Alan Orth
ffe7a872dd
According to Ansible we can use yes, true, True, "or any quoted st- ring" for a boolean true, but ansible-lint wants us to use either true or false. See: https://chronicler.tech/red-hat-ansible-yes-no-and/
77 lines
2.2 KiB
YAML
77 lines
2.2 KiB
YAML
---
|
|
- name: Add nginx.org apt signing key
|
|
ansible.builtin.apt_key: id=0x573BFD6B3D8FBC641079A6ABABF5BD827BD9BF62 url=https://nginx.org/keys/nginx_signing.key state=present
|
|
register: add_nginx_apt_key
|
|
tags: nginx, packages
|
|
|
|
- name: Add nginx.org repo
|
|
ansible.builtin.template: src=nginx_org_sources.list.j2 dest=/etc/apt/sources.list.d/nginx_org_sources.list owner=root group=root mode=0644
|
|
register: add_nginx_apt_repository
|
|
tags: nginx, packages
|
|
|
|
- name: Update apt cache
|
|
ansible.builtin.apt:
|
|
update_cache: true
|
|
when:
|
|
add_nginx_apt_key is changed or
|
|
add_nginx_apt_repository is changed
|
|
|
|
- name: Install nginx
|
|
ansible.builtin.apt: pkg=nginx cache_valid_time=3600 state=present
|
|
tags: nginx, packages
|
|
|
|
- name: Copy nginx.conf
|
|
ansible.builtin.template: src=nginx.conf.j2 dest=/etc/nginx/nginx.conf mode=0644 owner=root group=root
|
|
notify:
|
|
- reload nginx
|
|
tags: nginx
|
|
|
|
- name: Copy extra nginx configs
|
|
ansible.builtin.copy: src={{ item }} dest=/etc/nginx/{{ item }} mode=0644 owner=root group=root
|
|
loop:
|
|
- extra-security.conf
|
|
- fastcgi_cache
|
|
notify:
|
|
- reload nginx
|
|
tags: nginx
|
|
|
|
- name: Remove default nginx vhost
|
|
ansible.builtin.file: path=/etc/nginx/conf.d/default.conf state=absent
|
|
tags: nginx
|
|
|
|
- name: Create fastcgi cache dir
|
|
ansible.builtin.file: path=/var/cache/nginx/cached/fastcgi state=directory owner=nginx group=nginx mode=0755
|
|
tags: nginx
|
|
|
|
- name: Configure nginx virtual hosts
|
|
ansible.builtin.include_tasks: vhosts.yml
|
|
when: nginx_vhosts is defined
|
|
tags: nginx
|
|
|
|
- name: Configure WordPress
|
|
ansible.builtin.include_tasks: wordpress.yml
|
|
when: nginx_vhosts is defined
|
|
tags: wordpress
|
|
|
|
- name: Configure blank nginx vhost
|
|
ansible.builtin.template: src=blank-vhost.conf.j2 dest={{ nginx_confd_path }}/blank-vhost.conf mode=0644 owner=root group=root
|
|
notify:
|
|
- reload nginx
|
|
tags: nginx
|
|
|
|
- name: Configure munin vhost
|
|
ansible.builtin.copy: src=munin.conf dest=/etc/nginx/conf.d/munin.conf mode=0644 owner=root group=root
|
|
notify:
|
|
- reload nginx
|
|
tags: nginx
|
|
|
|
- name: Start and enable nginx service
|
|
ansible.builtin.systemd: name=nginx state=started enabled=true
|
|
tags: nginx
|
|
|
|
- name: Configure Let's Encrypt
|
|
ansible.builtin.include_tasks: letsencrypt.yml
|
|
tags: letsencrypt
|
|
|
|
# vim: set ts=2 sw=2:
|