From 2c04195a35fb2a425abfd0c6f0ce218176ed711e Mon Sep 17 00:00:00 2001 From: Dmitry Ilvokhin Date: Sat, 13 Jan 2024 17:28:35 +0000 Subject: Add role for blog.ilvokhin.com --- roles/blog/files/blog.ilvokhin.com | 32 +++++++++++++++++++++++++++++++ roles/blog/tasks/main.yml | 39 ++++++++++++++++++++++++++++++++++++++ 2 files changed, 71 insertions(+) create mode 100644 roles/blog/files/blog.ilvokhin.com create mode 100644 roles/blog/tasks/main.yml (limited to 'roles/blog') diff --git a/roles/blog/files/blog.ilvokhin.com b/roles/blog/files/blog.ilvokhin.com new file mode 100644 index 0000000..b00ec9c --- /dev/null +++ b/roles/blog/files/blog.ilvokhin.com @@ -0,0 +1,32 @@ +server { + server_name blog.ilvokhin.com www.blog.ilvokhin.com; + + root /srv/http/blog.ilvokhin.com; + index index.html; + + location / { + try_files $uri $uri/ = 404; + } + + listen [::]:443 ssl; + listen 443 ssl; + + ssl_certificate /etc/letsencrypt/live/blog.ilvokhin.com/fullchain.pem; + ssl_certificate_key /etc/letsencrypt/live/blog.ilvokhin.com/privkey.pem; +} + +server { + if ($host = www.blog.ilvokhin.com) { + return 301 https://$host$request_uri; + } + + if ($host = blog.ilvokhin.com) { + return 301 https://$host$request_uri; + } + + server_name blog.ilvokhin.com www.blog.ilvokhin.com; + + listen 80; + listen [::]:80; + return 404; +} diff --git a/roles/blog/tasks/main.yml b/roles/blog/tasks/main.yml new file mode 100644 index 0000000..5f9288e --- /dev/null +++ b/roles/blog/tasks/main.yml @@ -0,0 +1,39 @@ +- name: Create /srv/http/blog.ilvokhin.com directory + ansible.builtin.file: + path: /srv/http/blog.ilvokhin.com + state: directory + owner: http + group: http + mode: u+rw,g+rw,o+r + +- name: Request SSL certificate for blog.ilvokhin.com + ansible.builtin.include_role: + name: certificate + vars: + domains: + - blog.ilvokhin.com + - www.blog.ilvokhin.com + +- ansible.builtin.include_role: + name: nginx + +- name: Configure nginx for blog.ilvokhin.com + ansible.builtin.copy: + src: files/blog.ilvokhin.com + dest: /etc/nginx/sites-available + owner: root + group: root + mode: u+rw,g+r,o+r + notify: + - Reload nginx + +- name: Enable blog.ilvokhin.com site + ansible.builtin.file: + src: /etc/nginx/sites-available/blog.ilvokhin.com + dest: /etc/nginx/sites-enabled/blog.ilvokhin.com + owner: root + group: root + mode: u+rw,g+r,o+r + state: link + notify: + - Reload nginx -- cgit v1.2.3-70-g09d2