ansible-base/roles/tlscert_selfsigned/tasks/main.json

72 lines
1.6 KiB
JSON
Raw Normal View History

2023-11-20 02:07:08 +01:00
[
2025-10-08 11:20:09 +02:00
{
"name": "show vars",
"when": "switch_show_vars",
"ansible.builtin.debug": {
"var": "vars.cfg_tlscert_selfsigned"
}
},
2023-11-20 02:07:08 +01:00
{
"name": "install packages",
"become": true,
"ansible.builtin.apt": {
"update_cache": true,
2023-11-20 02:07:08 +01:00
"pkg": [
2023-11-29 16:52:23 +01:00
"openssl",
2023-11-20 02:07:08 +01:00
"python3-cryptography"
]
}
},
{
"name": "setup directories",
2023-11-22 15:20:34 +01:00
"become": true,
"loop": [
"/etc/ssl/private",
"/etc/ssl/csr",
"/etc/ssl/certs",
"/etc/ssl/fullchains"
],
2023-11-22 15:20:34 +01:00
"ansible.builtin.file": {
"state": "directory",
"path": "{{item}}"
2023-11-22 15:20:34 +01:00
}
},
{
"name": "csr | generate private key",
2023-11-20 02:07:08 +01:00
"become": true,
"community.crypto.openssl_privatekey": {
2025-10-08 11:20:09 +02:00
"path": "/etc/ssl/private/{{cfg_tlscert_selfsigned.domain}}.pem"
2023-11-20 02:07:08 +01:00
}
},
2023-11-22 15:20:34 +01:00
{
"name": "csr | execute",
"become": true,
"community.crypto.openssl_csr": {
2025-10-08 11:20:09 +02:00
"privatekey_path": "/etc/ssl/private/{{cfg_tlscert_selfsigned.domain}}.pem",
"common_name": "{{cfg_tlscert_selfsigned.domain}}",
2023-11-22 15:20:34 +01:00
"subject_alt_name": [
2025-10-08 11:20:09 +02:00
"DNS:{{cfg_tlscert_selfsigned.domain}}"
2023-11-22 15:20:34 +01:00
],
2025-10-08 11:20:09 +02:00
"path": "/etc/ssl/csr/{{cfg_tlscert_selfsigned.domain}}.pem"
2023-11-22 15:20:34 +01:00
},
"register": "temp_csr"
},
2023-11-20 02:07:08 +01:00
{
"name": "generate certificate",
"become": true,
"community.crypto.x509_certificate": {
2025-10-08 11:20:09 +02:00
"privatekey_path": "/etc/ssl/private/{{cfg_tlscert_selfsigned.domain}}.pem",
"csr_path": "/etc/ssl/csr/{{cfg_tlscert_selfsigned.domain}}.pem",
2023-11-20 02:07:08 +01:00
"provider": "selfsigned",
2025-10-08 11:20:09 +02:00
"path": "/etc/ssl/certs/{{cfg_tlscert_selfsigned.domain}}.pem"
2023-11-20 02:07:08 +01:00
}
2023-11-22 15:20:34 +01:00
},
{
"name": "compose fullchain",
"become": true,
"ansible.builtin.shell": {
2025-10-08 11:20:09 +02:00
"cmd": "cat /etc/ssl/certs/{{cfg_tlscert_selfsigned.domain}}.pem > /etc/ssl/fullchains/{{cfg_tlscert_selfsigned.domain}}.pem"
2023-11-22 15:20:34 +01:00
}
2023-11-20 02:07:08 +01:00
}
]