fix renewal

This commit is contained in:
Elizabeth Hunt 2024-01-12 20:58:04 -05:00
parent cee3332a3c
commit 0bfb4a99cd

View File

@ -84,11 +84,8 @@
- name: reload nginx to activate sites
service: name=nginx state=restarted
- name: add daily letsencrypt cronjob for cert renewal based on hash of domain name to prevent hitting LE rate limits
- name: add daily renewal
cron:
name: "letsencrypt_renewal_{{ item.stdout }}"
minute: "0"
hour: "5,17"
job: "REQUESTS_CA_BUNDLE=/usr/local/share/ca-certificates/{{ step_bootstrap_ca_url }}.crt letsencrypt renew --server https://{{ step_bootstrap_ca_url }}:{{ step_ca_port }}/acme/ACME/directory --cert-name {{ item.stdout }} -n --webroot -w /var/www/letsencrypt --agree-tos --email {{ step_acme_cert_contact }} && service nginx reload"
loop: "{{ extracted_domains.results }}"
when: item.stdout != ""
name: "letsencrypt_renewal"
special_time: "daily"
job: "REQUESTS_CA_BUNDLE=/usr/local/share/ca-certificates/{{ step_bootstrap_ca_url }}.crt letsencrypt renew --force-renewal"