This commit is contained in:
AnsibleGuy
2021-11-02 22:06:52 +01:00
commit 4875e6ef1f
20 changed files with 809 additions and 0 deletions
+13
View File
@@ -0,0 +1,13 @@
---
- name: Apache | Debian | LetsEncrypt Certbot | Cleanup | Disable temporary apache site
ansible.builtin.file:
state: absent
dest: '/etc/apache2/sites-enabled/tmp_le_dummy.conf'
register: tmp_site_config
- name: Apache | Debian | LetsEncrypt Certbot | Cleanup | Reload apache
ansible.builtin.systemd:
name: 'apache2.service'
state: reloaded
when: tmp_site_config.changed
+23
View File
@@ -0,0 +1,23 @@
---
- name: Apache | Debian | LetsEncrypt Certbot | Dependencies | Deploying temporary apache site
ansible.builtin.template:
src: 'templates/etc/apache2/sites-available/le_dummy.conf.j2'
dest: '/etc/apache2/sites-available/tmp_le_dummy.conf'
owner: 'root'
group: 'root'
mode: 0644
- name: Apache | Debian | LetsEncrypt Certbot | Dependencies | Enable apache site
ansible.builtin.file:
state: link
src: '/etc/apache2/sites-available/tmp_le_dummy.conf'
dest: '/etc/apache2/sites-enabled/tmp_le_dummy.conf'
owner: 'root'
group: 'root'
mode: 0644
- name: Apache | Debian | LetsEncrypt Certbot | Dependencies | Reload apache
ansible.builtin.systemd:
name: 'apache2.service'
state: reloaded
+45
View File
@@ -0,0 +1,45 @@
---
- name: "Apache | Debian | LetsEncrypt Certbot | Checking if cert for domain '{{ site.domain }}' exists"
ansible.builtin.shell: 'certbot certificates'
register: domain_cert
changed_when: false
# todo: check domains registered in current certificate (certbot certificates) and remove it if there are more than configured before re-configuring it
- name: "Apache | Debian | LetsEncrypt Certbot | Set key/cert paths for domain '{{ site.domain }}'"
ansible.builtin.set_fact:
_path_key: "{{ APACHE_CONFIG.letsencrypt.path_key }}/{{ name }}"
_path_cert: "{{ APACHE_CONFIG.letsencrypt.path_cert }}/{{ name }}"
_path_live: "{{ APACHE_CONFIG.letsencrypt.path }}/live/{{ name }}"
- name: "Apache | Debian | LetsEncrypt Certbot | Creating key/cert directories for domain '{{ site.domain }}'"
ansible.builtin.file:
path: "{{ item }}"
state: directory
owner: 'root'
group: 'root'
mode: 0755
with_items:
- "{{ _path_key }}"
- "{{ _path_cert }}"
- name: Apache | Debian | LetsEncrypt Certbot | Getting cert
ansible.builtin.include_tasks: domain_new.yml
when: domain_cert.stdout.find(site.domain) == -1
- name: "Apache | Debian | LetsEncrypt Certbot | Linking certificates for domain '{{ site.domain }}'"
ansible.builtin.file:
state: link
src: "{{ item.value.src }}"
dest: "{{ item.value.dst }}"
owner: "{{ APACHE_CONFIG.user }}"
group: "{{ APACHE_CONFIG.group }}"
mode: 0400
follow: yes
with_dict:
- {'config': {'dst': "{{ _path_key }}/privkey.pem", 'src': "{{ _path_live }}/privkey.pem"}}
- {'config': {'dst': "{{ _path_cert }}/cert.pem", 'src': "{{ _path_live }}/cert.pem"}}
- {'config': {'dst': "{{ _path_cert }}/chain.pem", 'src': "{{ _path_live }}/chain.pem"}}
- {'config': {'dst': "{{ _path_cert }}/fullchain.pem", 'src': "{{ _path_live }}/fullchain.pem"}}
ignore_errors: yes
+26
View File
@@ -0,0 +1,26 @@
---
- name: "Apache | Debian | LetsEncrypt Certbot | Creating alternative name string (1/3)"
ansible.builtin.set_fact:
_aliases: "{{ site.aliases | join(' --domain ') }}"
when: apache_aliases | length > 0
- name: "Apache | Debian | LetsEncrypt Certbot | Creating alternative name string (2/3)"
ansible.builtin.set_fact:
_apache_aliases: "{{ '--domain ' + _aliases }}"
when: apache_aliases | length > 0
- name: "Apache | Debian | LetsEncrypt Certbot | Creating alternative name string (3/3)"
ansible.builtin.set_fact:
_apache_aliases: ''
when: apache_aliases | length == 0
- name: debug
ansible.builtin.debug:
msg: "certbot certonly --apache -{{ APACHE_CONFIG.letsencrypt.verbosity }} --non-interactive --agree-tos --email {{ site.admin }} --cert-name {{ name }}
--rsa-key-size {{ APACHE_CONFIG.letsencrypt.key_size }} --no-redirect --domain {{ site.domain }} {{ _apache_aliases }}"
- name: "Apache | Debian | LetsEncrypt Certbot | Starting certbot for domain '{{ site.domain }}'"
ansible.builtin.shell: "certbot certonly --apache -{{ APACHE_CONFIG.letsencrypt.verbosity }} --non-interactive --agree-tos --email {{ site.admin }} --cert-name {{ name }}
--rsa-key-size {{ APACHE_CONFIG.letsencrypt.key_size }} --no-redirect --domain {{ site.domain }} {{ _apache_aliases }}"
ignore_errors: yes
+41
View File
@@ -0,0 +1,41 @@
---
- name: Apache | Debian | LetsEncrypt Certbot | Install package
ansible.builtin.apt:
name: "{{ packages.letsencrypt }}"
state: present
- name: Apache | Debian | LetsEncrypt Certbot | Check if a apache virtualhost is available
ansible.builtin.shell: 'ls /etc/apache2/sites-enabled/'
register: enabled_apache_sites
- name: Apache | Debian | LetsEncrypt Certbot | Checking dependencies
ansible.builtin.include_tasks: dependencies.yml
when: enabled_apache_sites.stdout == ''
- name: Apache | Debian | LetsEncrypt Certbot | Processing apache sites
ansible.builtin.include_tasks: domain.yml
vars:
site: "{{ default_site_config | combine(site_item, recursive=true) }}"
name: "{{ site_item.key | safe_key }}"
loop_control:
loop_var: site_item
with_dict: "{{ APACHE_CONFIG.sites }}"
- name: Apache | Debian | LetsEncrypt Certbot | Cleanup dependencies
ansible.builtin.include_tasks: cleanup.yml
- name: Apache | Debian | LetsEncrypt Certbot | Adding systemd files for certbot renewal
ansible.builtin.template:
src: "templates/etc/systemd/system/{{ item }}.j2"
dest: "/etc/systemd/system/{{ item }}"
with_items:
- 'ansibleguy.infra_apache.LetsEncryptCertbot.service'
- 'ansibleguy.infra_apache.LetsEncryptCertbot.timer'
- name: Apache | Debian | LetsEncrypt Certbot | Enabling cert-renewal systemd timer
ansible.builtin.systemd:
daemon_reload: yes
name: 'LetsEncryptCertbot.timer'
enabled: yes
state: started