mirror of
https://github.com/kevinveenbirkenbach/computer-playbook.git
synced 2025-08-15 08:30:46 +02:00
46 lines
1.8 KiB
YAML
46 lines
1.8 KiB
YAML
- name: Load former meta dependencies once
|
|
block:
|
|
- name: Include moved dependency 'srv-web-7-6-https'
|
|
include_role:
|
|
name: srv-web-7-6-https
|
|
- set_fact:
|
|
run_once_srv_web_6_6_tls_core: true
|
|
when: run_once_srv_web_6_6_tls_core is not defined
|
|
- name: "Include flavor '{{ certbot_flavor }}' for '{{ domain }}'"
|
|
include_tasks: "{{ role_path }}/tasks/flavors/{{ certbot_flavor }}.yml"
|
|
|
|
#- name: "Cleanup dedicated cert for {{ domain }}"
|
|
# command: >-
|
|
# certbot delete --cert-name {{ domain }} --non-interactive
|
|
# when:
|
|
# - mode_cleanup | bool
|
|
# # Cleanup mode is enabled
|
|
# - certbot_flavor != 'dedicated'
|
|
# # Wildcard certificate is enabled
|
|
# - domain.split('.') | length == (primary_domain.split('.') | length + 1) and domain.endswith(primary_domain)
|
|
# # AND: The domain is a direct first-level subdomain of the primary domain
|
|
# - domain != primary_domain
|
|
# # The domain is not the primary domain
|
|
# register: certbot_result
|
|
# failed_when: certbot_result.rc != 0 and ("No certificate found with name" not in certbot_result.stderr)
|
|
# changed_when: certbot_result.rc == 0 and ("No certificate found with name" not in certbot_result.stderr)
|
|
|
|
- name: "Find SSL cert folder for '{{ domain }}'"
|
|
cert_folder_find:
|
|
domain: "{{ domain }}"
|
|
cert_base_path: "{{ letsencrypt_live_path }}"
|
|
debug: "{{ enable_debug | default(false) }}"
|
|
register: cert_folder_result
|
|
delegate_to: "{{ inventory_hostname }}"
|
|
changed_when: false
|
|
|
|
- name: "Set ssl_cert_folder fact to '{{ cert_folder_result.folder }}'"
|
|
set_fact:
|
|
ssl_cert_folder: "{{ cert_folder_result.folder }}"
|
|
changed_when: false
|
|
|
|
- name: "Ensure ssl_cert_folder is set for domain {{ domain }}"
|
|
fail:
|
|
msg: "No certificate folder found for domain {{ domain }}"
|
|
when: ssl_cert_folder is undefined or ssl_cert_folder is none
|