Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -28,6 +28,7 @@ Manage a SSL certificate on a server
| ssl_certificate_files | | List of files to copy |
| ssl_certificate_group | root | Group to own the cert |
| ssl_certificate_mode | 0440 | Cert mode |
| ssl_certificate_notify | `[]` | List of handlers that should be notified on a change |
| ssl_certificate_owner | root | User to own the cert |
| ssl_certificate_path | /etc/ssl/private | Where to store the certificates |
| ssl_certificate_path_cert | `{ssl_certificate_path}/{ssl_certificate_name}` | Full certificate path |
Expand Down
4 changes: 3 additions & 1 deletion defaults/main.yml
Original file line number Diff line number Diff line change
Expand Up @@ -24,4 +24,6 @@ ssl_certificate_files_extra: []
ssl_certificate_source_cert_path: "{{ ssl_certificate_source_path + '/' + ssl_certificate_name + '/' }}"
ssl_certificate_source_ca_file: ca.crt
ssl_certificate_source_cert_file: server.crt
ssl_certificate_source_key_file: server.key
ssl_certificate_source_key_file: server.key

ssl_certificate_notify: []
32 changes: 28 additions & 4 deletions molecule/default/converge.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,14 @@
become: yes
vars:
ssl_certificate_name: kakaw
ssl_certificate_notify:
- Notify of change
handlers:
- name: Notify of change
ansible.builtin.file:
path: /tmp/notify_was_called
state: touch
mode: '0644'
roles:
- outsideopen.ssl_certificate

Expand Down Expand Up @@ -59,7 +67,23 @@
vars:
ssl_certificate_name: kakaw
ssl_certificate_path_cert: /etc/custom_cert
tasks:
- name: Create certificate
ansible.builtin.import_role:
name: outsideopen.ssl_certificate
roles:
- outsideopen.ssl_certificate

- name: 7 | Converge with custom notifications on full chain change
hosts: all
become: yes
handlers:
- name: Notify of change
ansible.builtin.file:
path: /tmp/notify_called_by_fullchain
state: touch
mode: '0644'
vars:
ssl_certificate_notify:
- Notify of change
ssl_certificate_name: kakaw
ssl_certificate_path_cert: /etc/custom_cert
ssl_certificate_create_fullchain: true
roles:
- outsideopen.ssl_certificate
12 changes: 12 additions & 0 deletions molecule/default/verify.yml
Original file line number Diff line number Diff line change
Expand Up @@ -11,6 +11,12 @@
register: __file
failed_when: not __file.stat.exists

- name: 1 | check that the notification was called
ansible.builtin.stat:
path: /tmp/notify_was_called
register: __notify_path
failed_when: not __notify_path.stat.exists

# converge #2 (alternate paths)
- name: 2 | check if /alt/circle/circle.key exists
ansible.builtin.stat:
Expand Down Expand Up @@ -50,3 +56,9 @@
path: /etc/custom_cert/kakaw.key
register: __full_path
failed_when: not __full_path.stat.exists

- name: 7 | check that full chain notify was called
ansible.builtin.stat:
path: /tmp/notify_called_by_fullchain
register: __notify_path
failed_when: not __notify_path.stat.exists
1 change: 1 addition & 0 deletions tasks/combine_cert.yml
Original file line number Diff line number Diff line change
Expand Up @@ -15,5 +15,6 @@
owner: "{{ ssl_certificate_owner }}"
group: "{{ ssl_certificate_group }}"
mode: "{{ ssl_certificate_mode }}"
notify: "{{ ssl_certificate_notify | default([]) }}"
tags:
- update-ssl
1 change: 1 addition & 0 deletions tasks/main.yml
Original file line number Diff line number Diff line change
Expand Up @@ -32,6 +32,7 @@
__ssl_cert_found: "{{ lookup('first_found', params) }}"
loop: "{{ ssl_certificate_files }}"
when: __ssl_cert_found | length > 0
notify: "{{ ssl_certificate_notify | default([]) }}"
tags:
- update-ssl

Expand Down
Loading