use certificates role instead of letsencrypt role
This commit is contained in:
parent
f79fec1356
commit
53a4544ba1
6 changed files with 27 additions and 2 deletions
1
.gitignore
vendored
Normal file
1
.gitignore
vendored
Normal file
|
|
@ -0,0 +1 @@
|
|||
__pycache__
|
||||
17
filter_plugins/filters.py
Executable file
17
filter_plugins/filters.py
Executable file
|
|
@ -0,0 +1,17 @@
|
|||
#!/usr/bin/env python3
|
||||
class FilterModule(object):
|
||||
def filters(self):
|
||||
return {
|
||||
'nginx_vhosts_to_certificates': self.nginx_vhosts_to_certificates
|
||||
}
|
||||
|
||||
def nginx_vhosts_to_certificates(self, vhosts):
|
||||
certs = {}
|
||||
for i in vhosts.keys():
|
||||
if not vhosts[i]['letsencrypt']:
|
||||
continue
|
||||
certs['nginx_'+i] = {
|
||||
'backend': 'letsencrypt',
|
||||
'san': vhosts[i]['servername']
|
||||
}
|
||||
return certs
|
||||
|
|
@ -2,3 +2,4 @@
|
|||
dependencies:
|
||||
- { role: monitoring, when: nginx.monitoring }
|
||||
- { role: pki-server, when: nginx.serverpki }
|
||||
- certificates
|
||||
|
|
|
|||
|
|
@ -5,6 +5,9 @@
|
|||
- delete nginx index.nginx-debian.html
|
||||
- restart nginx
|
||||
|
||||
- name: debugnginx
|
||||
debug: var=certificates
|
||||
|
||||
- name: copy configs
|
||||
copy:
|
||||
src: config/
|
||||
|
|
|
|||
|
|
@ -61,8 +61,8 @@ server {
|
|||
{% endfor %}
|
||||
|
||||
{% if vhost.letsencrypt|d(False) %}
|
||||
ssl_certificate /etc/ssl/letsencrypt_{{ vhost_name }}_chained.crt;
|
||||
ssl_certificate_key /etc/ssl/private/letsencrypt_{{ vhost_name }}.key;
|
||||
ssl_certificate /etc/ssl/nginx_{{ vhost_name }}.chain.crt;
|
||||
ssl_certificate_key /etc/ssl/private/nginx_{{ vhost_name }}.key;
|
||||
ssl_stapling_verify on;
|
||||
ssl_stapling on;
|
||||
{% endif %}
|
||||
|
|
|
|||
|
|
@ -3,3 +3,6 @@ monitoring:
|
|||
checks:
|
||||
local:
|
||||
nginx_status: {}
|
||||
|
||||
certificates:
|
||||
certs: "{{ nginx.vhosts|nginx_vhosts_to_certificates }}"
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue