ansible/roles/certbot/tasks/main.yml

39 lines
810 B
YAML
Raw Permalink Normal View History

2020-05-09 12:54:38 +02:00
---
- name: Install certbot and RFC2136 plugin
2020-05-09 12:54:38 +02:00
apt:
update_cache: true
name:
- certbot
- python3-certbot-dns-rfc2136
register: pkg_result
2020-05-09 12:54:38 +02:00
retries: 3
until: pkg_result is succeeded
2020-05-09 12:54:38 +02:00
- name: Create /etc/letsencrypt/conf.d
file:
path: /etc/letsencrypt/conf.d
state: directory
2020-11-04 19:31:50 +01:00
mode: 0755
2020-05-09 12:54:38 +02:00
- name: Lookup DNS masters IPv4
set_fact:
dns_masters_ipv4:
- "10.128.0.30"
cacheable: true
- name: Add DNS credentials
template:
src: letsencrypt/rfc2136.ini.j2
dest: /etc/letsencrypt/rfc2136.ini
mode: 0600
owner: root
2020-05-09 12:54:38 +02:00
- name: Add Certbot configuration
template:
src: "letsencrypt/conf.d/certname.ini.j2"
dest: "/etc/letsencrypt/conf.d/{{ certbot.certname }}.ini"
mode: 0644
2021-01-19 23:19:25 +01:00
notify:
- Generate certificates
- Reload nginx