Ansible Role - Certbot (for Let's Encrypt)
You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
ansible-role-certbot/tasks/create-cert-standalone.yml

28 lines
1.1 KiB

---
- name: Check if certificate exists or has been changed.
import_tasks: test-cert-exists.yml
- name: Stop services to allow certbot to generate a cert.
service:
name: "{{ item }}"
state: stopped
when: not letsencrypt_cert_exists.stat.exists or letsencrypt_cert_updated
with_items: "{{ certbot_create_standalone_stop_services }}"
- name: Generate new certificate if one doesn't exist.
shell: "{{ certbot_create_command }}"
when: not letsencrypt_cert_exists.stat.exists or letsencrypt_cert_updated
- name: Persist domain list to /etc/letsencrypt/domains-{{ cert_item.domains | first }}.
copy:
dest: /etc/letsencrypt/domains-{{ cert_item.domains | first }}.json
# Add a space here because of https://github.com/ansible/ansible/issues/6077
content: " {{ cert_item.domains | to_json }}\n"
when: not letsencrypt_cert_exists.stat.exists or letsencrypt_cert_updated
- name: Start services after cert has been generated.
service:
name: "{{ item }}"
state: started
when: not letsencrypt_cert_exists.stat.exists or letsencrypt_cert_updated
with_items: "{{ certbot_create_standalone_stop_services }}"