add nginx, sshd, ssl roles
This commit is contained in:
@@ -0,0 +1,10 @@
|
||||
---
|
||||
- name: deploy nginx config
|
||||
ansible.builtin.template:
|
||||
src: "{{ item }}"
|
||||
dest: "/etc/nginx/{{ item | basename | regex_replace('\\.j2$', '') }}"
|
||||
owner: root
|
||||
group: root
|
||||
mode: '0644'
|
||||
loop: "{{ query('ansible.builtin.fileglob', role_path + '/templates/' + inventory_hostname + '/*.conf.j2') }}"
|
||||
notify: restart nginx
|
||||
@@ -0,0 +1,81 @@
|
||||
---
|
||||
- name: install prerequisites for nginx repository
|
||||
ansible.builtin.apt:
|
||||
name:
|
||||
- curl
|
||||
- gnupg2
|
||||
- ca-certificates
|
||||
- lsb-release
|
||||
- debian-archive-keyring
|
||||
state: present
|
||||
update_cache: true
|
||||
|
||||
- name: check if nginx keyring already exists
|
||||
ansible.builtin.stat:
|
||||
path: /usr/share/keyrings/nginx-archive-keyring.gpg
|
||||
register: nginx_keyring
|
||||
|
||||
- name: download nginx gpg key
|
||||
ansible.builtin.get_url:
|
||||
url: https://nginx.org/keys/nginx_signing.key
|
||||
dest: /tmp/nginx_signing.key
|
||||
mode: '0644'
|
||||
when: not nginx_keyring.stat.exists
|
||||
|
||||
- name: dearmor nginx gpg key
|
||||
ansible.builtin.command:
|
||||
cmd: gpg --dearmor --yes -o /usr/share/keyrings/nginx-archive-keyring.gpg /tmp/nginx_signing.key
|
||||
when: not nginx_keyring.stat.exists
|
||||
|
||||
- name: ensure /root/.gnupg exists
|
||||
ansible.builtin.file:
|
||||
path: /root/.gnupg
|
||||
state: directory
|
||||
mode: '0700'
|
||||
owner: root
|
||||
group: root
|
||||
|
||||
- name: verify nginx signing key fingerprint
|
||||
ansible.builtin.command:
|
||||
cmd: gpg --dry-run --quiet --no-keyring --import --import-options import-show /usr/share/keyrings/nginx-archive-keyring.gpg
|
||||
register: nginx_key_check
|
||||
changed_when: false
|
||||
|
||||
- name: check nginx signing key fingerprint
|
||||
ansible.builtin.fail:
|
||||
msg: "nginx signing key fingerprint mismatch! Got: {{ nginx_key_check.stdout }}"
|
||||
when: "'573BFD6B3D8FBC641079A6ABABF5BD827BD9BF62' not in nginx_key_check.stdout"
|
||||
|
||||
- name: add nginx apt repository
|
||||
ansible.builtin.copy:
|
||||
dest: /etc/apt/sources.list.d/nginx.list
|
||||
content: >-
|
||||
deb [signed-by=/usr/share/keyrings/nginx-archive-keyring.gpg]
|
||||
https://nginx.org/packages/{{ 'mainline/' if (nginx_use_mainline | default(false)) else '' }}debian
|
||||
{{ ansible_facts['distribution_release'] }} nginx
|
||||
owner: root
|
||||
group: root
|
||||
mode: '0644'
|
||||
register: nginx_repo_file
|
||||
|
||||
- name: set up repository pinning for nginx
|
||||
ansible.builtin.copy:
|
||||
dest: /etc/apt/preferences.d/99nginx
|
||||
content: |
|
||||
Package: *
|
||||
Pin: origin nginx.org
|
||||
Pin: release o=nginx
|
||||
Pin-Priority: 900
|
||||
owner: root
|
||||
group: root
|
||||
mode: '0644'
|
||||
|
||||
- name: update apt cache
|
||||
ansible.builtin.apt:
|
||||
update_cache: true
|
||||
when: nginx_repo_file.changed
|
||||
|
||||
- name: install nginx
|
||||
ansible.builtin.apt:
|
||||
name: nginx
|
||||
state: present
|
||||
@@ -0,0 +1,6 @@
|
||||
---
|
||||
- name: include install
|
||||
ansible.builtin.include_tasks: install.yml
|
||||
|
||||
- name: include configure
|
||||
ansible.builtin.include_tasks: configure.yml
|
||||
Reference in New Issue
Block a user