Matrix Docker Ansible eploy
Вы не можете выбрать более 25 тем Темы должны начинаться с буквы или цифры, могут содержать дефисы(-) и должны содержать не более 35 символов.
 
 

51 строка
1.6 KiB

  1. ---
  2. - name: Allow access to HTTP/HTTPS in firewalld
  3. firewalld:
  4. service: "{{ item }}"
  5. state: enabled
  6. immediate: yes
  7. permanent: yes
  8. with_items:
  9. - http
  10. - https
  11. when: ansible_os_family == 'RedHat'
  12. - name: Ensure acmetool Docker image is pulled
  13. docker_image:
  14. name: willwill/acme-docker
  15. - name: Ensure SSL certificates path exists
  16. file:
  17. path: "{{ ssl_certs_path }}"
  18. state: directory
  19. mode: 0770
  20. owner: "{{ matrix_user_username }}"
  21. group: "{{ matrix_user_username }}"
  22. - name: Check matrix-nginx-proxy state
  23. service: name=matrix-nginx-proxy
  24. register: matrix_nginx_proxy_state
  25. - name: Ensure matrix-nginx-proxy is stopped (if previously installed & started)
  26. service: name=matrix-nginx-proxy state=stopped
  27. when: "matrix_nginx_proxy_state.status.ActiveState|default('missing') == 'active'"
  28. - name: Ensure SSL certificates are marked as wanted in acmetool
  29. shell: >-
  30. /usr/bin/docker run --rm --name acmetool-host-grab -p 80:80
  31. -v {{ ssl_certs_path }}:/certs
  32. -e ACME_EMAIL={{ ssl_support_email }}
  33. willwill/acme-docker
  34. acmetool want {{ hostname_matrix }} {{ hostname_riot }} --xlog.severity=debug
  35. - name: Ensure matrix-nginx-proxy is started (if previously installed & started)
  36. service: name=matrix-nginx-proxy state=started
  37. when: "matrix_nginx_proxy_state.status.ActiveState|default('missing') == 'active'"
  38. - name: Ensure periodic SSL renewal cronjob configured
  39. template:
  40. src: "{{ role_path }}/templates/cron.d/ssl-certificate-renewal.j2"
  41. dest: "/etc/cron.d/ssl-certificate-renewal"
  42. mode: 0600