30 lines
674 B
YAML
30 lines
674 B
YAML
---
|
|
- name: stat dhparam
|
|
become: true
|
|
stat:
|
|
path: /etc/ssl/certs/dhparam.pem
|
|
register: dhparam
|
|
tags: ssl
|
|
|
|
- name: generate openssl dhparam for nginx
|
|
become: true
|
|
command: |
|
|
openssl dhparam -out /etc/ssl/certs/dhparam.pem 2048
|
|
when: not dhparam.stat.exists
|
|
args:
|
|
creates: /etc/ssl/certs/dhparam.pem
|
|
tags: ssl
|
|
|
|
- name: create ssl certificate for ci server
|
|
become: true
|
|
command: |
|
|
certbot certonly --webroot --webroot-path=/srv/http/letsencrypt \
|
|
-m {{ ssl_email }} --agree-tos \
|
|
-d {{ item }}
|
|
args:
|
|
creates: "/etc/letsencrypt/live/{{ item }}"
|
|
loop:
|
|
- "{{ ci_server_name }}"
|
|
- "{{ parts_server_name }}"
|
|
tags: ssl
|