--- # Two-phase TLS setup: nginx first serves plain HTTP (for the certbot # webroot challenge), then certbot obtains real certs, then the TLS # vhosts (proxying to Woodpecker and Zot) are deployed and nginx reloaded. - name: Ensure certbot webroot directory exists ansible.builtin.file: path: "{{ certbot_webroot }}" state: directory mode: "0755" - name: Include geerlingguy.nginx role (HTTP-only vhosts for ACME challenge) ansible.builtin.include_role: name: geerlingguy.nginx - name: Include geerlingguy.certbot role (obtain certificates) ansible.builtin.include_role: name: geerlingguy.certbot - name: Deploy TLS vhost for Woodpecker ansible.builtin.template: src: woodpecker.conf.j2 dest: "/etc/nginx/sites-enabled/{{ woodpecker_domain }}.conf" mode: "0644" notify: Restart nginx - name: Deploy TLS vhost for Zot ansible.builtin.template: src: zot.conf.j2 dest: "/etc/nginx/sites-enabled/{{ zot_domain }}.conf" mode: "0644" notify: Restart nginx