Compare commits

..
3 Commits
9 changed files with 52 additions and 29 deletions
+3 -1
View File
@@ -40,8 +40,10 @@ script:
- 'sudo docker exec --tty "$(cat ${container_id})" env TERM=xterm ansible-playbook /etc/ansible/roles/role_under_test/tests/test.yml' - 'sudo docker exec --tty "$(cat ${container_id})" env TERM=xterm ansible-playbook /etc/ansible/roles/role_under_test/tests/test.yml'
# Test role idempotence. # Test role idempotence.
- idempotence=$(mktemp)
- sudo docker exec "$(cat ${container_id})" ansible-playbook /etc/ansible/roles/role_under_test/tests/test.yml | tee -a ${idempotence}
- > - >
sudo docker exec "$(cat ${container_id})" ansible-playbook /etc/ansible/roles/role_under_test/tests/test.yml tail ${idempotence}
| grep -q 'changed=0.*failed=0' | grep -q 'changed=0.*failed=0'
&& (echo 'Idempotence test: pass' && exit 0) && (echo 'Idempotence test: pass' && exit 0)
|| (echo 'Idempotence test: fail' && exit 1) || (echo 'Idempotence test: fail' && exit 1)
+31 -5
View File
@@ -1,16 +1,24 @@
# Ansible Role: Let's Encrypt # Ansible Role: Certbot (for Let's Encrypt)
[![Build Status](https://travis-ci.org/geerlingguy/ansible-role-letsencrypt.svg?branch=master)](https://travis-ci.org/geerlingguy/ansible-role-letsencrypt) [![Build Status](https://travis-ci.org/geerlingguy/ansible-role-certbot.svg?branch=master)](https://travis-ci.org/geerlingguy/ansible-role-certbot)
Installs Let's Encrypt for RHEL/CentOS or Debian/Ubuntu. Installs Certbot (for Let's Encrypt) for RHEL/CentOS or Debian/Ubuntu.
## Requirements ## Requirements
Let's Encrypt requires `git` to be installed. You can install using the `geerlingguy.git` role. Certbot requires Git to be installed. You can install Git using the `geerlingguy.git` role.
## Role Variables ## Role Variables
None. certbot_repo: https://github.com/certbot/certbot.git
certbot_version: master
certbot_keep_updated: yes
Certbot code repository options. This role clones the agent from the configured repo, then makes the `certbot-auto` script executable.
certbot_dir: /opt/certbot
The directory inside which Certbot will be cloned.
## Dependencies ## Dependencies
@@ -22,6 +30,24 @@ None.
roles: roles:
- geerlingguy.letsencrypt - geerlingguy.letsencrypt
After installation, you can create certificates using the `certbot-auto` script, which by default is installed inside the configured `certbot_dir`, so by default, `/opt/certbot/certbot-auto`. Here are some example commands to configure certificates with Certbot:
# Automatically add certs for all Apache virtualhosts (use with caution!).
/opt/certbot/certbot-auto --apache
# Generate certs, but don't modify Apache configuration (safer).
/opt/certbot/certbot-auto --apache certonly
To set up renewals, you should run the following command periodically (e.g. once or twice per day):
/opt/certbot/certbot-auto renew --quiet --no-self-upgrade
You can test the auto-renewal (without actually renewing the cert) with the command:
/opt/certbot/certbot-auto renew --dry-run
See full documentation and options on the [Certbot website](https://certbot.eff.org/).
## License ## License
MIT / BSD MIT / BSD
+4 -4
View File
@@ -1,6 +1,6 @@
--- ---
letsencrypt_repo: https://github.com/letsencrypt/letsencrypt certbot_repo: https://github.com/certbot/certbot.git
letsencrypt_version: master certbot_version: master
letsencrypt_keep_updated: yes certbot_keep_updated: yes
letsencrypt_dir: /opt/letsencrypt certbot_dir: /opt/certbot
+1 -1
View File
@@ -3,7 +3,7 @@ dependencies: []
galaxy_info: galaxy_info:
author: geerlingguy author: geerlingguy
description: "Let's Encrypt for RHEL/CentOS and Debian/Ubuntu." description: "Certbot (for Let's Encrypt) for RHEL/CentOS and Debian/Ubuntu."
company: "Midwestern Mac, LLC" company: "Midwestern Mac, LLC"
license: "license (BSD, MIT)" license: "license (BSD, MIT)"
min_ansible_version: 1.8 min_ansible_version: 1.8
+10 -5
View File
@@ -1,7 +1,12 @@
--- ---
- name: Clone Let's Encrypt into configured directory. - name: Clone Certbot into configured directory.
git: git:
repo: "{{ letsencrypt_repo }}" repo: "{{ certbot_repo }}"
dest: "{{ letsencrypt_dir }}" dest: "{{ certbot_dir }}"
version: "{{ letsencrypt_version }}" version: "{{ certbot_version }}"
update: "{{ letsencrypt_keep_updated }}" update: "{{ certbot_keep_updated }}"
- name: Ensure certbot-auto is executable.
file:
path: "{{ certbot_dir }}/certbot-auto"
mode: 0755
+1 -5
View File
@@ -3,17 +3,13 @@ FROM centos:6
# Install Ansible # Install Ansible
RUN yum -y update; yum clean all; RUN yum -y update; yum clean all;
RUN yum -y install epel-release RUN yum -y install epel-release
RUN yum -y install git python-setuptools gcc sudo libffi-devel python-devel openssl-devel RUN yum -y install git ansible sudo
RUN yum clean all RUN yum clean all
RUN easy_install pip
RUN pip install ansible
# Disable requiretty # Disable requiretty
RUN sed -i -e 's/^\(Defaults\s*requiretty\)/#--- \1/' /etc/sudoers RUN sed -i -e 's/^\(Defaults\s*requiretty\)/#--- \1/' /etc/sudoers
# Install Ansible inventory file # Install Ansible inventory file
RUN mkdir - p /etc/ansible
RUN echo -e '[local]\nlocalhost ansible_connection=local' > /etc/ansible/hosts RUN echo -e '[local]\nlocalhost ansible_connection=local' > /etc/ansible/hosts
CMD ["/usr/sbin/init"] CMD ["/usr/sbin/init"]
+2 -4
View File
@@ -13,16 +13,14 @@ rm -f /lib/systemd/system/basic.target.wants/*; \
rm -f /lib/systemd/system/anaconda.target.wants/*; rm -f /lib/systemd/system/anaconda.target.wants/*;
# Install Ansible # Install Ansible
RUN yum -y install git python-setuptools gcc sudo libffi-devel python-devel openssl-devel RUN yum -y install epel-release
RUN yum -y install git ansible sudo
RUN yum clean all RUN yum clean all
RUN easy_install pip
RUN pip install ansible
# Disable requiretty # Disable requiretty
RUN sed -i -e 's/^\(Defaults\s*requiretty\)/#--- \1/' /etc/sudoers RUN sed -i -e 's/^\(Defaults\s*requiretty\)/#--- \1/' /etc/sudoers
# Install Ansible inventory file # Install Ansible inventory file
RUN mkdir - p /etc/ansible
RUN echo -e '[local]\nlocalhost ansible_connection=local' > /etc/ansible/hosts RUN echo -e '[local]\nlocalhost ansible_connection=local' > /etc/ansible/hosts
VOLUME ["/sys/fs/cgroup"] VOLUME ["/sys/fs/cgroup"]
-2
View File
@@ -1,2 +0,0 @@
---
samba_daemon: smbd
-2
View File
@@ -1,2 +0,0 @@
---
samba_daemon: smb