Skip to content

Commit 8137d5b

Browse files
author
Federico Ceratto
committed
Move all ACME in sites-enabled/letsencrypt-http
1 parent 1940744 commit 8137d5b

File tree

13 files changed

+6
-78
lines changed

13 files changed

+6
-78
lines changed

ansible/roles/countly/tasks/main.yml

-6
Original file line numberDiff line numberDiff line change
@@ -6,9 +6,3 @@
66
group: root
77
mode: 0644
88
notify: restart nginx
9-
10-
- name: delete letsencrypt nginx config
11-
file:
12-
state: absent
13-
path: "/etc/nginx/sites-enabled/letsencrypt-http"
14-
notify: restart nginx

ansible/roles/explorer/tasks/main.yml

-5
Original file line numberDiff line numberDiff line change
@@ -42,9 +42,4 @@
4242
user: "{{ user_group_id.stdout }}"
4343
restart_policy: unless-stopped
4444

45-
- name: delete letsencrypt nginx config
46-
file:
47-
state: absent
48-
path: "/etc/nginx/sites-enabled/letsencrypt-http"
49-
notify: reload nginx
5045
...

ansible/roles/github-webhooks/tasks/main.yml

-5
Original file line numberDiff line numberDiff line change
@@ -51,9 +51,4 @@
5151
- "/srv/github-webhooks:/srv/github-webhooks"
5252
restart_policy: unless-stopped
5353

54-
- name: delete letsencrypt nginx config
55-
file:
56-
state: absent
57-
path: "/etc/nginx/sites-enabled/letsencrypt-http"
58-
notify: reload nginx
5954
...

ansible/roles/letsencrypt/templates/letsencrypt-http

+6-5
Original file line numberDiff line numberDiff line change
@@ -2,16 +2,17 @@
22
# Generated by ansible
33
# roles/letsencrypt/templates/letsencrypt-http
44

5-
{% for domain in letsencrypt_domains %}
6-
7-
# Domain: {{ domain }}
85
server {
6+
# Listen on port 80 for *any* domain
97
listen 80;
10-
server_name {{ domain }};
8+
server_name _;
119

10+
# Serve ACME challenge from disk
1211
location /.well-known/acme-challenge {
1312
root /var/www/letsencrypt;
1413
try_files $uri $uri/ =404;
1514
}
15+
16+
# Redirect everything else to port 443 regardless of domain
17+
return 301 https://$host$request_uri;
1618
}
17-
{% endfor %}

ansible/roles/ooni-bouncer/templates/ngx-bouncer

-6
Original file line numberDiff line numberDiff line change
@@ -36,10 +36,4 @@ server {
3636
location / {
3737
proxy_pass http://127.0.0.1:{{ bouncer_port }};
3838
}
39-
40-
location /.well-known/acme-challenge {
41-
default_type "text/plain";
42-
root /var/www/letsencrypt;
43-
try_files $uri $uri/ =404;
44-
}
4539
}

ansible/roles/ooni-collector/templates/ngx-collector

-6
Original file line numberDiff line numberDiff line change
@@ -37,10 +37,4 @@ server {
3737
location / {
3838
proxy_pass http://127.0.0.1:{{ collector_port }};
3939
}
40-
41-
location /.well-known/acme-challenge {
42-
default_type "text/plain";
43-
root /var/www/letsencrypt;
44-
try_files $uri $uri/ =404;
45-
}
4640
}

ansible/roles/ooni-measurements/tasks/main.yml

-8
Original file line numberDiff line numberDiff line change
@@ -59,11 +59,3 @@
5959
command: "gunicorn --config python:measurements.gunicorn_config --bind 0.0.0.0:{{ oomsm_backend_port }} --workers 20 --timeout 60 measurements.wsgi"
6060
# user: "oomsmweb:oomsmweb" XXX-UID
6161
restart_policy: unless-stopped
62-
63-
- name: delete letsencrypt nginx config
64-
file:
65-
state: absent
66-
path: "/etc/nginx/sites-enabled/letsencrypt-http"
67-
notify:
68-
- test API nginx config
69-
- reload API nginx

ansible/roles/ooni-orchestrate/templates/orchestra_nginx.conf.j2

-12
Original file line numberDiff line numberDiff line change
@@ -18,15 +18,3 @@ server {
1818
proxy_read_timeout 900;
1919
}
2020
}
21-
22-
server {
23-
server_name _;
24-
25-
listen 80;
26-
27-
location /.well-known/acme-challenge {
28-
default_type "text/plain";
29-
root /var/www/letsencrypt;
30-
try_files $uri $uri/ =404;
31-
}
32-
}

ansible/roles/ooni-run/tasks/main.yml

-6
Original file line numberDiff line numberDiff line change
@@ -48,9 +48,3 @@
4848
group: root
4949
mode: 0644
5050
notify: restart nginx
51-
52-
- name: delete letsencrypt nginx config
53-
file:
54-
state: absent
55-
path: "/etc/nginx/sites-enabled/letsencrypt-http"
56-
notify: restart nginx

ansible/roles/orchestra-frontend/tasks/main.yml

-6
Original file line numberDiff line numberDiff line change
@@ -54,9 +54,3 @@
5454
group: root
5555
mode: 0644
5656
notify: restart nginx
57-
58-
- name: delete letsencrypt nginx config
59-
file:
60-
state: absent
61-
path: "/etc/nginx/sites-enabled/letsencrypt-http"
62-
notify: restart nginx

ansible/roles/probe-services/tasks/main.yml

-6
Original file line numberDiff line numberDiff line change
@@ -11,12 +11,6 @@
1111
template: src=probe-services-nginx dest=/etc/nginx/sites-enabled/probe-services
1212
notify: reload nginx
1313

14-
- name: delete letsencrypt nginx config
15-
file:
16-
state: absent
17-
path: "/etc/nginx/sites-enabled/letsencrypt-http"
18-
notify: reload nginx
19-
2014
- name: mkdir for config and data
2115
file:
2216
path: "{{ item }}"

ansible/roles/probe-services/templates/probe-services-nginx

-1
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,6 @@
33
{% import 'common.j2' as c %}
44

55
server {
6-
listen 80;
76
listen 443 ssl;
87
{{ c.ssl_letsencrypt(probe_services_domain) }}
98

ansible/roles/slackin/tasks/main.yml

-6
Original file line numberDiff line numberDiff line change
@@ -40,9 +40,3 @@
4040
group: root
4141
mode: 0644
4242
notify: restart nginx
43-
44-
- name: delete letsencrypt nginx config
45-
file:
46-
state: absent
47-
path: "/etc/nginx/sites-enabled/letsencrypt-http"
48-
notify: reload nginx

0 commit comments

Comments
 (0)