# Host vars for: gpu-node (GPU workstation — spot K3s agent) ansible_python_interpreter: /usr/bin/python3.12 # ── common ───────────────────────────────────────────────────────────────────── timezone: Asia/Tokyo username: nik base_packages: - curl - git - htop - vim - wget - ca-certificates - gnupg - lsb-release - build-essential ufw_allowed_ports: - { port: "430", proto: tcp, comment: "SSH" } - { port: "11434", proto: tcp, comment: "Ollama API" } - { port: "61208", proto: tcp, comment: "Glances web UI" } # host_vars replaces (not merges) the common role's ufw_allowed_ports # default, so the K3s/flannel ports below must be repeated here - without # them, cross-node pod traffic (e.g. DNS to CoreDNS on nik-debian) blackholes # even though kubectl logs/exec/stats still work (those tunnel through the # agent's outbound connection to the k3s server on 6443, not a direct # inbound connection). - { port: "6443", proto: tcp, comment: "K3s API server" } - { port: "10250", proto: tcp, comment: "Kubelet", src: "10.10.40.0/24" } - { port: "8472", proto: udp, comment: "Flannel VXLAN", src: "10.10.40.0/24" } data_dirs: - /data/tts-gateway # ── nvidia ───────────────────────────────────────────────────────────────────── nvidia_driver_version: "570" cuda_version: "12-8" # ── k3s-agent ────────────────────────────────────────────────────────────────── k3s_server_url: "https://10.10.40.53:6443" k3s_node_token: "{{ vault_k3s_node_token }}" # Check current cluster version with: k3s --version on minisforum # Kept in sync with roles/k3s-server and roles/k3s-agent defaults — all three # must match; see ansible/README.md "K3s version" note. k3s_version: "v1.32.4+k3s1" k3s_node_labels: node-role: gpu nik4nao.com/node-type: spot nik4nao.com/gpu: "true" k3s_node_taints: - "spot=true:NoSchedule" # ── ollama ───────────────────────────────────────────────────────────────────── ollama_port: 11434 ollama_models: - qwen3:4b ollama_models_dir: /usr/share/ollama/.ollama/models # ── glances ──────────────────────────────────────────────────────────────────── # no extra vars — uses role defaults