system-config/playbooks/roles/letsencrypt-create-certs
Clark Boylan 96298bfcc4 Restart apache on graphite when LE updates certs
This was touching a file previously, but we can safely restart apache if
the certs update as this happens non concurrently with puppet updates.

Do this to ensure the cert is kept up to date.

Change-Id: I28168770258c38d13202fad48be3f61ecdc8ec4d
2020-06-03 09:51:23 -07:00
..
defaults letsencrypt: split staging and self-signed generation 2019-04-10 08:47:32 +10:00
handlers Restart apache on graphite when LE updates certs 2020-06-03 09:51:23 -07:00
tasks Generate ssl check list directly from letsencrypt variables 2020-05-20 14:27:14 +10:00
README.rst letsencrypt: split staging and self-signed generation 2019-04-10 08:47:32 +10:00

Generate letsencrypt certificates

This must run after the letsencrypt-install-acme-sh, letsencrypt-request-certs and letsencrypt-install-txt-records roles. It will run the acme.sh process to create the certificates on the host.

Role Variables

If set to True, will locally generate self-signed certificates in the same locations the real script would, instead of contacting letsencrypt. This is set during gate testing as the authentication tokens are not available.

If set to True will use the letsencrypt staging environment, rather than make production requests. Useful during initial provisioning of hosts to avoid affecting production quotas.

The same variable as described in letsencrypt-request-certs.