mirror of
https://github.com/geerlingguy/ansible-role-certbot.git
synced 2026-08-22 07:50:43 +02:00
Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
ca23b73996 | ||
|
|
7daaa25cf2 | ||
|
|
e9f5e5e30f | ||
|
|
c762892bb1 | ||
|
|
65071dd992 | ||
|
|
444064222b |
+25
-18
@@ -2,20 +2,24 @@
|
|||||||
sudo: required
|
sudo: required
|
||||||
|
|
||||||
env:
|
env:
|
||||||
- distribution: centos
|
- repository: geerlingguy/docker-centos7-ansible
|
||||||
version: 6
|
version: latest
|
||||||
init: /sbin/init
|
|
||||||
run_opts: ""
|
|
||||||
- distribution: centos
|
|
||||||
version: 7
|
|
||||||
init: /usr/lib/systemd/systemd
|
init: /usr/lib/systemd/systemd
|
||||||
run_opts: "--privileged --volume=/sys/fs/cgroup:/sys/fs/cgroup:ro"
|
run_opts: "--privileged --volume=/sys/fs/cgroup:/sys/fs/cgroup:ro"
|
||||||
- distribution: ubuntu
|
- repository: geerlingguy/docker-centos6-ansible
|
||||||
version: 14.04
|
version: latest
|
||||||
init: /sbin/init
|
init: /sbin/init
|
||||||
run_opts: ""
|
run_opts: ""
|
||||||
- distribution: ubuntu
|
- repository: geerlingguy/docker-ubuntu1604-ansible
|
||||||
version: 12.04
|
version: latest
|
||||||
|
init: /lib/systemd/systemd
|
||||||
|
run_opts: "--privileged --volume=/sys/fs/cgroup:/sys/fs/cgroup:ro"
|
||||||
|
- repository: geerlingguy/docker-ubuntu1404-ansible
|
||||||
|
version: latest
|
||||||
|
init: /sbin/init
|
||||||
|
run_opts: ""
|
||||||
|
- repository: geerlingguy/docker-ubuntu1204-ansible
|
||||||
|
version: latest
|
||||||
init: /sbin/init
|
init: /sbin/init
|
||||||
run_opts: ""
|
run_opts: ""
|
||||||
|
|
||||||
@@ -23,15 +27,16 @@ services:
|
|||||||
- docker
|
- docker
|
||||||
|
|
||||||
before_install:
|
before_install:
|
||||||
# Pull container
|
# Pull container.
|
||||||
- 'sudo docker pull ${distribution}:${version}'
|
- 'sudo docker pull ${repository}:${version}'
|
||||||
# Customize container
|
|
||||||
- 'sudo docker build --rm=true --file=tests/Dockerfile.${distribution}-${version} --tag=${distribution}-${version}:ansible tests'
|
|
||||||
|
|
||||||
script:
|
script:
|
||||||
- container_id=$(mktemp)
|
- container_id=$(mktemp)
|
||||||
# Run container in detached state
|
# Run container in detached state.
|
||||||
- 'sudo docker run --detach --volume="${PWD}":/etc/ansible/roles/role_under_test:ro ${run_opts} ${distribution}-${version}:ansible "${init}" > "${container_id}"'
|
- 'sudo docker run --detach --volume="${PWD}":/etc/ansible/roles/role_under_test:ro ${run_opts} ${repository}:${version} "${init}" > "${container_id}"'
|
||||||
|
|
||||||
|
# Install dependencies.
|
||||||
|
- 'sudo docker exec "$(cat ${container_id})" ansible-galaxy install -r /etc/ansible/roles/role_under_test/tests/requirements.yml'
|
||||||
|
|
||||||
# Ansible syntax check.
|
# Ansible syntax check.
|
||||||
- 'sudo docker exec --tty "$(cat ${container_id})" env TERM=xterm ansible-playbook /etc/ansible/roles/role_under_test/tests/test.yml --syntax-check'
|
- 'sudo docker exec --tty "$(cat ${container_id})" env TERM=xterm ansible-playbook /etc/ansible/roles/role_under_test/tests/test.yml --syntax-check'
|
||||||
@@ -40,13 +45,15 @@ script:
|
|||||||
- 'sudo docker exec --tty "$(cat ${container_id})" env TERM=xterm ansible-playbook /etc/ansible/roles/role_under_test/tests/test.yml'
|
- 'sudo docker exec --tty "$(cat ${container_id})" env TERM=xterm ansible-playbook /etc/ansible/roles/role_under_test/tests/test.yml'
|
||||||
|
|
||||||
# Test role idempotence.
|
# Test role idempotence.
|
||||||
|
- idempotence=$(mktemp)
|
||||||
|
- sudo docker exec "$(cat ${container_id})" ansible-playbook /etc/ansible/roles/role_under_test/tests/test.yml | tee -a ${idempotence}
|
||||||
- >
|
- >
|
||||||
sudo docker exec "$(cat ${container_id})" ansible-playbook /etc/ansible/roles/role_under_test/tests/test.yml
|
tail ${idempotence}
|
||||||
| grep -q 'changed=0.*failed=0'
|
| grep -q 'changed=0.*failed=0'
|
||||||
&& (echo 'Idempotence test: pass' && exit 0)
|
&& (echo 'Idempotence test: pass' && exit 0)
|
||||||
|| (echo 'Idempotence test: fail' && exit 1)
|
|| (echo 'Idempotence test: fail' && exit 1)
|
||||||
|
|
||||||
# Clean up
|
# Clean up.
|
||||||
- 'sudo docker stop "$(cat ${container_id})"'
|
- 'sudo docker stop "$(cat ${container_id})"'
|
||||||
|
|
||||||
notifications:
|
notifications:
|
||||||
|
|||||||
@@ -1,16 +1,24 @@
|
|||||||
# Ansible Role: Let's Encrypt
|
# Ansible Role: Certbot (for Let's Encrypt)
|
||||||
|
|
||||||
[](https://travis-ci.org/geerlingguy/ansible-role-letsencrypt)
|
[](https://travis-ci.org/geerlingguy/ansible-role-certbot)
|
||||||
|
|
||||||
Installs Let's Encrypt for RHEL/CentOS or Debian/Ubuntu.
|
Installs Certbot (for Let's Encrypt) for RHEL/CentOS or Debian/Ubuntu.
|
||||||
|
|
||||||
## Requirements
|
## Requirements
|
||||||
|
|
||||||
Let's Encrypt requires `git` to be installed. You can install using the `geerlingguy.git` role.
|
Certbot requires Git to be installed. You can install Git using the `geerlingguy.git` role.
|
||||||
|
|
||||||
## Role Variables
|
## Role Variables
|
||||||
|
|
||||||
None.
|
certbot_repo: https://github.com/certbot/certbot.git
|
||||||
|
certbot_version: master
|
||||||
|
certbot_keep_updated: yes
|
||||||
|
|
||||||
|
Certbot code repository options. This role clones the agent from the configured repo, then makes the `certbot-auto` script executable.
|
||||||
|
|
||||||
|
certbot_dir: /opt/certbot
|
||||||
|
|
||||||
|
The directory inside which Certbot will be cloned.
|
||||||
|
|
||||||
## Dependencies
|
## Dependencies
|
||||||
|
|
||||||
@@ -22,6 +30,24 @@ None.
|
|||||||
roles:
|
roles:
|
||||||
- geerlingguy.letsencrypt
|
- geerlingguy.letsencrypt
|
||||||
|
|
||||||
|
After installation, you can create certificates using the `certbot-auto` script, which by default is installed inside the configured `certbot_dir`, so by default, `/opt/certbot/certbot-auto`. Here are some example commands to configure certificates with Certbot:
|
||||||
|
|
||||||
|
# Automatically add certs for all Apache virtualhosts (use with caution!).
|
||||||
|
/opt/certbot/certbot-auto --apache
|
||||||
|
|
||||||
|
# Generate certs, but don't modify Apache configuration (safer).
|
||||||
|
/opt/certbot/certbot-auto --apache certonly
|
||||||
|
|
||||||
|
To set up renewals, you should run the following command periodically (e.g. once or twice per day):
|
||||||
|
|
||||||
|
/opt/certbot/certbot-auto renew --quiet --no-self-upgrade
|
||||||
|
|
||||||
|
You can test the auto-renewal (without actually renewing the cert) with the command:
|
||||||
|
|
||||||
|
/opt/certbot/certbot-auto renew --dry-run
|
||||||
|
|
||||||
|
See full documentation and options on the [Certbot website](https://certbot.eff.org/).
|
||||||
|
|
||||||
## License
|
## License
|
||||||
|
|
||||||
MIT / BSD
|
MIT / BSD
|
||||||
|
|||||||
+4
-4
@@ -1,6 +1,6 @@
|
|||||||
---
|
---
|
||||||
letsencrypt_repo: https://github.com/letsencrypt/letsencrypt
|
certbot_repo: https://github.com/certbot/certbot.git
|
||||||
letsencrypt_version: master
|
certbot_version: master
|
||||||
letsencrypt_keep_updated: yes
|
certbot_keep_updated: yes
|
||||||
|
|
||||||
letsencrypt_dir: /opt/letsencrypt
|
certbot_dir: /opt/certbot
|
||||||
|
|||||||
+1
-1
@@ -3,7 +3,7 @@ dependencies: []
|
|||||||
|
|
||||||
galaxy_info:
|
galaxy_info:
|
||||||
author: geerlingguy
|
author: geerlingguy
|
||||||
description: "Let's Encrypt for RHEL/CentOS and Debian/Ubuntu."
|
description: "Certbot (for Let's Encrypt) for RHEL/CentOS and Debian/Ubuntu."
|
||||||
company: "Midwestern Mac, LLC"
|
company: "Midwestern Mac, LLC"
|
||||||
license: "license (BSD, MIT)"
|
license: "license (BSD, MIT)"
|
||||||
min_ansible_version: 1.8
|
min_ansible_version: 1.8
|
||||||
|
|||||||
+10
-5
@@ -1,7 +1,12 @@
|
|||||||
---
|
---
|
||||||
- name: Clone Let's Encrypt into configured directory.
|
- name: Clone Certbot into configured directory.
|
||||||
git:
|
git:
|
||||||
repo: "{{ letsencrypt_repo }}"
|
repo: "{{ certbot_repo }}"
|
||||||
dest: "{{ letsencrypt_dir }}"
|
dest: "{{ certbot_dir }}"
|
||||||
version: "{{ letsencrypt_version }}"
|
version: "{{ certbot_version }}"
|
||||||
update: "{{ letsencrypt_keep_updated }}"
|
update: "{{ certbot_keep_updated }}"
|
||||||
|
|
||||||
|
- name: Ensure certbot-auto is executable.
|
||||||
|
file:
|
||||||
|
path: "{{ certbot_dir }}/certbot-auto"
|
||||||
|
mode: 0755
|
||||||
|
|||||||
@@ -1,19 +0,0 @@
|
|||||||
FROM centos:6
|
|
||||||
|
|
||||||
# Install Ansible
|
|
||||||
RUN yum -y update; yum clean all;
|
|
||||||
RUN yum -y install epel-release
|
|
||||||
RUN yum -y install git python-setuptools gcc sudo libffi-devel python-devel openssl-devel
|
|
||||||
RUN yum clean all
|
|
||||||
RUN easy_install pip
|
|
||||||
RUN pip install ansible
|
|
||||||
|
|
||||||
|
|
||||||
# Disable requiretty
|
|
||||||
RUN sed -i -e 's/^\(Defaults\s*requiretty\)/#--- \1/' /etc/sudoers
|
|
||||||
|
|
||||||
# Install Ansible inventory file
|
|
||||||
RUN mkdir - p /etc/ansible
|
|
||||||
RUN echo -e '[local]\nlocalhost ansible_connection=local' > /etc/ansible/hosts
|
|
||||||
|
|
||||||
CMD ["/usr/sbin/init"]
|
|
||||||
@@ -1,29 +0,0 @@
|
|||||||
FROM centos:7
|
|
||||||
|
|
||||||
# Install systemd -- See https://hub.docker.com/_/centos/
|
|
||||||
RUN yum -y swap -- remove fakesystemd -- install systemd systemd-libs
|
|
||||||
RUN yum -y update; yum clean all; \
|
|
||||||
(cd /lib/systemd/system/sysinit.target.wants/; for i in *; do [ $i == systemd-tmpfiles-setup.service ] || rm -f $i; done); \
|
|
||||||
rm -f /lib/systemd/system/multi-user.target.wants/*; \
|
|
||||||
rm -f /etc/systemd/system/*.wants/*; \
|
|
||||||
rm -f /lib/systemd/system/local-fs.target.wants/*; \
|
|
||||||
rm -f /lib/systemd/system/sockets.target.wants/*udev*; \
|
|
||||||
rm -f /lib/systemd/system/sockets.target.wants/*initctl*; \
|
|
||||||
rm -f /lib/systemd/system/basic.target.wants/*; \
|
|
||||||
rm -f /lib/systemd/system/anaconda.target.wants/*;
|
|
||||||
|
|
||||||
# Install Ansible
|
|
||||||
RUN yum -y install git python-setuptools gcc sudo libffi-devel python-devel openssl-devel
|
|
||||||
RUN yum clean all
|
|
||||||
RUN easy_install pip
|
|
||||||
RUN pip install ansible
|
|
||||||
|
|
||||||
# Disable requiretty
|
|
||||||
RUN sed -i -e 's/^\(Defaults\s*requiretty\)/#--- \1/' /etc/sudoers
|
|
||||||
|
|
||||||
# Install Ansible inventory file
|
|
||||||
RUN mkdir - p /etc/ansible
|
|
||||||
RUN echo -e '[local]\nlocalhost ansible_connection=local' > /etc/ansible/hosts
|
|
||||||
|
|
||||||
VOLUME ["/sys/fs/cgroup"]
|
|
||||||
CMD ["/usr/sbin/init"]
|
|
||||||
@@ -1,11 +0,0 @@
|
|||||||
FROM ubuntu:12.04
|
|
||||||
RUN apt-get update
|
|
||||||
|
|
||||||
# Install Ansible
|
|
||||||
RUN apt-get install -y software-properties-common python-software-properties git
|
|
||||||
RUN apt-add-repository -y ppa:ansible/ansible
|
|
||||||
RUN apt-get update
|
|
||||||
RUN apt-get install -y ansible
|
|
||||||
|
|
||||||
# Install Ansible inventory file
|
|
||||||
RUN echo "[local]\nlocalhost ansible_connection=local" > /etc/ansible/hosts
|
|
||||||
@@ -1,11 +0,0 @@
|
|||||||
FROM ubuntu:14.04
|
|
||||||
RUN apt-get update
|
|
||||||
|
|
||||||
# Install Ansible
|
|
||||||
RUN apt-get install -y software-properties-common git
|
|
||||||
RUN apt-add-repository -y ppa:ansible/ansible
|
|
||||||
RUN apt-get update
|
|
||||||
RUN apt-get install -y ansible
|
|
||||||
|
|
||||||
# Install Ansible inventory file
|
|
||||||
RUN echo "[local]\nlocalhost ansible_connection=local" > /etc/ansible/hosts
|
|
||||||
@@ -0,0 +1,2 @@
|
|||||||
|
---
|
||||||
|
- src: geerlingguy.git
|
||||||
@@ -1,5 +1,11 @@
|
|||||||
---
|
---
|
||||||
- hosts: all
|
- hosts: all
|
||||||
|
|
||||||
|
pre_tasks:
|
||||||
|
- name: Update apt cache.
|
||||||
|
apt: update_cache=yes
|
||||||
|
when: ansible_distribution == 'Ubuntu'
|
||||||
|
|
||||||
roles:
|
roles:
|
||||||
|
- geerlingguy.git
|
||||||
- role_under_test
|
- role_under_test
|
||||||
|
|||||||
@@ -1,2 +0,0 @@
|
|||||||
---
|
|
||||||
samba_daemon: smbd
|
|
||||||
@@ -1,2 +0,0 @@
|
|||||||
---
|
|
||||||
samba_daemon: smb
|
|
||||||
Reference in New Issue
Block a user