init non ssl vhost for nginx, add to notes role

This commit is contained in:
2026-02-03 21:34:24 -07:00
parent 21618d2e5e
commit e7f6648e4a
6 changed files with 69 additions and 40 deletions

View File

@@ -17,12 +17,14 @@
path: /etc/nginx/ssl
state: directory
mode: '0755'
when: nginx_ssl_enabled
- name: Generate dhparams
command:
cmd: openssl dhparam -out /etc/nginx/ssl/dhparam.pem 4096
creates: /etc/nginx/ssl/dhparam.pem
notify: Restart nginx
when: nginx_ssl_enabled
- name: Start and enable nginx
service:
@@ -45,13 +47,25 @@
permanent: true
immediate: true
offline: true
when: nginx_ssl_enabled
- name: Create nginx vhosts
- name: Create nginx non-ssl vhost
template:
src: templates/vhost.conf.j2
dest: /etc/nginx/conf.d/{{ inventory_hostname}}.conf
owner: nginx
group: nginx
mode: '0644'
notify: Restart nginx
when: not nginx_ssl_enabled
- name: Create nginx ssl vhost
template:
src: templates/vhost_ssl.conf.j2
dest: /etc/nginx/conf.d/{{ inventory_hostname }}.conf
owner: nginx
group: nginx
mode: '0644'
notify: Restart nginx
when: nginx_ssl_enabled