update cert references for renewal; ansible-lint cleanup

This commit is contained in:
2024-09-04 17:09:27 -04:00
parent b71c656e6a
commit 4646e5cf23
6 changed files with 110 additions and 40 deletions

View File

@ -1,67 +1,68 @@
---
- name: install proxy packages
package:
name : "{{ proxy_package_list }}"
state : present
- name: Install proxy packages
ansible.builtin.package:
name: "{{ proxy_package_list }}"
state: present
tags: always
- name: enable nginx at boot time
service:
name : nginx
enabled : yes
- name: Enable nginx at boot time
ansible.builtin.service:
name: nginx
enabled: true
tags: always
when: ansible_virtualization_type != "docker"
- name: clean conf.d
file:
- name: Clean conf.d
ansible.builtin.file:
path: "{{ proxy_site_conf_dir }}"
state: absent
tags: ['clean_deploy','never']
tags: ['clean_deploy', 'never']
- name: create conf.d directory
file:
path : "{{ proxy_site_conf_dir }}"
state : directory
mode : 0755
- name: Create conf.d directory
ansible.builtin.file:
path: "{{ proxy_site_conf_dir }}"
state: directory
mode: "0755"
tags: always
- name: create log directory
file:
path : "{{ proxy_site_log_path }}"
state : directory
mode : 0755
- name: Create log directory
ansible.builtin.file:
path: "{{ proxy_site_log_path }}"
state: directory
mode: "0755"
tags: always
## TODO: fix the perms on ssl certs!!@*&!@^&*
- name: clone ssl certs
git:
- name: Clone ssl certs
ansible.builtin.git:
repo: "{{ ssl_repo }}"
dest: "{{ proxy_site_ssl_directory }}"
version: "{{ ssl_repo_branch }}"
accept_newhostkey: true
tags: always
notify: restart nginx
- name: write configuration file(s)
template:
src : proxy_site.j2
dest : "{{ proxy_site_conf_dir }}/{{ item.key }}.conf"
mode : 0644
- name: Write configuration file(s)
ansible.builtin.template:
src: proxy_site.j2
dest: "{{ proxy_site_conf_dir }}/{{ item.key }}.conf"
mode: "0644"
with_dict:
- "{{ proxy_sites }}"
tags: always
notify: restart nginx
- name: start nginx
service:
name : nginx
state : started
- name: Start nginx
ansible.builtin.service:
name: nginx
state: started
tags: always
when: ansible_virtualization_type != "docker"