- hosts.ini: underscore group names, hostname aliases with ansible_host - move ansible_user/ansible_port to group_vars/all.yml - rename group_vars files to match underscore group names - trim sftp group_vars to its only override (password auth off) - run.yml: load moved secrets file (group_vars/secrets.yml) - untrack .DS_Store, extend .gitignore - prefill root/ansible/server READMEs, add jira + cloud server folders - update CLAUDE.md to match Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
3.3 KiB
3.3 KiB
CLAUDE.md
This file provides guidance to Claude Code (claude.ai/code) when working with code in this repository.
Rules Set
- Ask, don't assume. If something is unclear, ask before writing a single line. Never make silent assumptions about intent, architecture, or requirements.
- Simplest solution first. Always implement the simplest thing that could work. Do not add abstractions or flexibility that weren't explicitly requested.
- Don't touch unrelated code. If a file or function is not directly part of the current task, do not modify it, even if you think it could be improved.
- Flag uncertainty explicitly. If you are not confident about an approach or technical detail, say so before proceeding. Confidence without certainty causes more damage than admitting a gap.
Repository Purpose
Infrastructure as Code and runbooks for Phytron's server infrastructure. Global configuration is done via Ansible; host-specific documentation, scripts, and files live under server/.
Structure
ansible/ # Global settings & configuration for all servers
hosts.ini # Inventory: all existing and planned servers with IPs.
# One group per host; group names use underscores
# (phy_z_srv_git), host aliases the real hostnames
# (phy-z-srv-git ansible_host=<IP>)
group_vars/all.yml # Defaults shared by all hosts (incl. ansible_user/port)
group_vars/<group>.yml # Per-host overrides ONLY — no copies of all.yml values
group_vars/secrets.yml # ansible-vault encrypted secrets — never commit plaintext
run.yml # Main playbook
playbooks/ # Utility playbooks (update.yml, shutdown.yml)
roles/ # Custom roles (e.g. nextcloud)
requirements.yml # External Galaxy roles (geerlingguy.*, ...)
justfile # Task runner: just run HOST, just reqs, just vault ACTION
server/<hostname>/ # Host-specific docs, scripts, files
README.md # Server documentation, filled gradually
manuals/ # Runbooks, dated YYYYMMDD-<topic>.md
HW.md # Hardware specs (where relevant)
Servers
| Hostname | IP | Status |
|---|---|---|
| phy-z-srv-jira | 192.168.66.41 | configured |
| phy-z-srv-cloud | 192.168.66.66 | configured (Nextcloud) |
| phy-z-srv-git | 192.168.66.67 | configured |
| phy-z-dmz-sftp01 | 192.168.66.68 | configured |
| phy-z-srv-gpu01 | 192.168.66.69 | planned — setup is the next task |
Conventions
- Ansible commands run from
ansible/, preferably via thejustfile(e.g.just run <HOST>). - Secrets go into
ansible/group_vars/secrets.yml, encrypted with ansible-vault. Never commit plaintext secrets. - SSH password authentication stays enabled for easy access (servers are not reachable from outside); exception: DMZ hosts like phy-z-dmz-sftp01 are key-only.
- Dated documents (runbooks, assessments) use the
YYYYMMDD-<topic>.mdnaming scheme. - New servers get: an entry in
hosts.ini, agroup_vars/<group>.yml(overrides only), and aserver/<hostname>/folder with a README.