feat: enable n8n AI assistant AZ-PRM-1

This commit is contained in:
2026-09-08 10:45:26 +02:00
parent 1772ab207e
commit ef563f1ce1
13 changed files with 887 additions and 744 deletions
@@ -7,8 +7,6 @@
servicePort = config.m3ta.ports.get serviceName;
in {
virtualisation.oci-containers.containers."${serviceName}" = {
# Image contains the Semaphore server plus ansible, terraform,
# opentofu and terragrunt runners.
image = "docker.io/semaphoreui/semaphore:latest";
environment = {
SEMAPHORE_DB_DIALECT = "postgres";
@@ -16,26 +14,24 @@ in {
SEMAPHORE_DB_PORT = "5432";
SEMAPHORE_PLAYBOOK_PATH = "/tmp/semaphore/";
};
# SEMAPHORE_DB (name), SEMAPHORE_DB_USER, SEMAPHORE_DB_PASS and the
# admin bootstrap vars (SEMAPHORE_ADMIN*) come from the agenix secret
# (podman env-file).
environmentFiles = [config.age.secrets.semaphore-env.path];
ports = ["127.0.0.1:${toString servicePort}:3000"];
volumes = [
"semaphore_data:/var/lib/semaphore"
];
# Public DNS: the corporate DNS behind aardvark answers AAAA queries for
# galaxy.ansible.com but not A queries — with no IPv6 route in the web
# network ansible-galaxy downloads failed (EAI_AGAIN / empty responses).
# Bypass with public resolvers; git.az-gruppe.com is publicly resolvable,
# targets connect by IP (same pattern as librechat/homarr on AZ-CLD-1).
extraOptions = ["--network=web" "--ip=10.89.0.17" "--add-host=postgres:10.89.0.1" "--dns=8.8.8.8" "--dns=8.8.4.4"];
extraOptions = [
"--network=web:ip=10.89.0.17"
"--network=vpn-egress"
"--add-host=postgres:10.89.0.1"
"--dns=8.8.8.8"
"--dns=8.8.4.4"
];
};
# Idempotent provisioning of the semaphore role/database on the host
# PostgreSQL 17 (same pattern as atrocore-db-init: initialScript cannot
# be used, the cluster is already initialized and the password must
# never land in the Nix store).
networking.firewall.extraForwardRules = ''
iifname "vpn-egress" oifname "wt0" accept
'';
systemd.services.semaphore-db-init = {
description = "Provision semaphore role/database from agenix secret";
after = ["postgresql.service"];
@@ -49,8 +45,6 @@ in {
RemainAfterExit = true;
};
path = [config.services.postgresql.package];
# Env-file format: plain KEY=value lines (no quotes), same file the
# container consumes.
script = ''
set -euo pipefail
ENV_FILE="${config.age.secrets.semaphore-env.path}"