# Generated by mcp/build_host_files.py from inventory.yaml. # Do NOT edit by hand — your changes will be overwritten. # Source of truth: ../inventory.yaml name: netbird-vps kind: external os: linux role: netbird-mgmt state: active mesh: netbird: ip: 100.122.165.149 fqdn: netbird-ionos.netbird.selfhosted mesh_globals: primary: netbird accepted: - netbird - tailscale ssh: user: root runs: - authentik services_hosted: - name: authentik url: https://auth.hubris.network backend: netbird-vps doc_page: knowledge/wiki/containers/106-auth-outpost.md note: core runs on the VPS since 2026-05-31; LAN forward-auth outpost is auth-outpost (LXC 106) at 192.168.8.6:9000. Previous backend value "authentik" referenced the retired embedded-outpost host (LXC 124). risk_notes: "SSO provider \u2014 outage locks login to OIDC/forward-auth services" notes: - "Public IONOS VPS \u2014 hosts the vanilla netbird mgmt+signal+relay+dashboard stack + host coturn (see\ \ infrastructure/vps-hardening.md + infrastructure/mesh.md changelog 2026-05-21)." - NOT a homelab client. No /etc/age/key.txt, no /opt/homelab-context clone. Managed via ssh from hubris; sshd is locked to hubris's pubkey. - Public IPv4 82.165.190.79. Auto-patching via unattended-upgrades. - Configs rendered by `homelab render-vps-configs` from vps/turnserver.conf.tmpl + vps/management.json.tmpl, with secrets decrypted from secrets/turn-shared-secret.yaml + secrets/netbird-authentik-oidc.yaml on hubris. mcp_endpoint: https://mcp.hubris.network/mcp secrets_issuance_endpoint: https://secrets.hubris.network/issue