mirror of
https://github.com/geerlingguy/ansible-role-certbot.git
synced 2026-08-22 07:50:43 +02:00
Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
9045ec5a59 | ||
|
|
98ea3238ed | ||
|
|
78f4cb5ad5 | ||
|
|
d1cbcde4de | ||
|
|
03f4cc3a99 | ||
|
|
63638f4471 | ||
|
|
4be771f12a | ||
|
|
de52a1f4c8 |
@@ -19,12 +19,12 @@ jobs:
|
|||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Check out the codebase.
|
- name: Check out the codebase.
|
||||||
uses: actions/checkout@v2
|
uses: actions/checkout@v4
|
||||||
with:
|
with:
|
||||||
path: 'geerlingguy.certbot'
|
path: 'geerlingguy.certbot'
|
||||||
|
|
||||||
- name: Set up Python 3.
|
- name: Set up Python 3.
|
||||||
uses: actions/setup-python@v2
|
uses: actions/setup-python@v5
|
||||||
with:
|
with:
|
||||||
python-version: '3.x'
|
python-version: '3.x'
|
||||||
|
|
||||||
@@ -41,35 +41,28 @@ jobs:
|
|||||||
strategy:
|
strategy:
|
||||||
matrix:
|
matrix:
|
||||||
include:
|
include:
|
||||||
- distro: centos8
|
- distro: rockylinux9
|
||||||
playbook: converge.yml
|
playbook: converge.yml
|
||||||
experimental: false
|
experimental: false
|
||||||
- distro: centos7
|
- distro: ubuntu2004
|
||||||
playbook: converge.yml
|
|
||||||
experimental: false
|
|
||||||
- distro: ubuntu1804
|
|
||||||
playbook: converge.yml
|
playbook: converge.yml
|
||||||
experimental: false
|
experimental: false
|
||||||
- distro: debian10
|
- distro: debian10
|
||||||
playbook: converge.yml
|
playbook: converge.yml
|
||||||
experimental: false
|
experimental: false
|
||||||
# Source install started failing recently.
|
|
||||||
# - distro: centos7
|
|
||||||
# playbook: playbook-source-install.yml
|
|
||||||
# experimental: false
|
|
||||||
|
|
||||||
- distro: centos7
|
- distro: rockylinux9
|
||||||
playbook: playbook-snap-install.yml
|
playbook: playbook-snap-install.yml
|
||||||
experimental: true
|
experimental: true
|
||||||
|
|
||||||
steps:
|
steps:
|
||||||
- name: Check out the codebase.
|
- name: Check out the codebase.
|
||||||
uses: actions/checkout@v2
|
uses: actions/checkout@v4
|
||||||
with:
|
with:
|
||||||
path: 'geerlingguy.certbot'
|
path: 'geerlingguy.certbot'
|
||||||
|
|
||||||
- name: Set up Python 3.
|
- name: Set up Python 3.
|
||||||
uses: actions/setup-python@v2
|
uses: actions/setup-python@v5
|
||||||
with:
|
with:
|
||||||
python-version: '3.x'
|
python-version: '3.x'
|
||||||
|
|
||||||
|
|||||||
@@ -22,12 +22,12 @@ jobs:
|
|||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Check out the codebase.
|
- name: Check out the codebase.
|
||||||
uses: actions/checkout@v2
|
uses: actions/checkout@v4
|
||||||
with:
|
with:
|
||||||
path: 'geerlingguy.certbot'
|
path: 'geerlingguy.certbot'
|
||||||
|
|
||||||
- name: Set up Python 3.
|
- name: Set up Python 3.
|
||||||
uses: actions/setup-python@v2
|
uses: actions/setup-python@v5
|
||||||
with:
|
with:
|
||||||
python-version: '3.x'
|
python-version: '3.x'
|
||||||
|
|
||||||
|
|||||||
@@ -14,6 +14,7 @@ certbot_hsts: false
|
|||||||
certbot_create_if_missing: false
|
certbot_create_if_missing: false
|
||||||
certbot_create_method: standalone
|
certbot_create_method: standalone
|
||||||
certbot_admin_email: email@example.com
|
certbot_admin_email: email@example.com
|
||||||
|
certbot_expand: false
|
||||||
|
|
||||||
# Default webroot, overwritten by individual per-cert webroot directories
|
# Default webroot, overwritten by individual per-cert webroot directories
|
||||||
certbot_webroot: /var/www/letsencrypt
|
certbot_webroot: /var/www/letsencrypt
|
||||||
@@ -27,12 +28,15 @@ certbot_certs: []
|
|||||||
# - domains:
|
# - domains:
|
||||||
# - example3.com
|
# - example3.com
|
||||||
|
|
||||||
|
certbot_create_extra_args: ""
|
||||||
|
|
||||||
certbot_create_command: >-
|
certbot_create_command: >-
|
||||||
{{ certbot_script }} certonly --{{ certbot_create_method }}
|
{{ certbot_script }} certonly --{{ certbot_create_method }}
|
||||||
{{ '--hsts' if certbot_hsts else '' }}
|
{{ '--hsts' if certbot_hsts else '' }}
|
||||||
{{ '--test-cert' if certbot_testmode else '' }}
|
{{ '--test-cert' if certbot_testmode else '' }}
|
||||||
--noninteractive --agree-tos
|
--noninteractive --agree-tos
|
||||||
--email {{ cert_item.email | default(certbot_admin_email) }}
|
--email {{ cert_item.email | default(certbot_admin_email) }}
|
||||||
|
{{ '--expand' if certbot_expand else '' }}
|
||||||
{{ '--webroot-path ' if certbot_create_method == 'webroot' else '' }}
|
{{ '--webroot-path ' if certbot_create_method == 'webroot' else '' }}
|
||||||
{{ cert_item.webroot | default(certbot_webroot) if certbot_create_method == 'webroot' else '' }}
|
{{ cert_item.webroot | default(certbot_webroot) if certbot_create_method == 'webroot' else '' }}
|
||||||
{{ certbot_create_extra_args }}
|
{{ certbot_create_extra_args }}
|
||||||
|
|||||||
@@ -2,11 +2,13 @@
|
|||||||
role_name_check: 1
|
role_name_check: 1
|
||||||
dependency:
|
dependency:
|
||||||
name: galaxy
|
name: galaxy
|
||||||
|
options:
|
||||||
|
ignore-errors: true
|
||||||
driver:
|
driver:
|
||||||
name: docker
|
name: docker
|
||||||
platforms:
|
platforms:
|
||||||
- name: instance
|
- name: instance
|
||||||
image: "geerlingguy/docker-${MOLECULE_DISTRO:-centos7}-ansible:latest"
|
image: "geerlingguy/docker-${MOLECULE_DISTRO:-rockylinux9}-ansible:latest"
|
||||||
command: ${MOLECULE_DOCKER_COMMAND:-""}
|
command: ${MOLECULE_DOCKER_COMMAND:-""}
|
||||||
volumes:
|
volumes:
|
||||||
- /sys/fs/cgroup:/sys/fs/cgroup:rw
|
- /sys/fs/cgroup:/sys/fs/cgroup:rw
|
||||||
|
|||||||
@@ -1,9 +1,4 @@
|
|||||||
---
|
---
|
||||||
- name: Check if certificate already exists.
|
|
||||||
stat:
|
|
||||||
path: /etc/letsencrypt/live/{{ cert_item.domains | first | replace('*.', '') }}/cert.pem
|
|
||||||
register: letsencrypt_cert
|
|
||||||
|
|
||||||
- name: Ensure pre and post hook folders exist.
|
- name: Ensure pre and post hook folders exist.
|
||||||
file:
|
file:
|
||||||
path: /etc/letsencrypt/renewal-hooks/{{ item }}
|
path: /etc/letsencrypt/renewal-hooks/{{ item }}
|
||||||
@@ -39,4 +34,5 @@
|
|||||||
|
|
||||||
- name: Generate new certificate if one doesn't exist.
|
- name: Generate new certificate if one doesn't exist.
|
||||||
command: "{{ certbot_create_command }}"
|
command: "{{ certbot_create_command }}"
|
||||||
when: not letsencrypt_cert.stat.exists
|
register: certbot_create
|
||||||
|
changed_when: "'no action taken' not in certbot_create.stdout"
|
||||||
|
|||||||
@@ -1,9 +1,4 @@
|
|||||||
---
|
---
|
||||||
- name: Check if certificate already exists.
|
|
||||||
stat:
|
|
||||||
path: /etc/letsencrypt/live/{{ cert_item.domains | first }}/cert.pem
|
|
||||||
register: letsencrypt_cert
|
|
||||||
|
|
||||||
- name: Create webroot directory if it doesn't exist yet
|
- name: Create webroot directory if it doesn't exist yet
|
||||||
file:
|
file:
|
||||||
path: "{{ cert_item.webroot | default(certbot_webroot) }}"
|
path: "{{ cert_item.webroot | default(certbot_webroot) }}"
|
||||||
@@ -11,4 +6,5 @@
|
|||||||
|
|
||||||
- name: Generate new certificate if one doesn't exist.
|
- name: Generate new certificate if one doesn't exist.
|
||||||
command: "{{ certbot_create_command }}"
|
command: "{{ certbot_create_command }}"
|
||||||
when: not letsencrypt_cert.stat.exists
|
register: certbot_create
|
||||||
|
changed_when: "'no action taken' not in certbot_create.stdout"
|
||||||
|
|||||||
+3
-22
@@ -1,30 +1,11 @@
|
|||||||
---
|
---
|
||||||
# See: https://github.com/geerlingguy/ansible-role-certbot/issues/107
|
# See: https://github.com/geerlingguy/ansible-role-certbot/issues/107
|
||||||
- block:
|
- name: Ensure dnf-plugins are installed on Rocky/AlmaLinux.
|
||||||
|
|
||||||
- name: Ensure dnf-plugins are installed on CentOS 8+.
|
|
||||||
yum:
|
yum:
|
||||||
name: dnf-plugins-core
|
name: dnf-plugins-core
|
||||||
state: present
|
state: present
|
||||||
|
|
||||||
- block:
|
- name: Enable DNF module for Rocky/AlmaLinux.
|
||||||
|
|
||||||
- name: Enable DNF module for CentOS 8.3+.
|
|
||||||
shell: |
|
shell: |
|
||||||
dnf config-manager --set-enabled powertools
|
dnf config-manager --set-enabled crb
|
||||||
register: dnf_module_enable
|
|
||||||
changed_when: false
|
changed_when: false
|
||||||
|
|
||||||
when: ansible_facts['distribution_version'] is version('8.3', '>=')
|
|
||||||
|
|
||||||
- name: Enable DNF module for CentOS 8.0–8.2.
|
|
||||||
shell: |
|
|
||||||
dnf config-manager --set-enabled PowerTools
|
|
||||||
register: dnf_module_enable
|
|
||||||
changed_when: false
|
|
||||||
|
|
||||||
when: ansible_facts['distribution_version'] is version('8.2', '<=')
|
|
||||||
|
|
||||||
when:
|
|
||||||
- ansible_distribution == 'CentOS'
|
|
||||||
- ansible_distribution_major_version | int >= 8
|
|
||||||
|
|||||||
Reference in New Issue
Block a user