Skip to content
GitLab
Projects
Groups
Snippets
Help
Loading...
Help
Help
Support
Community forum
Keyboard shortcuts
?
Submit feedback
Contribute to GitLab
Sign in
Toggle navigation
piops
Project overview
Project overview
Details
Activity
Releases
Repository
Repository
Files
Commits
Branches
Tags
Contributors
Graph
Compare
Issues
1
Issues
1
List
Boards
Labels
Service Desk
Milestones
Merge Requests
6
Merge Requests
6
CI / CD
CI / CD
Pipelines
Jobs
Schedules
Operations
Operations
Incidents
Environments
Analytics
Analytics
CI / CD
Repository
Value Stream
Wiki
Wiki
Snippets
Snippets
Members
Members
Collapse sidebar
Close sidebar
Activity
Graph
Create a new issue
Jobs
Commits
Issue Boards
Open sidebar
LQDN Adminsys
piops
Commits
965c7389
Commit
965c7389
authored
Apr 03, 2019
by
Okhin
Browse files
Options
Browse Files
Download
Email Patches
Plain Diff
Adding CertBot necessary configs
parent
b1ecb0fd
Pipeline
#2769
canceled with stages
Changes
6
Pipelines
3
Show whitespace changes
Inline
Side-by-side
Showing
6 changed files
with
36 additions
and
8 deletions
+36
-8
.gitmodules
.gitmodules
+3
-0
ansible.cfg
ansible.cfg
+1
-0
host_vars/pi3.lqdn.fr.yml
host_vars/pi3.lqdn.fr.yml
+29
-7
roles/alternc
roles/alternc
+1
-0
roles/rp
roles/rp
+1
-1
site.yml
site.yml
+1
-0
No files found.
.gitmodules
View file @
965c7389
...
@@ -7,3 +7,6 @@
...
@@ -7,3 +7,6 @@
[submodule "roles/rp"]
[submodule "roles/rp"]
path = roles/rp
path = roles/rp
url = gitlab@git.laquadrature.net:lqdn-interne/piops-roles/rp.git
url = gitlab@git.laquadrature.net:lqdn-interne/piops-roles/rp.git
[submodule "roles/alternc"]
path = roles/alternc
url = gitlab@git.laquadrature.net:lqdn-interne/piops-roles/alternc.git
ansible.cfg
View file @
965c7389
[defaults]
[defaults]
inventory = hosts
inventory = hosts
retry_files_enabled = False
retry_files_enabled = False
vault_password_file = .password
[diff]
[diff]
always = yes
always = yes
host_vars/pi3.lqdn.fr.yml
View file @
965c7389
...
@@ -52,7 +52,7 @@ wordpress_wildcard_keyfile: /etc/letsencrypt/live/grange.dev.lqdn.fr/privkey.pem
...
@@ -52,7 +52,7 @@ wordpress_wildcard_keyfile: /etc/letsencrypt/live/grange.dev.lqdn.fr/privkey.pem
wordpress_vhost
:
wordpress_vhost
:
-
servername
:
"
grange.dev.lqdn.fr"
-
servername
:
"
grange.dev.lqdn.fr"
serveralias
:
"
*.grange.dev.lqdn.fr"
serveralias
:
"
\
*.grange.dev.lqdn.fr"
documentroot
:
"
{{
wordpress_path
}}"
documentroot
:
"
{{
wordpress_path
}}"
allow_override
:
"
All"
allow_override
:
"
All"
#certificate_file: "{{ wordpress_wildcard_certfile }}"
#certificate_file: "{{ wordpress_wildcard_certfile }}"
...
@@ -63,12 +63,20 @@ wordpress_vhost:
...
@@ -63,12 +63,20 @@ wordpress_vhost:
#certbot_create_command: "{{ certbot_script }} certonly --webroot --webrootpath /var/www/letsencrypt/ --noninteractive --agree-tos --email {{ cert_item.email | default(certbot_admin_email) }} -d {{ cert_item.domains | join(,)"
certbot_create_method
:
standalone
certbot_create_standalone_stop_services
:
-
apache2
#certbot_certs:
certbot_create_command
:
"
{{
certbot_script
}}
certonly
--noninteractive
--manual
--agree-tos
--email
{{
cert_item.email
|
default(certbot_admin_email)
}}
--server
https://acme-v02.api.letsencrypt.org/directory
--manual-public-ip-logging-ok
--preferred-challenges=dns
--agree-tos
--manual-auth-hook
/usr/local/bin/certbot-auth.php
--manual-cleanup-hook
/usr/local/bin/certbot-cleanup.php
-d
{{cert_item.domains
|
join(',')
}}"
# - domains:
# - "grange.dev.lqdn.fr"
certbot_certs
:
# - "*.grange.dev.lqdn.fr"
-
domains
:
-
"
grange.dev.lqdn.fr"
-
"
*.grange.dev.lqdn.fr"
email
:
"
okhin@laquadrature.net"
certbot_create_if_missing
:
True
certbot_admin_email
:
okhin@laquadrature.net
rp_path
:
/srv/rp
rp_path
:
/srv/rp
rp_source_path
:
/srv/rp/rp-rp2
rp_source_path
:
/srv/rp/rp-rp2
...
@@ -89,7 +97,7 @@ rp_vhost:
...
@@ -89,7 +97,7 @@ rp_vhost:
serveralias
:
"
rp2.dev.lqdn.fr
rp.dev.laquadrature.net
rp2.dev.laquadrature.net"
serveralias
:
"
rp2.dev.lqdn.fr
rp.dev.laquadrature.net
rp2.dev.laquadrature.net"
documentroot
:
"
{{
rp_path
}}"
documentroot
:
"
{{
rp_path
}}"
uwsgi
:
uwsgi
:
socket
:
/run/uwsgi/app/rp/socket
socket
:
/run/uwsgi/app/rp
2
/socket
statics
:
statics
:
-
alias
:
/static/
-
alias
:
/static/
path
:
"
{{
rp_source_path
}}/static/static_root/"
path
:
"
{{
rp_source_path
}}/static/static_root/"
...
@@ -102,3 +110,17 @@ nodejs_packages_update_cache: no
...
@@ -102,3 +110,17 @@ nodejs_packages_update_cache: no
npm_packages
:
npm_packages
:
-
yarn
-
yarn
-
webpack
-
webpack
# Altern-C configuration
alternc_username
:
pi
alternc_password
:
!vault
|
$ANSIBLE_VAULT;1.1;AES256
36646462633066656439643964376532663562346630333534386366313135303562373464316662
3064366534356637623139343132343665623034346239330a643230396666396262383464323266
33353037656233326262343939303064653962303364343361396661393762323666333538663838
3934383264643161340a623232333162366163623839663930356262636166313563313638393432
6261
alternc_panel_url
:
https://pi.lqdn.fr/
alternc_token_file
:
/root/.alternc-token
alternc_token_url
:
"
{{
alternc_panel_url
}}api/auth/login?login={{
alternc_username
}}&password={{
alternc_password
|
trim
}}&duration=3650"
alternc_domain_root
:
lqdn.fr
alternc
@
839880e2
Subproject commit 839880e2e2adcfdead58dde5a7c1b1dbc3ff9da6
rp
@
b0b7629d
Compare
1b52ee2a
...
b0b7629d
Subproject commit
1b52ee2a2d8d92644011c3e146a55926ddc67087
Subproject commit
b0b7629dbee68e166b32becd071b8fc61d2acf69
site.yml
View file @
965c7389
...
@@ -11,6 +11,7 @@
...
@@ -11,6 +11,7 @@
-
role
:
geerlingguy.mysql
-
role
:
geerlingguy.mysql
-
role
:
geerlingguy.php
-
role
:
geerlingguy.php
-
role
:
geerlingguy.php-mysql
-
role
:
geerlingguy.php-mysql
-
role
:
alternc
-
role
:
geerlingguy.certbot
-
role
:
geerlingguy.certbot
-
role
:
geerlingguy.apache
-
role
:
geerlingguy.apache
vars
:
vars
:
...
...
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
.
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment