ansible-edda/playbooks/roles/services/deploy/rproxy/tasks/main.yml

112 lines
4.3 KiB
YAML
Raw Normal View History

2022-12-18 23:43:40 +01:00
---
2023-07-17 22:31:05 +02:00
- name: "{{ services_service_name }} : set the user variables"
2022-12-16 21:49:50 +01:00
ansible.builtin.import_role:
2022-12-18 19:36:21 +01:00
name: "services/include"
2022-12-16 21:49:50 +01:00
vars_from: "user"
2023-07-17 22:31:05 +02:00
- name: "{{ services_service_name }} : set the rproxy variables"
2022-12-16 21:49:50 +01:00
ansible.builtin.include_vars:
file: "nginx.yml"
- block:
2023-07-17 22:31:05 +02:00
- name: "{{ services_service_name }} : create nginx conf.d"
2022-12-16 21:49:50 +01:00
ansible.builtin.file:
2022-12-18 23:43:40 +01:00
path: "\
{{ services_service_user_home }}/.config/{{ services_service_user_name }}/nginx-conf.d"
2022-12-16 21:49:50 +01:00
state: "directory"
mode: 0755
2023-07-17 22:31:05 +02:00
- name: "{{ services_service_name }} : generic nginx reverse proxy configuration"
2022-12-16 21:49:50 +01:00
ansible.builtin.copy:
2023-07-17 22:31:05 +02:00
src: "./config/nginx.conf"
dest: "{{ services_service_user_home }}/.config/{{ services_service_user_name }}/nginx.conf"
2022-12-16 21:49:50 +01:00
mode: 0644
2023-07-17 22:31:05 +02:00
register: services_deploy_rproxy_generic_config
- name: "{{ services_service_name }} : stream nginx reverse proxy configuration"
ansible.builtin.copy:
src: "{{ services_deploy_rproxy_nginx_stream_config }}"
dest: "\
{{ services_service_user_home }}/.config/{{ services_service_user_name }}/stream.conf"
mode: 0644
register: services_deploy_rproxy_stream_config
- name: "{{ services_service_name }} : subdomain nginx reverse proxy configuration"
ansible.builtin.copy:
src: "{{ item }}"
dest: "\
{{ services_service_user_home }}/.config/\
{{ services_service_user_name }}/nginx-conf.d/{{ item | basename }}"
mode: 0644
loop: "{{ services_deploy_rproxy_nginx_subdomain_config_files }}"
register: services_deploy_rproxy_subdomain_config_files
2022-12-16 21:49:50 +01:00
2023-07-17 22:31:05 +02:00
- name: "{{ services_service_name }} : configure systemd service"
2022-12-16 21:49:50 +01:00
ansible.builtin.template:
2023-07-08 10:04:37 +02:00
src: "./systemd/{{ item }}"
2023-07-17 22:31:05 +02:00
dest: "\
{{ services_service_user_home }}/.config/systemd/user/\
{{ item | replace('rproxy', services_service_name) }}"
mode: 0600
2022-12-16 21:49:50 +01:00
loop:
- "pod-rproxy.service"
- "container-rproxy-nginx.service"
- "container-rproxy-certbot.service"
- "container-rproxy-certbot.timer"
register: services_deploy_rproxy_systemd_files
2023-07-17 22:31:05 +02:00
- name: "{{ services_service_name }} : systemd user daemon reload"
2022-12-16 22:16:23 +01:00
ansible.builtin.systemd:
2022-12-16 21:49:50 +01:00
daemon_reload: true
scope: "user"
when:
services_deploy_rproxy_systemd_files.changed
2023-07-17 22:31:05 +02:00
- name: "{{ services_service_name }} : enable container-{{ services_service_name }}-certbot timer"
2022-12-16 21:49:50 +01:00
ansible.builtin.systemd:
2023-07-17 22:31:05 +02:00
name: "container-{{ services_service_name }}-certbot.timer"
2022-12-16 21:49:50 +01:00
enabled: true
scope: "user"
register: services_deploy_rproxy_certbot_timer
2023-07-17 22:31:05 +02:00
- name: "{{ services_service_name }} : generate diffie hellman ephemeral parameters"
2022-12-18 23:43:40 +01:00
ansible.builtin.command: >-
openssl dhparam
--out /{{ services_service_user_home }}/.config/{{ services_service_user_name }}/dhparam.pem
4096
2022-12-16 21:49:50 +01:00
args:
2022-12-18 23:43:40 +01:00
creates: "\
{{ services_service_user_home }}/.config/{{ services_service_user_name }}/dhparam.pem"
2022-12-16 21:49:50 +01:00
register: services_deploy_rproxy_dhparam
2023-07-17 22:31:05 +02:00
- name: "{{ services_service_name }} : get uid"
ansible.builtin.getent:
database: "passwd"
key: "{{ services_service_user_name }}"
2022-12-16 21:49:50 +01:00
2023-07-17 22:31:05 +02:00
- name: "{{ services_service_name }} : get service status"
ansible.builtin.command: >-
systemctl --user show --property ActiveState --value
{{ services_service_user_name }}.service
environment:
XDG_RUNTIME_DIR: "/run/user/{{ getent_passwd[services_service_user_name].1 }}"
changed_when: false
register: services_deploy_rproxy_service_active_state
2022-12-16 21:49:50 +01:00
2023-07-17 22:31:05 +02:00
- name: "{{ services_service_name }} : restart the service"
2022-12-16 21:49:50 +01:00
ansible.builtin.systemd:
name: "pod-{{ services_service_name }}.service"
state: "restarted"
scope: "user"
2022-12-16 21:49:50 +01:00
when:
2023-07-17 22:31:05 +02:00
(services_deploy_rproxy_generic_config.changed or
services_deploy_rproxy_stream_config.changed or
services_deploy_rproxy_subdomain_config_files.changed or
2022-12-16 21:49:50 +01:00
services_deploy_rproxy_systemd_files.changed or
services_deploy_rproxy_certbot_timer.changed or
services_deploy_rproxy_dhparam.changed) and
services_deploy_rproxy_service_active_state.stdout == "active"
2022-12-16 21:49:50 +01:00
become_user: "{{ services_service_user_name }}"