Skip to content

Commit f79e6d0

Browse files
IzakEygelaargdzien
authored andcommitted
Allow making use of Ansible-vault to encrypt and decrypt sensitive certs and keys (#95)
* Allow making use of Ansible-vault to encrypt sensitive certs and keys
1 parent 8ead2b7 commit f79e6d0

File tree

2 files changed

+5
-0
lines changed

2 files changed

+5
-0
lines changed

tasks/conf/upload-config.yml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -68,6 +68,8 @@
6868
copy:
6969
src: "{{ item }}"
7070
dest: "{{ nginx_ssl_crt_upload_dest }}"
71+
mode: 0640
72+
decrypt: yes
7173
backup: yes
7274
with_fileglob: "{{ nginx_ssl_crt_upload_src }}"
7375
when: nginx_ssl_upload_enable
@@ -76,6 +78,8 @@
7678
copy:
7779
src: "{{ item }}"
7880
dest: "{{ nginx_ssl_key_upload_dest }}"
81+
mode: 0640
82+
decrypt: yes
7983
backup: yes
8084
with_fileglob: "{{ nginx_ssl_key_upload_src }}"
8185
when: nginx_ssl_upload_enable

tasks/plus/setup-license.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -8,6 +8,7 @@
88
copy:
99
src: "{{ item }}"
1010
dest: /etc/ssl/nginx
11+
decrypt: yes
1112
with_items:
1213
- "{{ nginx_license.certificate }}"
1314
- "{{ nginx_license.key }}"

0 commit comments

Comments
 (0)