summaryrefslogtreecommitdiff
path: root/roles/private
diff options
context:
space:
mode:
authorElizabeth Hunt <elizabeth.hunt@simponic.xyz>2024-01-12 20:58:04 -0500
committerElizabeth Hunt <elizabeth.hunt@simponic.xyz>2024-01-12 20:58:04 -0500
commit0bfb4a99cd606144244a3f07913997ecab4971bc (patch)
treea29575ffb371d671e9025cd01abec1204f41e3ce /roles/private
parentcee3332a3c6ff506a1cbce14ed9ff424c1a87950 (diff)
downloadoldinfra-0bfb4a99cd606144244a3f07913997ecab4971bc.tar.gz
oldinfra-0bfb4a99cd606144244a3f07913997ecab4971bc.zip
fix renewal
Diffstat (limited to 'roles/private')
-rw-r--r--roles/private/tasks/main.yml11
1 files changed, 4 insertions, 7 deletions
diff --git a/roles/private/tasks/main.yml b/roles/private/tasks/main.yml
index dabebeb..ee11e28 100644
--- a/roles/private/tasks/main.yml
+++ b/roles/private/tasks/main.yml
@@ -84,11 +84,8 @@
- name: reload nginx to activate sites
service: name=nginx state=restarted
-- name: add daily letsencrypt cronjob for cert renewal based on hash of domain name to prevent hitting LE rate limits
+- name: add daily renewal
cron:
- name: "letsencrypt_renewal_{{ item.stdout }}"
- minute: "0"
- hour: "5,17"
- job: "REQUESTS_CA_BUNDLE=/usr/local/share/ca-certificates/{{ step_bootstrap_ca_url }}.crt letsencrypt renew --server https://{{ step_bootstrap_ca_url }}:{{ step_ca_port }}/acme/ACME/directory --cert-name {{ item.stdout }} -n --webroot -w /var/www/letsencrypt --agree-tos --email {{ step_acme_cert_contact }} && service nginx reload"
- loop: "{{ extracted_domains.results }}"
- when: item.stdout != ""
+ name: "letsencrypt_renewal"
+ special_time: "daily"
+ job: "REQUESTS_CA_BUNDLE=/usr/local/share/ca-certificates/{{ step_bootstrap_ca_url }}.crt letsencrypt renew --force-renewal"