: "Check the secrets every deployment needs" ansible.builtin.assert: - that: EXCHANGE_ATTRIBUTE_ENCRYPTION_KEY is defined + that: exchange_attribute_encryption_key is defined quiet: true - name: "Check the KYCAID secrets" - when: DEPLOYMENT_KIND == 'tops' + when: deployment_kind == 'tops' ansible.builtin.assert: - that: EXCHANGE_KYCAID_ACCESS_TOKEN is defined + that: exchange_kycaid_access_token is defined quiet: true - name: "Check the auditor secrets" when: deploy_auditor | bool ansible.builtin.assert: - that: AUDITOR_ACCESS_TOKEN is defined + that: auditor_access_token is defined quiet: true - name: "Check the monitoring secrets" when: deploy_monitoring | bool ansible.builtin.assert: that: - - LOKI_ACCESS_TOKEN is defined - - PROMETHEUS_ACCESS_TOKEN is defined + - loki_access_token is defined + - prometheus_access_token is defined quiet: true - name: "Check the challenger secrets" when: deploy_challenger | bool ansible.builtin.assert: that: - - SMS_CHALLENGER_TELESIGN_AUTH_TOKEN is defined - - POSTAL_CHALLENGER_PINGEN_CLIENT_ID is defined - - POSTAL_CHALLENGER_PINGEN_CLIENT_SECRET is defined - - POSTAL_CHALLENGER_PINGEN_ORG_ID is defined + - sms_challenger_telesign_auth_token is defined + - postal_challenger_pingen_client_id is defined + - postal_challenger_pingen_client_secret is defined + - postal_challenger_pingen_org_id is defined quiet: true - name: "Check the EBICS secrets" when: use_ebics | bool or configure_ebics | bool ansible.builtin.assert: that: - - LIBEUFIN_NEXUS_EBICS_HOST_BASE_URL is defined - - LIBEUFIN_NEXUS_EBICS_HOST_ID is defined - - LIBEUFIN_NEXUS_EBICS_USER_ID is defined - - LIBEUFIN_NEXUS_EBICS_PARTNER_ID is defined - - LIBEUFIN_NEXUS_EBICS_SYSTEM_ID is defined + - libeufin_nexus_ebics_host_base_url is defined + - libeufin_nexus_ebics_host_id is defined + - libeufin_nexus_ebics_user_id is defined + - libeufin_nexus_ebics_partner_id is defined + - libeufin_nexus_ebics_system_id is defined quiet: true roles: diff --git a/roles/auditor/templates/etc/nginx/sites-available/auditor-nginx.conf.j2 b/roles/auditor/templates/etc/nginx/sites-available/auditor-nginx.conf.j2 @@ -19,7 +19,7 @@ server { access_log /var/log/nginx/auditor.{{ domain_name }}.tal taler if=$log_perf; location / { # Most of the API we will put behind simple access control for now. - if ($http_authorization != "Bearer {{ AUDITOR_ACCESS_TOKEN }}") { + if ($http_authorization != "Bearer {{ auditor_access_token }}") { return 401; } proxy_pass http://unix:/var/run/taler-auditor/httpd/auditor-http.sock; diff --git a/roles/auditor/templates/etc/taler-auditor/conf.d/taler-auditor-master.conf.j2 b/roles/auditor/templates/etc/taler-auditor/conf.d/taler-auditor-master.conf.j2 @@ -1,19 +1,19 @@ [auditor] -PUBLIC_KEY = {{ AUDITOR_PUB }} -BASE_URL = {{ AUDITOR_BASE_URL }} +PUBLIC_KEY = {{ auditor_pub }} +BASE_URL = {{ auditor_base_url }} SERVE = unix -TINY_AMOUNT = {{ CURRENCY_ROUND_UNIT }} +TINY_AMOUNT = {{ currency_round_unit }} [exchange] -MASTER_PUBLIC_KEY = {{ EXCHANGE_MASTER_PUB }} -BASE_URL = {{ EXCHANGE_BASE_URL }} -CURRENCY = {{ CURRENCY }} -CURRENCY_ROUND_UNIT = {{ CURRENCY_ROUND_UNIT }} +MASTER_PUBLIC_KEY = {{ exchange_master_pub }} +BASE_URL = {{ exchange_base_url }} +CURRENCY = {{ currency }} +CURRENCY_ROUND_UNIT = {{ currency_round_unit }} DB = postgres # Here you MUST add the master public key of the offline system # which you can get using `taler-exchange-offline setup`. -MASTER_PUBLIC_KEY = {{ EXCHANGE_MASTER_PUB }} +MASTER_PUBLIC_KEY = {{ exchange_master_pub }} # Bank accounts used by the exchange should be specified here: @@ -25,7 +25,7 @@ ENABLE_DEBIT = YES # Account identifier in the form of an RFC-8905 payto:// URI. # For SEPA, looks like payto://sepa/$IBAN?receiver-name=$NAME # Make sure to URL-encode spaces in $NAME! -PAYTO_URI = {{ EXCHANGE_BANK_ACCOUNT_PAYTO }} +PAYTO_URI = {{ exchange_bank_account_payto }} # Credentials to access the account are in a separate diff --git a/roles/borg-start/tasks/main.yml b/roles/borg-start/tasks/main.yml @@ -30,14 +30,14 @@ - name: Check whether we already know the host key of the borg server ansible.builtin.command: - cmd: ssh-keygen -F {{ BORG_HOST }} -f /root/.ssh/known_hosts + cmd: ssh-keygen -F {{ borg_host }} -f /root/.ssh/known_hosts register: known_host changed_when: false failed_when: false - name: Add host key for borg server ansible.builtin.shell: - cmd: ssh-keyscan {{ BORG_HOST }} >> /root/.ssh/known_hosts + cmd: ssh-keyscan {{ borg_host }} >> /root/.ssh/known_hosts when: known_host.rc != 0 - name: Fail if we do not have an SSH key for the backup server diff --git a/roles/borg-start/templates/root/.ssh/config b/roles/borg-start/templates/root/.ssh/config @@ -1,5 +1,5 @@ -Host {{ BORG_HOST }} - HostName {{ BORG_HOST }} +Host {{ borg_host }} + HostName {{ borg_host }} Port 22 User borg IdentityFile ~/.ssh/borg diff --git a/roles/borg-start/templates/root/bin/borg-backup.sh b/roles/borg-start/templates/root/bin/borg-backup.sh @@ -1,7 +1,7 @@ #!/bin/bash -export BORG_REPO='{{ BORG_REPO }}' -export BORG_PASSPHRASE='{{ BORG_PASSPHRASE }}' +export BORG_REPO='{{ borg_repo }}' +export BORG_PASSPHRASE='{{ borg_passphrase }}' # some helpers and error handling: info() { printf "\n%s %s\n\n" "$( date )" "$*" >&2; } diff --git a/roles/challenger/tasks/pre-exchange.yml b/roles/challenger/tasks/pre-exchange.yml @@ -185,7 +185,7 @@ - challenger-sms - /etc/challenger/challenger-sms.conf - "{{ ansible_local['sms-challenger-client-secret'] }}" - - "{{ EXCHANGE_BASE_URL }}kyc-proof/sms-challenger" + - "{{ exchange_base_url }}kyc-proof/sms-challenger" creates: /etc/ansible/facts.d/sms-challenger-client-id.fact - name: Setup Email Challenger exchange account @@ -196,7 +196,7 @@ - challenger-email - /etc/challenger/challenger-email.conf - "{{ ansible_local['email-challenger-client-secret'] }}" - - "{{ EXCHANGE_BASE_URL }}kyc-proof/email-challenger" + - "{{ exchange_base_url }}kyc-proof/email-challenger" creates: /etc/ansible/facts.d/email-challenger-client-id.fact - name: Setup Postal Challenger exchange account @@ -207,7 +207,7 @@ - challenger-postal - /etc/challenger/challenger-postal.conf - "{{ ansible_local['postal-challenger-client-secret'] }}" - - "{{ EXCHANGE_BASE_URL }}kyc-proof/postal-challenger" + - "{{ exchange_base_url }}kyc-proof/postal-challenger" creates: /etc/ansible/facts.d/postal-challenger-client-id.fact - name: Force ansible to regather the challenger client IDs diff --git a/roles/challenger/templates/etc/challenger/challenger-postal.conf.j2 b/roles/challenger/templates/etc/challenger/challenger-postal.conf.j2 @@ -35,10 +35,10 @@ MESSAGE_TEMPLATE_FILE = /etc/challenger/postal-message-template.txt ADDRESS_TYPE = postal-ch # Hint to show on the address format. -ADDRESS_HINT = {{ EXCHANGE_AML_PROGRAM_TOPS_POSTAL_EXAMPLE }} +ADDRESS_HINT = {{ exchange_aml_program_tops_postal_example }} # What addresses are allowed. -ADDRESS_RESTRICTIONS = {"COUNTRY_CODE":{"hint":"{{ EXCHANGE_AML_PROGRAM_TOPS_POSTAL_COUNTRY_HINT }}","regex":"^{{ EXCHANGE_AML_PROGRAM_TOPS_POSTAL_COUNTRY_REGEX }}$"}} +ADDRESS_RESTRICTIONS = {"COUNTRY_CODE":{"hint":"{{ exchange_aml_program_tops_postal_country_hint }}","regex":"^{{ exchange_aml_program_tops_postal_country_regex }}$"}} [challengerdb-postgres] #The connection string the plugin has to use for connecting to the database diff --git a/roles/challenger/templates/etc/challenger/challenger-sms.conf.j2 b/roles/challenger/templates/etc/challenger/challenger-sms.conf.j2 @@ -28,10 +28,10 @@ BASE_URL = https://sms.challenger.{{ domain_name }}/ ADDRESS_TYPE = phone # Hint to show on the address format. -ADDRESS_HINT = {{ EXCHANGE_AML_PROGRAM_TOPS_SMS_EXAMPLE }} +ADDRESS_HINT = {{ exchange_aml_program_tops_sms_example }} # Limit acceptable phone numbers. -ADDRESS_RESTRICTIONS = {"CONTACT_PHONE":{"hint":"{{ EXCHANGE_AML_PROGRAM_TOPS_SMS_HINT }}","regex":"{{ EXCHANGE_AML_PROGRAM_TOPS_SMS_REGEX }}"}} +ADDRESS_RESTRICTIONS = {"CONTACT_PHONE":{"hint":"{{ exchange_aml_program_tops_sms_hint }}","regex":"{{ exchange_aml_program_tops_sms_regex }}"}} [challengerdb-postgres] diff --git a/roles/challenger/templates/etc/challenger/postal-challenger.env.j2 b/roles/challenger/templates/etc/challenger/postal-challenger.env.j2 @@ -1,6 +1,6 @@ # systemd environment file for challenger-httpd # Provides secrets needed. # Set to pingen.ch auth token! -PINGEN_CLIENT_ID={{ POSTAL_CHALLENGER_PINGEN_CLIENT_ID }} -PINGEN_CLIENT_SECRET={{ POSTAL_CHALLENGER_PINGEN_CLIENT_SECRET }} -PINGEN_ORG_ID={{ POSTAL_CHALLENGER_PINGEN_ORG_ID }} +PINGEN_CLIENT_ID={{ postal_challenger_pingen_client_id }} +PINGEN_CLIENT_SECRET={{ postal_challenger_pingen_client_secret }} +PINGEN_ORG_ID={{ postal_challenger_pingen_org_id }} diff --git a/roles/challenger/templates/etc/challenger/sms-challenger.env.j2 b/roles/challenger/templates/etc/challenger/sms-challenger.env.j2 @@ -1,9 +1,9 @@ # systemd environment file for challenger-httpd # Provides secrets needed. # Legacy style -AUTH_TOKEN={{ SMS_CHALLENGER_TELESIGN_AUTH_TOKEN }} +AUTH_TOKEN={{ sms_challenger_telesign_auth_token }} # Modern style -TELESIGN_AUTH_TOKEN={{ SMS_CHALLENGER_TELESIGN_AUTH_TOKEN }} +TELESIGN_AUTH_TOKEN={{ sms_challenger_telesign_auth_token }} # Uncomment to use clicksend instead of telesign: # CLICKSEND_API_KEY={{ '{{' }} sms_challenger_clicksend_api_key {{ '}}' }} # CLICKSEND_USERNAME={{ '{{' }} sms_challenger_clicksend_username {{ '}}' }} diff --git a/roles/challenger/templates/etc/taler-exchange/secrets/challenger-email.secret.conf.j2 b/roles/challenger/templates/etc/taler-exchange/secrets/challenger-email.secret.conf.j2 @@ -6,7 +6,7 @@ KYC_OAUTH2_TOKEN_URL = https://email.challenger.{{ domain_name }}/token KYC_OAUTH2_INFO_URL = https://email.challenger.{{ domain_name }}/info KYC_OAUTH2_CLIENT_ID = {{ ansible_local['email-challenger-client-id'] }} KYC_OAUTH2_CLIENT_SECRET = {{ ansible_local['email-challenger-client-secret'] }} -KYC_OAUTH2_POST_URL = {{ KYC_THANK_YOU_URL }} +KYC_OAUTH2_POST_URL = {{ kyc_thank_you_url }} KYC_OAUTH2_CONVERTER_HELPER = /usr/bin/taler-exchange-kyc-challenger-email-converter # Error responses may include the full response of the challenger, # which can contain the address being validated. diff --git a/roles/challenger/templates/etc/taler-exchange/secrets/challenger-postal.secret.conf.j2 b/roles/challenger/templates/etc/taler-exchange/secrets/challenger-postal.secret.conf.j2 @@ -6,7 +6,7 @@ KYC_OAUTH2_TOKEN_URL = https://postal.challenger.{{ domain_name }}/token KYC_OAUTH2_INFO_URL = https://postal.challenger.{{ domain_name }}/info KYC_OAUTH2_CLIENT_ID = {{ ansible_local['postal-challenger-client-id'] }} KYC_OAUTH2_CLIENT_SECRET = {{ ansible_local['postal-challenger-client-secret'] }} -KYC_OAUTH2_POST_URL = {{ KYC_THANK_YOU_URL }} +KYC_OAUTH2_POST_URL = {{ kyc_thank_you_url }} KYC_OAUTH2_CONVERTER_HELPER = /usr/bin/taler-exchange-kyc-challenger-postal-converter # Error responses may include the full response of the challenger, # which can contain the address being validated. diff --git a/roles/challenger/templates/etc/taler-exchange/secrets/challenger-sms.secret.conf.j2 b/roles/challenger/templates/etc/taler-exchange/secrets/challenger-sms.secret.conf.j2 @@ -6,7 +6,7 @@ KYC_OAUTH2_TOKEN_URL = https://sms.challenger.{{ domain_name }}/token KYC_OAUTH2_INFO_URL = https://sms.challenger.{{ domain_name }}/info KYC_OAUTH2_CLIENT_ID = {{ ansible_local['sms-challenger-client-id'] }} KYC_OAUTH2_CLIENT_SECRET = {{ ansible_local['sms-challenger-client-secret'] }} -KYC_OAUTH2_POST_URL = {{ KYC_THANK_YOU_URL }} +KYC_OAUTH2_POST_URL = {{ kyc_thank_you_url }} KYC_OAUTH2_CONVERTER_HELPER = /usr/bin/taler-exchange-kyc-challenger-sms-converter # Error responses may include the full response of the challenger, # which can contain the address being validated. diff --git a/roles/common_packages/tasks/main.yml b/roles/common_packages/tasks/main.yml @@ -90,7 +90,7 @@ - robocop state: latest when: - - SANCTION_LIST is defined + - sanction_list is defined - ansible_facts["os_family"] == 'Debian' - name: Install setup-secret-fact helper @@ -114,7 +114,7 @@ args: chdir: /etc/ssl/private/ creates: /etc/ssl/private/dhparam.pem - when: not (USE_PREGENERATED_DHPARAM | default(False)) + when: not (use_pregenerated_dhparam | default(False)) - name: Deploy pregenerated dhparam.pem copy: @@ -123,4 +123,4 @@ owner: root group: root mode: "0644" - when: (USE_PREGENERATED_DHPARAM | default(False)) + when: (use_pregenerated_dhparam | default(False)) diff --git a/roles/database/tasks/main.yml b/roles/database/tasks/main.yml @@ -60,7 +60,7 @@ - name: Fail if trying to import backup and versioning schema exists fail: msg="Backup for import provided, but _v schema exists on target host" when: - - ENABLE_RESTORE_BACKUP + - enable_restore_backup - versioning_schema_exists | default(false) | bool - local_backup_exists | bool @@ -68,11 +68,11 @@ - name: Fail if a restore was requested but no backup is available fail: msg: >- - ENABLE_RESTORE_BACKUP is set but + enable_restore_backup is set but {{ role_path }}/files/postgres-backup.sql.gz does not resolve to a file. Fetch the backup with restore.sh first. when: - - ENABLE_RESTORE_BACKUP + - enable_restore_backup - not (local_backup_exists | bool) - not (exchange_db_exists | bool) @@ -86,7 +86,7 @@ group: postgres mode: "0400" when: - - ENABLE_RESTORE_BACKUP + - enable_restore_backup - local_backup_exists | bool - name: Restore PostgreSQL database from backup @@ -94,7 +94,7 @@ become_user: postgres shell: "gunzip -c /tmp/postgres-backup.sql.gz | psql -X -d postgres" when: - - ENABLE_RESTORE_BACKUP + - enable_restore_backup - local_backup_exists | bool - name: Remove backup from server (delete file) diff --git a/roles/exchange-sanctionlist-import/tasks/main.yml b/roles/exchange-sanctionlist-import/tasks/main.yml @@ -16,7 +16,7 @@ block: - name: Push file to local system copy: - src: "{{ SANCTION_LIST }}" + src: "{{ sanction_list }}" dest: "{{ importfile.path }}" owner: taler-exchange-httpd mode: "0400" @@ -25,7 +25,7 @@ # the point of importing a new list. - name: Check sanction list ansible.builtin.command: - cmd: "taler-exchange-sanctionscheck --reset -- {{ EXCHANGE_SANCTION_HELPER }} {{ importfile.path }}" + cmd: "taler-exchange-sanctionscheck --reset -- {{ exchange_sanction_helper }} {{ importfile.path }}" become: true become_user: taler-exchange-httpd always: diff --git a/roles/exchange/handlers/main.yml b/roles/exchange/handlers/main.yml @@ -1,9 +1,9 @@ - name: sanctions-reset ansible.builtin.command: - # Command line argument ("robocop /var/lib/taler-exchange/{{ SANCTION_LIST }}") + # Command line argument ("robocop /var/lib/taler-exchange/{{ sanction_list }}") # is deprecated and lives in the config now. # Only kept for compatibility, should be removed soon. - cmd: taler-exchange-sanctionscheck --reset --norun robocop /var/lib/taler-exchange/{{ SANCTION_LIST }} + cmd: taler-exchange-sanctionscheck --reset --norun robocop /var/lib/taler-exchange/{{ sanction_list }} chdir: /tmp become: true become_user: taler-exchange-sanctionscheck diff --git a/roles/exchange/tasks/main.yml b/roles/exchange/tasks/main.yml @@ -180,7 +180,7 @@ - name: Apply deployment-specific exchange configuration ansible.builtin.include_role: - name: "exchange_{{ DEPLOYMENT_KIND }}" + name: "exchange_{{ deployment_kind }}" # FIXME: Implement this as handler, so it's only # done when necessary. @@ -196,27 +196,27 @@ delegate_to: localhost run_once: true ansible.builtin.stat: - path: "{{ role_path }}/files/var/lib/taler-exchange/{{ SANCTION_LIST }}" + path: "{{ role_path }}/files/var/lib/taler-exchange/{{ sanction_list }}" register: sanction_list_stat - when: SANCTION_LIST is defined + when: sanction_list is defined - name: Fail if sanction list file does not exist delegate_to: localhost run_once: true ansible.builtin.fail: - msg: "The local file 'files/var/lib/taler-exchange/{{ SANCTION_LIST }}' does not exist. Aborting." + msg: "The local file 'files/var/lib/taler-exchange/{{ sanction_list }}' does not exist. Aborting." when: - - SANCTION_LIST is defined + - sanction_list is defined - not sanction_list_stat.stat.exists -- name: Copy sanction list to server if SANCTION_LIST is defined +- name: Copy sanction list to server if sanction_list is defined ansible.builtin.copy: - src: "var/lib/taler-exchange/{{ SANCTION_LIST }}" - dest: "/var/lib/taler-exchange/{{ SANCTION_LIST }}" + src: "var/lib/taler-exchange/{{ sanction_list }}" + dest: "/var/lib/taler-exchange/{{ sanction_list }}" owner: root group: root mode: "0644" - when: SANCTION_LIST is defined + when: sanction_list is defined notify: sanctions-reset - name: Ensure sanctionscheck service is restarted after the upgrade @@ -227,4 +227,4 @@ enabled: true when: - '"taler-exchange-sanctionscheck.service" in ansible_facts["services"]' - - SANCTION_LIST is defined + - sanction_list is defined diff --git a/roles/exchange/templates/etc/taler-exchange/conf.d/exchange-business.conf.j2 b/roles/exchange/templates/etc/taler-exchange/conf.d/exchange-business.conf.j2 @@ -3,36 +3,36 @@ [exchange] # Currency of this exchange. -CURRENCY = {{ CURRENCY }} -CURRENCY_ROUND_UNIT = {{ CURRENCY_ROUND_UNIT }} -TINY_AMOUNT = {{ CURRENCY_ROUND_UNIT }} +CURRENCY = {{ currency }} +CURRENCY_ROUND_UNIT = {{ currency_round_unit }} +TINY_AMOUNT = {{ currency_round_unit }} # Here you MUST add the master public key of the offline system # which you can get using `taler-exchange-offline setup`. -MASTER_PUBLIC_KEY = {{ EXCHANGE_MASTER_PUB }} +MASTER_PUBLIC_KEY = {{ exchange_master_pub }} # Publicly visible base URL of the exchange. # BASE_URL = https://example.com/ -BASE_URL = {{ EXCHANGE_BASE_URL }} +BASE_URL = {{ exchange_base_url }} # Where to find accepting shops? -SHOPPING_URL = {{ EXCHANGE_SHOPPING_URL }} +SHOPPING_URL = {{ exchange_shopping_url }} -AML_SPA_DIALECT = {{ EXCHANGE_SPA_DIALECT }} +AML_SPA_DIALECT = {{ exchange_spa_dialect }} # Attribute encryption key for storing attributes encrypted # in the database. Should be a high-entropy nonce. -ATTRIBUTE_ENCRYPTION_KEY = {{ EXCHANGE_ATTRIBUTE_ENCRYPTION_KEY }} +ATTRIBUTE_ENCRYPTION_KEY = {{ exchange_attribute_encryption_key }} # For your terms of service and privacy policy, you should specify # an Etag that must be updated whenever there are significant # changes to either document. The format is up to you, what matters # is that the value is updated and never re-used. See the HTTP # specification on Etags. -TERMS_ETAG = {{ EXCHANGE_TERMS_ETAG }} -PRIVACY_ETAG = {{ EXCHANGE_PP_ETAG }} +TERMS_ETAG = {{ exchange_terms_etag }} +PRIVACY_ETAG = {{ exchange_pp_etag }} -{% if DEPLOYMENT_KIND == "gls" %} +{% if deployment_kind == "gls" %} BANK_COMPLIANCE_LANGUAGE = gls {% endif %} @@ -46,13 +46,13 @@ ENABLE_DEBIT = YES # Account identifier in the form of an RFC-8905 payto:// URI. # For SEPA, looks like payto://sepa/$IBAN?receiver-name=$NAME # Make sure to URL-encode spaces in $NAME! -PAYTO_URI = {{ EXCHANGE_BANK_ACCOUNT_PAYTO }} +PAYTO_URI = {{ exchange_bank_account_payto }} WIRE_METHOD = iban -{% if SANCTION_LIST is defined %} +{% if sanction_list is defined %} [exchange-sanctionscheck] -RATER_COMMAND = /usr/bin/robocop /var/lib/taler-exchange/{{ SANCTION_LIST }} +RATER_COMMAND = /usr/bin/robocop /var/lib/taler-exchange/{{ sanction_list }} # Name where we store the sanctions check offset. MIN_ROW_FILENAME = ${HOME}/.cache/sanctionscheck-offset.bin @@ -62,7 +62,7 @@ MIN_ROW_FILENAME = ${HOME}/.cache/sanctionscheck-offset.bin # config file with restricted permissions. @inline-secret@ exchange-accountcredentials-primary ../secrets/exchange-accountcredentials-primary.secret.conf -{% if DEPLOYMENT_KIND == "tops" %} +{% if deployment_kind == "tops" %} # Credentials to access KYC providers are in separate # config files with restricted permissions. Only the tops deployment # uses KYCAID, and only exchange_tops places these files. @@ -70,7 +70,7 @@ MIN_ROW_FILENAME = ${HOME}/.cache/sanctionscheck-offset.bin @inline-secret@ kyc-provider-kycaid-business ../secrets/exchange-kyc-provider-business.secret.conf {% endif %} -{% if RESERVE_CLOSING_DELAY is defined %} +{% if reserve_closing_delay is defined %} [exchangedb] -IDLE_RESERVE_EXPIRATION_TIME = {{ RESERVE_CLOSING_DELAY }} +IDLE_RESERVE_EXPIRATION_TIME = {{ reserve_closing_delay }} {% endif %} diff --git a/roles/exchange/templates/etc/taler-exchange/secrets/exchange-accountcredentials-primary.secret.conf.j2 b/roles/exchange/templates/etc/taler-exchange/secrets/exchange-accountcredentials-primary.secret.conf.j2 @@ -1,4 +1,4 @@ [exchange-accountcredentials-primary] WIRE_GATEWAY_AUTH_METHOD = bearer -WIRE_GATEWAY_URL = "http://localhost:{{ LIBEUFIN_PORT }}/taler-wire-gateway/" +WIRE_GATEWAY_URL = "http://localhost:{{ libeufin_port }}/taler-wire-gateway/" TOKEN = {{ ansible_local['libeufin-nexus-access-token'] }} diff --git a/roles/exchange_tops/tasks/main.yml b/roles/exchange_tops/tasks/main.yml @@ -43,7 +43,7 @@ stat: path: "/usr/share/taler-exchange/terms/{{ item.0 }}.{{ item.1 }}.rst" register: legal_sources - loop: "{{ [EXCHANGE_TERMS_ETAG, EXCHANGE_PP_ETAG] + loop: "{{ [exchange_terms_etag, exchange_pp_etag] | product(exchange_tops_terms_languages) | list }}" loop_control: label: "{{ item.0 }}.{{ item.1 }}" diff --git a/roles/exchange_tops/templates/etc/taler-exchange/conf.d/denominations.conf.j2 b/roles/exchange_tops/templates/etc/taler-exchange/conf.d/denominations.conf.j2 @@ -1,229 +1,229 @@ # Coin configuration for the exchange. [coin_n1-t1732389541] -VALUE = {{ CURRENCY }}:0.0025 +VALUE = {{ currency }}:0.0025 DURATION_WITHDRAW = 7 days DURATION_SPEND = 2 years DURATION_LEGAL = 10 years -FEE_WITHDRAW = {{ CURRENCY }}:0 -FEE_DEPOSIT = {{ CURRENCY }}:0 -FEE_REFRESH = {{ CURRENCY }}:0 -FEE_REFUND = {{ CURRENCY }}:0 +FEE_WITHDRAW = {{ currency }}:0 +FEE_DEPOSIT = {{ currency }}:0 +FEE_REFRESH = {{ currency }}:0 +FEE_REFUND = {{ currency }}:0 RSA_KEYSIZE = 2048 CIPHER = RSA [coin_n2-t1732389541] -VALUE = {{ CURRENCY }}:0.005 +VALUE = {{ currency }}:0.005 DURATION_WITHDRAW = 7 days DURATION_SPEND = 2 years DURATION_LEGAL = 10 years -FEE_WITHDRAW = {{ CURRENCY }}:0 -FEE_DEPOSIT = {{ CURRENCY }}:0 -FEE_REFRESH = {{ CURRENCY }}:0 -FEE_REFUND = {{ CURRENCY }}:0 +FEE_WITHDRAW = {{ currency }}:0 +FEE_DEPOSIT = {{ currency }}:0 +FEE_REFRESH = {{ currency }}:0 +FEE_REFUND = {{ currency }}:0 RSA_KEYSIZE = 2048 CIPHER = RSA [coin_n3-t1732389541] -VALUE = {{ CURRENCY }}:0.01 +VALUE = {{ currency }}:0.01 DURATION_WITHDRAW = 7 days DURATION_SPEND = 2 years DURATION_LEGAL = 10 years -FEE_WITHDRAW = {{ CURRENCY }}:0 -FEE_DEPOSIT = {{ CURRENCY }}:0 -FEE_REFRESH = {{ CURRENCY }}:0 -FEE_REFUND = {{ CURRENCY }}:0 +FEE_WITHDRAW = {{ currency }}:0 +FEE_DEPOSIT = {{ currency }}:0 +FEE_REFRESH = {{ currency }}:0 +FEE_REFUND = {{ currency }}:0 RSA_KEYSIZE = 2048 CIPHER = RSA [coin_n4-t1732389541] -VALUE = {{ CURRENCY }}:0.02 +VALUE = {{ currency }}:0.02 DURATION_WITHDRAW = 7 days DURATION_SPEND = 2 years DURATION_LEGAL = 10 years -FEE_WITHDRAW = {{ CURRENCY }}:0 -FEE_DEPOSIT = {{ CURRENCY }}:0 -FEE_REFRESH = {{ CURRENCY }}:0 -FEE_REFUND = {{ CURRENCY }}:0 +FEE_WITHDRAW = {{ currency }}:0 +FEE_DEPOSIT = {{ currency }}:0 +FEE_REFRESH = {{ currency }}:0 +FEE_REFUND = {{ currency }}:0 RSA_KEYSIZE = 2048 CIPHER = RSA [coin_n5-t1732389541] -VALUE = {{ CURRENCY }}:0.04 +VALUE = {{ currency }}:0.04 DURATION_WITHDRAW = 7 days DURATION_SPEND = 2 years DURATION_LEGAL = 10 years -FEE_WITHDRAW = {{ CURRENCY }}:0 -FEE_DEPOSIT = {{ CURRENCY }}:0 -FEE_REFRESH = {{ CURRENCY }}:0 -FEE_REFUND = {{ CURRENCY }}:0 +FEE_WITHDRAW = {{ currency }}:0 +FEE_DEPOSIT = {{ currency }}:0 +FEE_REFRESH = {{ currency }}:0 +FEE_REFUND = {{ currency }}:0 RSA_KEYSIZE = 2048 CIPHER = RSA [coin_n6-t1732389541] -VALUE = {{ CURRENCY }}:0.08 +VALUE = {{ currency }}:0.08 DURATION_WITHDRAW = 7 days DURATION_SPEND = 2 years DURATION_LEGAL = 10 years -FEE_WITHDRAW = {{ CURRENCY }}:0 -FEE_DEPOSIT = {{ CURRENCY }}:0 -FEE_REFRESH = {{ CURRENCY }}:0 -FEE_REFUND = {{ CURRENCY }}:0 +FEE_WITHDRAW = {{ currency }}:0 +FEE_DEPOSIT = {{ currency }}:0 +FEE_REFRESH = {{ currency }}:0 +FEE_REFUND = {{ currency }}:0 RSA_KEYSIZE = 2048 CIPHER = RSA [coin_n7-t1732389541] -VALUE = {{ CURRENCY }}:0.16 +VALUE = {{ currency }}:0.16 DURATION_WITHDRAW = 7 days DURATION_SPEND = 2 years DURATION_LEGAL = 10 years -FEE_WITHDRAW = {{ CURRENCY }}:0 -FEE_DEPOSIT = {{ CURRENCY }}:0 -FEE_REFRESH = {{ CURRENCY }}:0 -FEE_REFUND = {{ CURRENCY }}:0 +FEE_WITHDRAW = {{ currency }}:0 +FEE_DEPOSIT = {{ currency }}:0 +FEE_REFRESH = {{ currency }}:0 +FEE_REFUND = {{ currency }}:0 RSA_KEYSIZE = 2048 CIPHER = RSA [coin_n8-t1732389541] -VALUE = {{ CURRENCY }}:0.32 +VALUE = {{ currency }}:0.32 DURATION_WITHDRAW = 7 days DURATION_SPEND = 2 years DURATION_LEGAL = 10 years -FEE_WITHDRAW = {{ CURRENCY }}:0 -FEE_DEPOSIT = {{ CURRENCY }}:0 -FEE_REFRESH = {{ CURRENCY }}:0 -FEE_REFUND = {{ CURRENCY }}:0 +FEE_WITHDRAW = {{ currency }}:0 +FEE_DEPOSIT = {{ currency }}:0 +FEE_REFRESH = {{ currency }}:0 +FEE_REFUND = {{ currency }}:0 RSA_KEYSIZE = 2048 CIPHER = RSA [coin_n9-t1732389541] -VALUE = {{ CURRENCY }}:0.64 +VALUE = {{ currency }}:0.64 DURATION_WITHDRAW = 7 days DURATION_SPEND = 2 years DURATION_LEGAL = 10 years -FEE_WITHDRAW = {{ CURRENCY }}:0 -FEE_DEPOSIT = {{ CURRENCY }}:0 -FEE_REFRESH = {{ CURRENCY }}:0 -FEE_REFUND = {{ CURRENCY }}:0 +FEE_WITHDRAW = {{ currency }}:0 +FEE_DEPOSIT = {{ currency }}:0 +FEE_REFRESH = {{ currency }}:0 +FEE_REFUND = {{ currency }}:0 RSA_KEYSIZE = 2048 CIPHER = RSA [coin_n10-t1732389541] -VALUE = {{ CURRENCY }}:1.28 +VALUE = {{ currency }}:1.28 DURATION_WITHDRAW = 7 days DURATION_SPEND = 2 years DURATION_LEGAL = 10 years -FEE_WITHDRAW = {{ CURRENCY }}:0 -FEE_DEPOSIT = {{ CURRENCY }}:0 -FEE_REFRESH = {{ CURRENCY }}:0 -FEE_REFUND = {{ CURRENCY }}:0 +FEE_WITHDRAW = {{ currency }}:0 +FEE_DEPOSIT = {{ currency }}:0 +FEE_REFRESH = {{ currency }}:0 +FEE_REFUND = {{ currency }}:0 RSA_KEYSIZE = 2048 CIPHER = RSA [coin_n11-t1732389541] -VALUE = {{ CURRENCY }}:2.56 +VALUE = {{ currency }}:2.56 DURATION_WITHDRAW = 7 days DURATION_SPEND = 2 years DURATION_LEGAL = 10 years -FEE_WITHDRAW = {{ CURRENCY }}:0 -FEE_DEPOSIT = {{ CURRENCY }}:0 -FEE_REFRESH = {{ CURRENCY }}:0 -FEE_REFUND = {{ CURRENCY }}:0 +FEE_WITHDRAW = {{ currency }}:0 +FEE_DEPOSIT = {{ currency }}:0 +FEE_REFRESH = {{ currency }}:0 +FEE_REFUND = {{ currency }}:0 RSA_KEYSIZE = 2048 CIPHER = RSA [coin_n12-t1732389541] -VALUE = {{ CURRENCY }}:5.12 +VALUE = {{ currency }}:5.12 DURATION_WITHDRAW = 7 days DURATION_SPEND = 2 years DURATION_LEGAL = 10 years -FEE_WITHDRAW = {{ CURRENCY }}:0 -FEE_DEPOSIT = {{ CURRENCY }}:0 -FEE_REFRESH = {{ CURRENCY }}:0 -FEE_REFUND = {{ CURRENCY }}:0 +FEE_WITHDRAW = {{ currency }}:0 +FEE_DEPOSIT = {{ currency }}:0 +FEE_REFRESH = {{ currency }}:0 +FEE_REFUND = {{ currency }}:0 RSA_KEYSIZE = 2048 CIPHER = RSA [coin_n13-t1732389541] -VALUE = {{ CURRENCY }}:10.24 +VALUE = {{ currency }}:10.24 DURATION_WITHDRAW = 7 days DURATION_SPEND = 2 years DURATION_LEGAL = 10 years -FEE_WITHDRAW = {{ CURRENCY }}:0 -FEE_DEPOSIT = {{ CURRENCY }}:0 -FEE_REFRESH = {{ CURRENCY }}:0 -FEE_REFUND = {{ CURRENCY }}:0 +FEE_WITHDRAW = {{ currency }}:0 +FEE_DEPOSIT = {{ currency }}:0 +FEE_REFRESH = {{ currency }}:0 +FEE_REFUND = {{ currency }}:0 RSA_KEYSIZE = 2048 CIPHER = RSA [coin_n14-t1732389541] -VALUE = {{ CURRENCY }}:20.48 +VALUE = {{ currency }}:20.48 DURATION_WITHDRAW = 7 days DURATION_SPEND = 2 years DURATION_LEGAL = 10 years -FEE_WITHDRAW = {{ CURRENCY }}:0 -FEE_DEPOSIT = {{ CURRENCY }}:0 -FEE_REFRESH = {{ CURRENCY }}:0 -FEE_REFUND = {{ CURRENCY }}:0 +FEE_WITHDRAW = {{ currency }}:0 +FEE_DEPOSIT = {{ currency }}:0 +FEE_REFRESH = {{ currency }}:0 +FEE_REFUND = {{ currency }}:0 RSA_KEYSIZE = 2048 CIPHER = RSA [coin_n15-t1732389541] -VALUE = {{ CURRENCY }}:40.96 +VALUE = {{ currency }}:40.96 DURATION_WITHDRAW = 7 days DURATION_SPEND = 2 years DURATION_LEGAL = 10 years -FEE_WITHDRAW = {{ CURRENCY }}:0 -FEE_DEPOSIT = {{ CURRENCY }}:0 -FEE_REFRESH = {{ CURRENCY }}:0 -FEE_REFUND = {{ CURRENCY }}:0 +FEE_WITHDRAW = {{ currency }}:0 +FEE_DEPOSIT = {{ currency }}:0 +FEE_REFRESH = {{ currency }}:0 +FEE_REFUND = {{ currency }}:0 RSA_KEYSIZE = 2048 CIPHER = RSA [coin_n16-t1732389541] -VALUE = {{ CURRENCY }}:81.92 +VALUE = {{ currency }}:81.92 DURATION_WITHDRAW = 7 days DURATION_SPEND = 2 years DURATION_LEGAL = 10 years -FEE_WITHDRAW = {{ CURRENCY }}:0 -FEE_DEPOSIT = {{ CURRENCY }}:0 -FEE_REFRESH = {{ CURRENCY }}:0 -FEE_REFUND = {{ CURRENCY }}:0 +FEE_WITHDRAW = {{ currency }}:0 +FEE_DEPOSIT = {{ currency }}:0 +FEE_REFRESH = {{ currency }}:0 +FEE_REFUND = {{ currency }}:0 RSA_KEYSIZE = 2048 CIPHER = RSA [coin_n17-t1732389541] -VALUE = {{ CURRENCY }}:163.84 +VALUE = {{ currency }}:163.84 DURATION_WITHDRAW = 7 days DURATION_SPEND = 2 years DURATION_LEGAL = 10 years -FEE_WITHDRAW = {{ CURRENCY }}:0 -FEE_DEPOSIT = {{ CURRENCY }}:0 -FEE_REFRESH = {{ CURRENCY }}:0 -FEE_REFUND = {{ CURRENCY }}:0 +FEE_WITHDRAW = {{ currency }}:0 +FEE_DEPOSIT = {{ currency }}:0 +FEE_REFRESH = {{ currency }}:0 +FEE_REFUND = {{ currency }}:0 RSA_KEYSIZE = 2048 CIPHER = RSA [coin_n18-t1732389541] -VALUE = {{ CURRENCY }}:327.68 +VALUE = {{ currency }}:327.68 DURATION_WITHDRAW = 7 days DURATION_SPEND = 2 years DURATION_LEGAL = 10 years -FEE_WITHDRAW = {{ CURRENCY }}:0 -FEE_DEPOSIT = {{ CURRENCY }}:0 -FEE_REFRESH = {{ CURRENCY }}:0 -FEE_REFUND = {{ CURRENCY }}:0 +FEE_WITHDRAW = {{ currency }}:0 +FEE_DEPOSIT = {{ currency }}:0 +FEE_REFRESH = {{ currency }}:0 +FEE_REFUND = {{ currency }}:0 RSA_KEYSIZE = 2048 CIPHER = RSA [coin_n19-t1732389541] -VALUE = {{ CURRENCY }}:655.36 +VALUE = {{ currency }}:655.36 DURATION_WITHDRAW = 7 days DURATION_SPEND = 2 years DURATION_LEGAL = 10 years -FEE_WITHDRAW = {{ CURRENCY }}:0 -FEE_DEPOSIT = {{ CURRENCY }}:0 -FEE_REFRESH = {{ CURRENCY }}:0 -FEE_REFUND = {{ CURRENCY }}:0 +FEE_WITHDRAW = {{ currency }}:0 +FEE_DEPOSIT = {{ currency }}:0 +FEE_REFRESH = {{ currency }}:0 +FEE_REFUND = {{ currency }}:0 RSA_KEYSIZE = 2048 CIPHER = RSA diff --git a/roles/exchange_tops/templates/etc/taler-exchange/conf.d/kyc-rules.conf.j2 b/roles/exchange_tops/templates/etc/taler-exchange/conf.d/kyc-rules.conf.j2 @@ -146,7 +146,7 @@ CONTEXT = {} [kyc-measure-accept-tos] CHECK_NAME = form-accept-tos PROGRAM = check-tos -CONTEXT = {"tos_url":"{{ EXCHANGE_BASE_URL }}terms","provider_name":"Taler Operations AG", "successor_measure":"accept-tos", "validity_years":10} +CONTEXT = {"tos_url":"{{ exchange_base_url }}terms","provider_name":"Taler Operations AG", "successor_measure":"accept-tos", "validity_years":10} VOLUNTARY = NO [kyc-measure-kyx] diff --git a/roles/exchange_tops/templates/etc/taler-exchange/secrets/exchange-kyc-provider-business.secret.conf.j2 b/roles/exchange_tops/templates/etc/taler-exchange/secrets/exchange-kyc-provider-business.secret.conf.j2 @@ -1,8 +1,8 @@ [kyc-provider-kycaid-business] LOGIC = kycaid KYC_KYCAID_VALIDITY = forever -KYC_KYCAID_AUTH_TOKEN = {{ EXCHANGE_KYCAID_ACCESS_TOKEN }} +KYC_KYCAID_AUTH_TOKEN = {{ exchange_kycaid_access_token }} # FIXME: correct converter? business should differ! KYC_KYCAID_CONVERTER_HELPER = taler-exchange-kyc-kycaid-converter.sh -KYC_KYCAID_FORM_ID = {{ KYCAID_TEMPLATE_BUSINESS }} -KYC_KYCAID_POST_URL = {{ KYC_THANK_YOU_URL }} +KYC_KYCAID_FORM_ID = {{ kycaid_template_business }} +KYC_KYCAID_POST_URL = {{ kyc_thank_you_url }} diff --git a/roles/exchange_tops/templates/etc/taler-exchange/secrets/exchange-kyc-provider-individual.secret.conf.j2 b/roles/exchange_tops/templates/etc/taler-exchange/secrets/exchange-kyc-provider-individual.secret.conf.j2 @@ -1,8 +1,8 @@ [kyc-provider-kycaid-individual] LOGIC = kycaid KYC_KYCAID_VALIDITY = forever -KYC_KYCAID_AUTH_TOKEN = {{ EXCHANGE_KYCAID_ACCESS_TOKEN }} +KYC_KYCAID_AUTH_TOKEN = {{ exchange_kycaid_access_token }} # FIXME: correct converter? KYC_KYCAID_CONVERTER_HELPER = taler-exchange-kyc-kycaid-converter.sh -KYC_KYCAID_FORM_ID = {{ KYCAID_TEMPLATE_INDIVIDUAL }} -KYC_KYCAID_POST_URL = {{ KYC_THANK_YOU_URL }} +KYC_KYCAID_FORM_ID = {{ kycaid_template_individual }} +KYC_KYCAID_POST_URL = {{ kyc_thank_you_url }} diff --git a/roles/exchange_tops/templates/etc/taler-exchange/taler-exchange.env.j2 b/roles/exchange_tops/templates/etc/taler-exchange/taler-exchange.env.j2 @@ -1,9 +1,9 @@ # Environment variables for taler-exchange-helper-measure-tops-sms-check -EXCHANGE_AML_PROGRAM_TOPS_SMS_CHECK_REGEX="{{ EXCHANGE_AML_PROGRAM_TOPS_SMS_REGEX }}" +EXCHANGE_AML_PROGRAM_TOPS_SMS_CHECK_REGEX="{{ exchange_aml_program_tops_sms_regex }}" # Environment variables for taler-exchange-helper-measure-tops-postal-check -EXCHANGE_AML_PROGRAM_TOPS_POSTAL_CHECK_COUNTRY_REGEX="{{ EXCHANGE_AML_PROGRAM_TOPS_POSTAL_COUNTRY_REGEX }}" +EXCHANGE_AML_PROGRAM_TOPS_POSTAL_CHECK_COUNTRY_REGEX="{{ exchange_aml_program_tops_postal_country_regex }}" # Environment variables for taler-exchange-helper-measure-enable-deposits -EXCHANGE_AML_PROGRAM_TOPS_ENABLE_DEPOSITS_TOS_NAME="{{ EXCHANGE_TERMS_ETAG }}" +EXCHANGE_AML_PROGRAM_TOPS_ENABLE_DEPOSITS_TOS_NAME="{{ exchange_terms_etag }}" diff --git a/roles/libeufin-nexus/templates/etc/libeufin/libeufin-nexus-ebics.conf.j2 b/roles/libeufin-nexus/templates/etc/libeufin/libeufin-nexus-ebics.conf.j2 @@ -1,16 +1,16 @@ [nexus-ebics] # Base URL of the bank EBICS server. -HOST_BASE_URL = {{ LIBEUFIN_NEXUS_EBICS_HOST_BASE_URL }} +HOST_BASE_URL = {{ libeufin_nexus_ebics_host_base_url }} # EBICS host ID. -HOST_ID = {{ LIBEUFIN_NEXUS_EBICS_HOST_ID }} +HOST_ID = {{ libeufin_nexus_ebics_host_id }} # EBICS user ID, as assigned by the bank. -USER_ID = {{ LIBEUFIN_NEXUS_EBICS_USER_ID }} +USER_ID = {{ libeufin_nexus_ebics_user_id }} # EBICS partner ID, as assigned by the bank. -PARTNER_ID = {{ LIBEUFIN_NEXUS_EBICS_PARTNER_ID }} +PARTNER_ID = {{ libeufin_nexus_ebics_partner_id }} # EBICS system ID, as assigned by the bank. -SYSTEM_ID = {{ LIBEUFIN_NEXUS_EBICS_SYSTEM_ID }} +SYSTEM_ID = {{ libeufin_nexus_ebics_system_id }} diff --git a/roles/libeufin-nexus/templates/etc/libeufin/libeufin-nexus.conf.j2 b/roles/libeufin-nexus/templates/etc/libeufin/libeufin-nexus.conf.j2 @@ -6,23 +6,23 @@ CONFIG = postgres:///libeufin [nexus-ebics] # Currency used by the bank where Nexus is client. -CURRENCY = {{ CURRENCY }} +CURRENCY = {{ currency }} # Exchange accounts bounce invalid incoming transactions. ACCOUNT_TYPE = exchange # IBAN of the bank account that is associated with the EBICS subscriber. -IBAN = {{ EXCHANGE_BANK_ACCOUNT_IBAN }} +IBAN = {{ exchange_bank_account_iban }} # BIC of the bank account that is associated with the EBICS subscriber -BIC = {{ EXCHANGE_BANK_ACCOUNT_BIC }} +BIC = {{ exchange_bank_account_bic }} # Legal entity that is associated with the EBICS subscriber. -NAME = {{ EXCHANGE_OPERATOR_LEGAL_NAME }} +NAME = {{ exchange_operator_legal_name }} # EBICS version and ISO20022 recommendations that # Nexus would honor in the communication with the bank. -BANK_DIALECT = {{ LIBEUFIN_NEXUS_BANK_DIALECT }} +BANK_DIALECT = {{ libeufin_nexus_bank_dialect }} [nexus-fetch] @@ -33,7 +33,7 @@ BANK_DIALECT = {{ LIBEUFIN_NEXUS_BANK_DIALECT }} # first place. FREQUENCY = 300s -{% if DEPLOYMENT_KIND == 'tops' %} +{% if deployment_kind == 'tops' %} RESTRICTION_PAYTO_REGEX = payto://iban/CH.* {%endif %} @@ -42,7 +42,7 @@ FREQUENCY = 90s [nexus-httpd] SERVE = tcp -PORT = {{ LIBEUFIN_PORT }} +PORT = {{ libeufin_port }} BIND_TO = 127.0.0.1 {% if exchange_qr_iban is defined and exchange_qr_iban %} diff --git a/roles/libeufin-nexus/templates/etc/nginx/sites-available/nexus-nginx.conf.j2 b/roles/libeufin-nexus/templates/etc/nginx/sites-available/nexus-nginx.conf.j2 @@ -30,6 +30,6 @@ server { # Other nexus APIs might be allowed # in the future. location /taler-prepared-transfer/ { - proxy_pass http://localhost:{{ LIBEUFIN_PORT }}/taler-prepared-transfer/; + proxy_pass http://localhost:{{ libeufin_port }}/taler-prepared-transfer/; } } diff --git a/roles/monitoring/templates/etc/alloy/config.alloy b/roles/monitoring/templates/etc/alloy/config.alloy @@ -8,10 +8,10 @@ logging { loki.write "grafana_loki" { endpoint { url = "https://loki.taler-systems.com/loki/api/v1/push" - tenant_id = "{{ TARGET_HOST_NAME }}" + tenant_id = "{{ target_host_name }}" authorization { type = "Bearer" - credentials = "{{ LOKI_ACCESS_TOKEN }}" + credentials = "{{ loki_access_token }}" } } } @@ -23,7 +23,7 @@ local.file_match "local_files" { { "__path__" = "/var/log/*.log", "job" = "system logs", - "hostname" = "{{ TARGET_HOST_NAME }}", + "hostname" = "{{ target_host_name }}", }, ] sync_period = "5s" @@ -44,7 +44,7 @@ local.file_match "postgres_log_files" { { "__path__" = "/var/log/postgresql/*.log", "job" = "postgres logs", - "hostname" = "{{ TARGET_HOST_NAME }}", + "hostname" = "{{ target_host_name }}", }, ] sync_period = "5s" @@ -65,7 +65,7 @@ local.file_match "nginx_errors" { { "__path__" = "/var/log/nginx/*.err", "job" = "nginx errors", - "hostname" = "{{ TARGET_HOST_NAME }}", + "hostname" = "{{ target_host_name }}", }, ] sync_period = "5s" @@ -86,7 +86,7 @@ local.file_match "http_logs" { { "__path__" = "/var/log/nginx/*.log", "job" = "nginx logs", - "hostname" = "{{ TARGET_HOST_NAME }}", + "hostname" = "{{ target_host_name }}", }, ] sync_period = "5s" @@ -145,7 +145,7 @@ local.file_match "nginx_taler_performance_logs" { { "__path__" = "/var/log/nginx/*.tal", "job" = "nginx/performance", - "hostname" = "{{ TARGET_HOST_NAME }}", + "hostname" = "{{ target_host_name }}", }, ] sync_period = "5s" diff --git a/roles/monitoring/templates/etc/nginx/sites-available/monitoring-nginx.conf.j2 b/roles/monitoring/templates/etc/nginx/sites-available/monitoring-nginx.conf.j2 @@ -12,7 +12,7 @@ server { access_log /var/log/nginx/monitoring.{{ domain_name }}.log; location /prometheus/ { - if ($http_authorization != "Bearer {{ PROMETHEUS_ACCESS_TOKEN }}") { + if ($http_authorization != "Bearer {{ prometheus_access_token }}") { return 401; } rewrite ^/prometheus/(.*)$ /$1 break; @@ -21,7 +21,7 @@ server { location /node/ { # Put API behind simple access control. - if ($http_authorization != "Bearer {{ PROMETHEUS_ACCESS_TOKEN }}") { + if ($http_authorization != "Bearer {{ prometheus_access_token }}") { return 401; } rewrite ^/node/(.*)$ /$1 break; @@ -30,7 +30,7 @@ server { location /nginx/ { # Put API behind simple access control. - if ($http_authorization != "Bearer {{ PROMETHEUS_ACCESS_TOKEN }}") { + if ($http_authorization != "Bearer {{ prometheus_access_token }}") { return 401; } rewrite ^/nginx/(.*)$ /$1 break; @@ -39,7 +39,7 @@ server { location /postgres/ { # Put API behind simple access control. - if ($http_authorization != "Bearer {{ PROMETHEUS_ACCESS_TOKEN }}") { + if ($http_authorization != "Bearer {{ prometheus_access_token }}") { return 401; } rewrite ^/postgres/(.*)$ /$1 break; @@ -48,7 +48,7 @@ server { # location /systemd/ { # Put API behind simple access control. -# if ($http_authorization != "Bearer {{ PROMETHEUS_ACCESS_TOKEN }}") { +# if ($http_authorization != "Bearer {{ prometheus_access_token }}") { # return 401; # } # rewrite ^/systemd/(.*)$ /$1 break; @@ -58,7 +58,7 @@ server { # See /etc/default/alloy for the export location /alloy/ { # Put API behind simple access control. - if ($http_authorization != "Bearer {{ PROMETHEUS_ACCESS_TOKEN }}") { + if ($http_authorization != "Bearer {{ prometheus_access_token }}") { return 401; } rewrite ^/alloy/(.*)$ /$1 break; @@ -66,7 +66,7 @@ server { } location /alertmanager/ { - if ($http_authorization != "Bearer {{ PROMETHEUS_ACCESS_TOKEN }}") { + if ($http_authorization != "Bearer {{ prometheus_access_token }}") { return 401; } rewrite ^/alertmanager/(.*)$ /$1 break; diff --git a/roles/pixel_borg/tasks/main.yml b/roles/pixel_borg/tasks/main.yml @@ -43,7 +43,7 @@ chdir: /home/borg creates: /home/borg/pixel-backup/config environment: - BORG_PASSPHRASE: "{{ PIXEL_BORG_KEY }}" + BORG_PASSPHRASE: "{{ pixel_borg_key }}" become: true become_user: borg @@ -53,7 +53,7 @@ chdir: /home/borg creates: /home/borg/borg-repo.key environment: - BORG_PASSPHRASE: "{{ PIXEL_BORG_KEY }}" + BORG_PASSPHRASE: "{{ pixel_borg_key }}" become: true become_user: borg diff --git a/sanction-check.sh b/sanction-check.sh @@ -18,7 +18,7 @@ if [ ! -f "$2" ]; then fi ansible-playbook \ - --extra-vars "SANCTION_LIST=$2" \ + --extra-vars "sanction_list=$2" \ --verbose \ --limit "$1" \ --inventory inventories/default \ diff --git a/setup-pixel-borg.sh b/setup-pixel-borg.sh @@ -8,7 +8,7 @@ then exit 1 fi ansible-playbook \ - --extra-vars "PIXEL_BORG_KEY={{ lookup('env', 'PIXEL_BORG_KEY') }}" \ + --extra-vars "pixel_borg_key={{ lookup('env', 'PIXEL_BORG_KEY') }}" \ --inventory inventories/default \ --limit "${1:-spec}" \ --user root \ diff --git a/start-borg-backups.sh b/start-borg-backups.sh @@ -15,7 +15,7 @@ then fi ansible-playbook \ --verbose \ - --extra-vars "BORG_PASSPHRASE={{ lookup('env', 'BORG_PASSPHRASE') }}" \ + --extra-vars "borg_passphrase={{ lookup('env', 'BORG_PASSPHRASE') }}" \ --inventory inventories/default \ --limit "${1:-spec}" \ playbooks/borg-start.yml