2014-08-16 23:35:57 +02:00
|
|
|
---
|
2023-08-22 20:33:19 +02:00
|
|
|
- name: Remove nginx apt signing key from apt-key
|
2023-08-10 22:44:47 +02:00
|
|
|
ansible.builtin.apt_key:
|
2023-08-23 21:22:51 +02:00
|
|
|
id: "053473772654754373614404074646527257655730117366337542"
|
2023-08-22 20:33:19 +02:00
|
|
|
state: absent
|
|
|
|
tags:
|
|
|
|
- packages
|
|
|
|
- nginx
|
|
|
|
|
|
|
|
- name: Check nginx apt signing key
|
|
|
|
ansible.builtin.stat:
|
|
|
|
path: /usr/share/keyrings/nginx_signing.key
|
|
|
|
register: nginx_signing_key_stat
|
2023-08-10 22:44:47 +02:00
|
|
|
tags:
|
2023-08-22 20:33:19 +02:00
|
|
|
- packages
|
2023-08-10 22:44:47 +02:00
|
|
|
- nginx
|
2023-08-22 20:33:19 +02:00
|
|
|
|
|
|
|
- name: Download nginx apt signing key
|
|
|
|
ansible.builtin.get_url:
|
|
|
|
url: https://nginx.org/keys/nginx_signing.key
|
|
|
|
dest: /usr/share/keyrings/nginx_signing.key
|
|
|
|
owner: root
|
|
|
|
group: root
|
2023-08-23 21:22:51 +02:00
|
|
|
mode: "0644"
|
2023-08-22 20:33:19 +02:00
|
|
|
register: download_nginx_signing_key
|
|
|
|
when: not nginx_signing_key_stat.stat.exists
|
|
|
|
tags:
|
2023-08-10 22:44:47 +02:00
|
|
|
- packages
|
2023-08-22 20:33:19 +02:00
|
|
|
- nginx
|
2014-08-16 23:35:57 +02:00
|
|
|
|
2015-05-24 23:15:49 +02:00
|
|
|
- name: Add nginx.org repo
|
2023-08-10 22:44:47 +02:00
|
|
|
ansible.builtin.template:
|
|
|
|
src: nginx_org_sources.list.j2
|
|
|
|
dest: /etc/apt/sources.list.d/nginx_org_sources.list
|
|
|
|
owner: root
|
|
|
|
group: root
|
2023-08-23 21:22:51 +02:00
|
|
|
mode: "0644"
|
2019-03-17 16:29:15 +01:00
|
|
|
register: add_nginx_apt_repository
|
2023-08-10 22:44:47 +02:00
|
|
|
tags:
|
|
|
|
- nginx
|
|
|
|
- packages
|
2014-08-16 23:35:57 +02:00
|
|
|
|
2019-03-17 16:29:15 +01:00
|
|
|
- name: Update apt cache
|
2023-08-22 20:33:19 +02:00
|
|
|
ansible.builtin.apt: # noqa no-handler
|
2022-09-10 21:33:19 +02:00
|
|
|
update_cache: true
|
2023-08-23 21:22:51 +02:00
|
|
|
when: (download_nginx_signing_key.status_code is defined and download_nginx_signing_key.status_code == 200) or add_nginx_apt_repository is changed
|
2019-03-17 16:29:15 +01:00
|
|
|
|
2021-09-27 09:48:24 +02:00
|
|
|
- name: Install nginx
|
2023-08-10 22:44:47 +02:00
|
|
|
ansible.builtin.apt:
|
|
|
|
pkg: nginx
|
|
|
|
cache_valid_time: 3600
|
|
|
|
state: present
|
|
|
|
tags:
|
|
|
|
- nginx
|
|
|
|
- packages
|
2014-08-16 23:35:57 +02:00
|
|
|
|
2017-01-30 14:43:03 +01:00
|
|
|
- name: Copy nginx.conf
|
2023-08-10 22:44:47 +02:00
|
|
|
ansible.builtin.template:
|
|
|
|
src: nginx.conf.j2
|
|
|
|
dest: /etc/nginx/nginx.conf
|
2023-08-23 21:22:51 +02:00
|
|
|
mode: "0644"
|
2023-08-10 22:44:47 +02:00
|
|
|
owner: root
|
|
|
|
group: root
|
2017-01-30 14:43:03 +01:00
|
|
|
notify:
|
|
|
|
- reload nginx
|
|
|
|
tags: nginx
|
|
|
|
|
|
|
|
- name: Copy extra nginx configs
|
2023-08-10 22:44:47 +02:00
|
|
|
ansible.builtin.copy:
|
|
|
|
src: "{{ item }}"
|
2023-08-23 21:22:51 +02:00
|
|
|
dest: /etc/nginx/{{ item }}
|
|
|
|
mode: "0644"
|
2023-08-10 22:44:47 +02:00
|
|
|
owner: root
|
|
|
|
group: root
|
2018-04-02 14:52:51 +02:00
|
|
|
loop:
|
2015-01-24 11:05:42 +01:00
|
|
|
- extra-security.conf
|
2015-02-10 21:04:28 +01:00
|
|
|
- fastcgi_cache
|
2014-08-16 23:35:57 +02:00
|
|
|
notify:
|
|
|
|
- reload nginx
|
|
|
|
tags: nginx
|
|
|
|
|
|
|
|
- name: Remove default nginx vhost
|
2023-08-10 22:44:47 +02:00
|
|
|
ansible.builtin.file:
|
|
|
|
path: /etc/nginx/conf.d/default.conf
|
|
|
|
state: absent
|
2014-08-16 23:35:57 +02:00
|
|
|
tags: nginx
|
|
|
|
|
2015-02-19 16:49:39 +01:00
|
|
|
- name: Create fastcgi cache dir
|
2023-08-10 22:44:47 +02:00
|
|
|
ansible.builtin.file:
|
|
|
|
path: /var/cache/nginx/cached/fastcgi
|
|
|
|
state: directory
|
|
|
|
owner: nginx
|
|
|
|
group: nginx
|
2023-08-23 21:22:51 +02:00
|
|
|
mode: "0755"
|
2016-04-15 11:29:35 +02:00
|
|
|
tags: nginx
|
2014-08-16 23:35:57 +02:00
|
|
|
|
2017-10-03 14:02:38 +02:00
|
|
|
- name: Configure nginx virtual hosts
|
2022-09-10 17:09:12 +02:00
|
|
|
ansible.builtin.include_tasks: vhosts.yml
|
2015-12-09 23:14:47 +01:00
|
|
|
when: nginx_vhosts is defined
|
2014-08-27 19:03:34 +02:00
|
|
|
tags: nginx
|
|
|
|
|
2018-04-26 16:09:09 +02:00
|
|
|
- name: Configure WordPress
|
2022-09-10 17:09:12 +02:00
|
|
|
ansible.builtin.include_tasks: wordpress.yml
|
2018-04-26 16:09:09 +02:00
|
|
|
when: nginx_vhosts is defined
|
|
|
|
tags: wordpress
|
|
|
|
|
2015-06-04 22:30:06 +02:00
|
|
|
- name: Configure blank nginx vhost
|
2023-08-10 22:44:47 +02:00
|
|
|
ansible.builtin.template:
|
|
|
|
src: blank-vhost.conf.j2
|
|
|
|
dest: "{{ nginx_confd_path }}/blank-vhost.conf"
|
2023-08-23 21:22:51 +02:00
|
|
|
mode: "0644"
|
2023-08-10 22:44:47 +02:00
|
|
|
owner: root
|
|
|
|
group: root
|
2015-06-04 22:30:06 +02:00
|
|
|
notify:
|
|
|
|
- reload nginx
|
2015-06-05 23:05:09 +02:00
|
|
|
tags: nginx
|
2015-06-04 22:30:06 +02:00
|
|
|
|
2014-08-16 23:35:57 +02:00
|
|
|
- name: Configure munin vhost
|
2023-08-10 22:44:47 +02:00
|
|
|
ansible.builtin.copy:
|
|
|
|
src: munin.conf
|
|
|
|
dest: /etc/nginx/conf.d/munin.conf
|
2023-08-23 21:22:51 +02:00
|
|
|
mode: "0644"
|
2023-08-10 22:44:47 +02:00
|
|
|
owner: root
|
|
|
|
group: root
|
2014-08-16 23:35:57 +02:00
|
|
|
notify:
|
|
|
|
- reload nginx
|
|
|
|
tags: nginx
|
|
|
|
|
2016-06-27 18:13:20 +02:00
|
|
|
- name: Start and enable nginx service
|
2023-08-10 22:44:47 +02:00
|
|
|
ansible.builtin.systemd:
|
|
|
|
name: nginx
|
|
|
|
state: started
|
|
|
|
enabled: true
|
2014-08-16 23:35:57 +02:00
|
|
|
tags: nginx
|
2014-08-27 19:00:42 +02:00
|
|
|
|
2018-04-26 16:12:22 +02:00
|
|
|
- name: Configure Let's Encrypt
|
2022-09-10 17:09:12 +02:00
|
|
|
ansible.builtin.include_tasks: letsencrypt.yml
|
2018-04-26 10:00:47 +02:00
|
|
|
tags: letsencrypt
|
|
|
|
|
2014-08-27 19:00:42 +02:00
|
|
|
# vim: set ts=2 sw=2:
|