mirror of
https://github.com/ansibleguy/infra_apache.git
synced 2026-10-06 09:42:51 +02:00
init
This commit is contained in:
@@ -0,0 +1,68 @@
|
||||
---
|
||||
|
||||
- name: "Apache | Debian | Config | Site '{{ name }}' | Configuring listen-ports"
|
||||
ansible.builtin.blockinfile:
|
||||
path: '/etc/apache2/ports.conf'
|
||||
block: |
|
||||
Listen {{ port }}
|
||||
marker: "# {mark} ANSIBLE MANAGED BLOCK - port '{{ port }}'"
|
||||
insertafter: '# /etc/apache2/sites-enabled/000-default.conf'
|
||||
ignore_errors: true
|
||||
when:
|
||||
- port != 80
|
||||
- port != 443
|
||||
- port != '80'
|
||||
- port != '443'
|
||||
loop_control:
|
||||
loop_var: port
|
||||
with_items:
|
||||
- "{{ site.port_plain }}"
|
||||
- "{{ site.port_ssl }}"
|
||||
|
||||
- name: "Apache | Debian | Config | Site '{{ name }}' | Create root directory"
|
||||
ansible.builtin.file:
|
||||
path: "{{ site.serve.path }}"
|
||||
state: directory
|
||||
owner: "{{ APACHE_CONFIG.user }}"
|
||||
group: "{{ APACHE_CONFIG.group }}"
|
||||
mode: 0755
|
||||
when: site.mode == 'serve'
|
||||
|
||||
- name: "Apache | Debian | Config | Site '{{ name }}' | Configuring site"
|
||||
ansible.builtin.template:
|
||||
src: 'templates/etc/apache2/sites-available/site.conf.j2'
|
||||
dest: "/etc/apache2/sites-available/site_{{ name }}.conf"
|
||||
owner: 'root'
|
||||
group: 'root'
|
||||
mode: 0644
|
||||
validate: 'apachectl -t -f %s'
|
||||
register: apache_config_deployment
|
||||
ignore_errors: yes
|
||||
|
||||
- name: "Apache | Debian | Config | Site '{{ name }}' | Ask user"
|
||||
ansible.builtin.pause:
|
||||
prompt: "The apache config validation failed! Sometimes this is a false-negative.
|
||||
Do you want to force the deployment? (yes/no)"
|
||||
register: force_deploy
|
||||
when: apache_config_deployment.failed
|
||||
|
||||
- name: "Apache | Debian | Config | Site '{{ name }}' | Configuring site (forced)"
|
||||
ansible.builtin.template:
|
||||
src: 'templates/etc/apache2/sites-available/site.conf.j2'
|
||||
dest: "/etc/apache2/sites-available/site_{{ name }}.conf"
|
||||
owner: 'root'
|
||||
group: 'root'
|
||||
mode: 0644
|
||||
backup: true
|
||||
when:
|
||||
- apache_config_deployment.failed
|
||||
- force_deploy.user_input == 'yes'
|
||||
|
||||
- name: "Apache | Debian | Config | Site '{{ name }}' | Enabling site"
|
||||
ansible.builtin.file:
|
||||
state: link
|
||||
src: "/etc/apache2/sites-available/site_{{ name }}.conf"
|
||||
dest: "/etc/apache2/sites-enabled/site_{{ name }}.conf"
|
||||
owner: 'root'
|
||||
group: 'root'
|
||||
mode: 0644
|
||||
@@ -0,0 +1,13 @@
|
||||
---
|
||||
|
||||
- name: Apache | Debian | LetsEncrypt Certbot | Cleanup | Disable temporary apache site
|
||||
ansible.builtin.file:
|
||||
state: absent
|
||||
dest: '/etc/apache2/sites-enabled/tmp_le_dummy.conf'
|
||||
register: tmp_site_config
|
||||
|
||||
- name: Apache | Debian | LetsEncrypt Certbot | Cleanup | Reload apache
|
||||
ansible.builtin.systemd:
|
||||
name: 'apache2.service'
|
||||
state: reloaded
|
||||
when: tmp_site_config.changed
|
||||
@@ -0,0 +1,23 @@
|
||||
---
|
||||
|
||||
- name: Apache | Debian | LetsEncrypt Certbot | Dependencies | Deploying temporary apache site
|
||||
ansible.builtin.template:
|
||||
src: 'templates/etc/apache2/sites-available/le_dummy.conf.j2'
|
||||
dest: '/etc/apache2/sites-available/tmp_le_dummy.conf'
|
||||
owner: 'root'
|
||||
group: 'root'
|
||||
mode: 0644
|
||||
|
||||
- name: Apache | Debian | LetsEncrypt Certbot | Dependencies | Enable apache site
|
||||
ansible.builtin.file:
|
||||
state: link
|
||||
src: '/etc/apache2/sites-available/tmp_le_dummy.conf'
|
||||
dest: '/etc/apache2/sites-enabled/tmp_le_dummy.conf'
|
||||
owner: 'root'
|
||||
group: 'root'
|
||||
mode: 0644
|
||||
|
||||
- name: Apache | Debian | LetsEncrypt Certbot | Dependencies | Reload apache
|
||||
ansible.builtin.systemd:
|
||||
name: 'apache2.service'
|
||||
state: reloaded
|
||||
@@ -0,0 +1,45 @@
|
||||
---
|
||||
|
||||
- name: "Apache | Debian | LetsEncrypt Certbot | Checking if cert for domain '{{ site.domain }}' exists"
|
||||
ansible.builtin.shell: 'certbot certificates'
|
||||
register: domain_cert
|
||||
changed_when: false
|
||||
|
||||
# todo: check domains registered in current certificate (certbot certificates) and remove it if there are more than configured before re-configuring it
|
||||
|
||||
- name: "Apache | Debian | LetsEncrypt Certbot | Set key/cert paths for domain '{{ site.domain }}'"
|
||||
ansible.builtin.set_fact:
|
||||
_path_key: "{{ APACHE_CONFIG.letsencrypt.path_key }}/{{ name }}"
|
||||
_path_cert: "{{ APACHE_CONFIG.letsencrypt.path_cert }}/{{ name }}"
|
||||
_path_live: "{{ APACHE_CONFIG.letsencrypt.path }}/live/{{ name }}"
|
||||
|
||||
- name: "Apache | Debian | LetsEncrypt Certbot | Creating key/cert directories for domain '{{ site.domain }}'"
|
||||
ansible.builtin.file:
|
||||
path: "{{ item }}"
|
||||
state: directory
|
||||
owner: 'root'
|
||||
group: 'root'
|
||||
mode: 0755
|
||||
with_items:
|
||||
- "{{ _path_key }}"
|
||||
- "{{ _path_cert }}"
|
||||
|
||||
- name: Apache | Debian | LetsEncrypt Certbot | Getting cert
|
||||
ansible.builtin.include_tasks: domain_new.yml
|
||||
when: domain_cert.stdout.find(site.domain) == -1
|
||||
|
||||
- name: "Apache | Debian | LetsEncrypt Certbot | Linking certificates for domain '{{ site.domain }}'"
|
||||
ansible.builtin.file:
|
||||
state: link
|
||||
src: "{{ item.value.src }}"
|
||||
dest: "{{ item.value.dst }}"
|
||||
owner: "{{ APACHE_CONFIG.user }}"
|
||||
group: "{{ APACHE_CONFIG.group }}"
|
||||
mode: 0400
|
||||
follow: yes
|
||||
with_dict:
|
||||
- {'config': {'dst': "{{ _path_key }}/privkey.pem", 'src': "{{ _path_live }}/privkey.pem"}}
|
||||
- {'config': {'dst': "{{ _path_cert }}/cert.pem", 'src': "{{ _path_live }}/cert.pem"}}
|
||||
- {'config': {'dst': "{{ _path_cert }}/chain.pem", 'src': "{{ _path_live }}/chain.pem"}}
|
||||
- {'config': {'dst': "{{ _path_cert }}/fullchain.pem", 'src': "{{ _path_live }}/fullchain.pem"}}
|
||||
ignore_errors: yes
|
||||
@@ -0,0 +1,26 @@
|
||||
---
|
||||
|
||||
- name: "Apache | Debian | LetsEncrypt Certbot | Creating alternative name string (1/3)"
|
||||
ansible.builtin.set_fact:
|
||||
_aliases: "{{ site.aliases | join(' --domain ') }}"
|
||||
when: apache_aliases | length > 0
|
||||
|
||||
- name: "Apache | Debian | LetsEncrypt Certbot | Creating alternative name string (2/3)"
|
||||
ansible.builtin.set_fact:
|
||||
_apache_aliases: "{{ '--domain ' + _aliases }}"
|
||||
when: apache_aliases | length > 0
|
||||
|
||||
- name: "Apache | Debian | LetsEncrypt Certbot | Creating alternative name string (3/3)"
|
||||
ansible.builtin.set_fact:
|
||||
_apache_aliases: ''
|
||||
when: apache_aliases | length == 0
|
||||
|
||||
- name: debug
|
||||
ansible.builtin.debug:
|
||||
msg: "certbot certonly --apache -{{ APACHE_CONFIG.letsencrypt.verbosity }} --non-interactive --agree-tos --email {{ site.admin }} --cert-name {{ name }}
|
||||
--rsa-key-size {{ APACHE_CONFIG.letsencrypt.key_size }} --no-redirect --domain {{ site.domain }} {{ _apache_aliases }}"
|
||||
|
||||
- name: "Apache | Debian | LetsEncrypt Certbot | Starting certbot for domain '{{ site.domain }}'"
|
||||
ansible.builtin.shell: "certbot certonly --apache -{{ APACHE_CONFIG.letsencrypt.verbosity }} --non-interactive --agree-tos --email {{ site.admin }} --cert-name {{ name }}
|
||||
--rsa-key-size {{ APACHE_CONFIG.letsencrypt.key_size }} --no-redirect --domain {{ site.domain }} {{ _apache_aliases }}"
|
||||
ignore_errors: yes
|
||||
@@ -0,0 +1,41 @@
|
||||
---
|
||||
|
||||
- name: Apache | Debian | LetsEncrypt Certbot | Install package
|
||||
ansible.builtin.apt:
|
||||
name: "{{ packages.letsencrypt }}"
|
||||
state: present
|
||||
|
||||
- name: Apache | Debian | LetsEncrypt Certbot | Check if a apache virtualhost is available
|
||||
ansible.builtin.shell: 'ls /etc/apache2/sites-enabled/'
|
||||
register: enabled_apache_sites
|
||||
|
||||
- name: Apache | Debian | LetsEncrypt Certbot | Checking dependencies
|
||||
ansible.builtin.include_tasks: dependencies.yml
|
||||
when: enabled_apache_sites.stdout == ''
|
||||
|
||||
- name: Apache | Debian | LetsEncrypt Certbot | Processing apache sites
|
||||
ansible.builtin.include_tasks: domain.yml
|
||||
vars:
|
||||
site: "{{ default_site_config | combine(site_item, recursive=true) }}"
|
||||
name: "{{ site_item.key | safe_key }}"
|
||||
loop_control:
|
||||
loop_var: site_item
|
||||
with_dict: "{{ APACHE_CONFIG.sites }}"
|
||||
|
||||
- name: Apache | Debian | LetsEncrypt Certbot | Cleanup dependencies
|
||||
ansible.builtin.include_tasks: cleanup.yml
|
||||
|
||||
- name: Apache | Debian | LetsEncrypt Certbot | Adding systemd files for certbot renewal
|
||||
ansible.builtin.template:
|
||||
src: "templates/etc/systemd/system/{{ item }}.j2"
|
||||
dest: "/etc/systemd/system/{{ item }}"
|
||||
with_items:
|
||||
- 'ansibleguy.infra_apache.LetsEncryptCertbot.service'
|
||||
- 'ansibleguy.infra_apache.LetsEncryptCertbot.timer'
|
||||
|
||||
- name: Apache | Debian | LetsEncrypt Certbot | Enabling cert-renewal systemd timer
|
||||
ansible.builtin.systemd:
|
||||
daemon_reload: yes
|
||||
name: 'LetsEncryptCertbot.timer'
|
||||
enabled: yes
|
||||
state: started
|
||||
@@ -0,0 +1,100 @@
|
||||
---
|
||||
|
||||
- name: Apache | Debian | Install apache
|
||||
ansible.builtin.apt:
|
||||
name: "{{ packages.apache }}"
|
||||
state: present
|
||||
|
||||
- name: Apache | Debian | Checking if all sites exist (1/2)
|
||||
ansible.builtin.stat:
|
||||
path: "/etc/apache2/sites-available/site_{{ item.key | safe_key }}.conf"
|
||||
register: sites_exist_raw
|
||||
with_dict: "{{ APACHE_CONFIG.sites }}"
|
||||
|
||||
- name: Apache | Debian | Checking if all sites exist (2/2)
|
||||
ansible.builtin.set_fact:
|
||||
sites_exist: "{{ sites_exist_raw | json_query('[*].results.stat.exists') | all_true }}"
|
||||
|
||||
- name: Apache | Debian | Getting certificate via LetsEncrypt
|
||||
ansible.builtin.import_tasks: letsencrypt/main.yml
|
||||
when: >
|
||||
(APACHE_CONFIG.ssl.renew or
|
||||
not sites_exist) and
|
||||
APACHE_CONFIG.ssl.mode == 'letsencrypt'
|
||||
|
||||
- name: Apache | Debian | Enabling apache modules
|
||||
community.general.apache2_module:
|
||||
state: present
|
||||
name: "{{ item }}"
|
||||
when: item not in APACHE_CONFIG.modules.absent
|
||||
loop: "{{ APACHE_CONFIG.modules.present }}"
|
||||
|
||||
- name: Apache | Debian | Disabling apache modules
|
||||
community.general.apache2_module:
|
||||
state: absent
|
||||
name: "{{ item }}"
|
||||
loop: "{{ APACHE_CONFIG.modules.absent }}"
|
||||
|
||||
# todo: configure module settings
|
||||
|
||||
# todo: check if apache2.conf editing is still needed
|
||||
#- name: Apache | Debian | Adding global config
|
||||
# ansible.builtin.blockinfile:
|
||||
# path: '/etc/apache2/apache2.conf'
|
||||
# block: |
|
||||
# {% for setting, value in apache_config_additions_default.items() %}
|
||||
# {{ setting }} {{ value }}
|
||||
# {% endfor %}
|
||||
# {% for setting, value in apache_config_additions.items() %}
|
||||
# {{ setting }} {{ value }}
|
||||
# {% endfor %}
|
||||
# marker: "# {mark} ANSIBLE MANAGED BLOCK - global config"
|
||||
# validate: 'apachectl -t -f %s'
|
||||
|
||||
- name: Apache | Debian | Disabling default apache sites
|
||||
ansible.builtin.file:
|
||||
state: absent
|
||||
dest: "/etc/apache2/sites-enabled/{{ item }}"
|
||||
with_items:
|
||||
- '000-default.conf'
|
||||
- 'default-ssl.conf'
|
||||
|
||||
- name: Apache | Debian | Removing apache site
|
||||
ansible.builtin.include_tasks: rm_site.yml
|
||||
vars:
|
||||
site: "{{ default_site_config | combine(site_item, recursive=true) }}"
|
||||
name: "{{ site_item.key | safe_key }}"
|
||||
when: site_item.state | default('present') != 'present'
|
||||
loop_control:
|
||||
loop_var: site_item
|
||||
with_dict: "{{ APACHE_CONFIG.sites }}"
|
||||
|
||||
- name: Apache | Debian | Reloading apache
|
||||
ansible.builtin.systemd:
|
||||
name: 'apache2.service'
|
||||
state: reloaded
|
||||
tags: [base, config, sites, certs]
|
||||
|
||||
- name: Apache | Debian | Adding apache site
|
||||
ansible.builtin.include_tasks: add_site.yml
|
||||
vars:
|
||||
site: "{{ default_site_config | combine(site_item, recursive=true) }}"
|
||||
name: "{{ site_item.key | safe_key }}"
|
||||
when: site_item.state | default('present') == 'present'
|
||||
loop_control:
|
||||
loop_var: site_item
|
||||
with_dict: "{{ APACHE_CONFIG.sites }}"
|
||||
|
||||
- name: Apache | Debian | Starting/Enabling apache
|
||||
ansible.builtin.systemd:
|
||||
name: 'apache2.service'
|
||||
enabled: yes
|
||||
state: started
|
||||
tags: [base]
|
||||
|
||||
- name: Apache | Debian | Reloading apache
|
||||
ansible.builtin.systemd:
|
||||
name: 'apache2.service'
|
||||
enabled: yes
|
||||
state: reloaded
|
||||
tags: [base, config, sites, certs]
|
||||
@@ -0,0 +1,24 @@
|
||||
---
|
||||
|
||||
# ports will be left configured since I found no clean way to manage them statefully
|
||||
|
||||
- name: "Apache | Debian | Config | Site '{{ name }}' | Removing web-root"
|
||||
ansible.builtin.file:
|
||||
path: "{{ site.serve.path }}"
|
||||
state: absent
|
||||
force: yes
|
||||
when: site.mode == 'serve'
|
||||
|
||||
- name: "Apache | Debian | Config | Site '{{ name }}' | Removing/Disabling site"
|
||||
ansible.builtin.template:
|
||||
path: "{{ item }}"
|
||||
state: absent
|
||||
loop:
|
||||
- "/etc/apache2/sites-available/site_{{ name }}.conf"
|
||||
- "/etc/apache2/sites-enabled/site_{{ name }}.conf"
|
||||
|
||||
- name: "Apache | Debian | Config | Site '{{ name }}' | Removing certificate from certbot"
|
||||
ansible.builtin.shell: "certbot certonly --apache -{{ APACHE_LE_CONFIG.verbosity }} --non-interactive --agree-tos --email {{ site.admin }} --cert-name {{ name }}
|
||||
--rsa-key-size {{ APACHE_LE_CONFIG.key_size }} --no-redirect --domain {{ site.domain }} {{ _apache_aliases }}"
|
||||
ignore_errors: yes
|
||||
when: site.ssl.mode == 'letsencrypt'
|
||||
@@ -0,0 +1,5 @@
|
||||
---
|
||||
|
||||
- name: Apache | Processing debian config
|
||||
ansible.builtin.import_tasks: debian/main.yml
|
||||
when: "ansible_distribution|lower in ['debian', 'ubuntu']"
|
||||
Reference in New Issue
Block a user