cleanup bastion deployment a bit
This commit is contained in:
parent
bc5f1ec01c
commit
61a891ae24
|
@ -0,0 +1,3 @@
|
||||||
|
- hosts: k3s-agent0,k3s-agent1,k3s-agent2,k3s-agent3
|
||||||
|
tasks:
|
||||||
|
- reboot:
|
|
@ -42,9 +42,3 @@
|
||||||
dest: /opt/certbot/certbot-deploy.sh
|
dest: /opt/certbot/certbot-deploy.sh
|
||||||
mode: '0700'
|
mode: '0700'
|
||||||
notify: Run certbot
|
notify: Run certbot
|
||||||
|
|
||||||
- name: Install weekly haproxy reload
|
|
||||||
cron:
|
|
||||||
name: "haproxy reload"
|
|
||||||
special_time: weekly
|
|
||||||
job: "/bin/systemctl reload haproxy"
|
|
|
@ -1,2 +1,3 @@
|
||||||
#!/bin/sh
|
#!/bin/sh
|
||||||
cat /etc/letsencrypt/live/{{ letsencrypt.domains[0] }}/fullchain.pem /etc/letsencrypt/live/{{ letsencrypt.domains[0] }}/privkey.pem >/etc/letsencrypt/live/{{ letsencrypt.domains[0] }}/{{ letsencrypt.domains[0] }}.pem
|
cat /etc/letsencrypt/live/{{ letsencrypt.domains[0] }}/fullchain.pem /etc/letsencrypt/live/{{ letsencrypt.domains[0] }}/privkey.pem >/etc/letsencrypt/live/{{ letsencrypt.domains[0] }}/{{ letsencrypt.domains[0] }}.pem
|
||||||
|
systemctl restart haproxy
|
|
@ -22,17 +22,19 @@
|
||||||
creates: /etc/wireguard/private.key
|
creates: /etc/wireguard/private.key
|
||||||
register: private_key_gen
|
register: private_key_gen
|
||||||
|
|
||||||
- name: Fetch private key
|
- name: Read private key
|
||||||
command: cat /etc/wireguard/private.key
|
command: cat /etc/wireguard/private.key
|
||||||
register: private_key
|
register: private_key
|
||||||
|
changed_when: false
|
||||||
|
|
||||||
- name: Generate public key
|
- name: Generate public key
|
||||||
shell: cat /etc/wireguard/private.key | wg pubkey >/etc/wireguard/public.key
|
shell: cat /etc/wireguard/private.key | wg pubkey >/etc/wireguard/public.key
|
||||||
when: not public_key_stats.stat.exists or private_key_gen.changed
|
when: not public_key_stats.stat.exists or private_key_gen.changed
|
||||||
|
|
||||||
- name: Fetch public key
|
- name: Read public key
|
||||||
command: cat /etc/wireguard/public.key
|
command: cat /etc/wireguard/public.key
|
||||||
register: public_key
|
register: public_key
|
||||||
|
changed_when: false
|
||||||
|
|
||||||
- name: Print public key
|
- name: Print public key
|
||||||
debug:
|
debug:
|
||||||
|
|
Loading…
Reference in New Issue