Forward Let's Encrypt challenges for updates from srv03 to srv02

This commit is contained in:
Alexander Dietrich 2017-04-07 20:54:58 +02:00
parent acf416f7ef
commit 81ccb6e583
5 changed files with 15 additions and 4 deletions

View file

@ -1,3 +1,4 @@
letsencrypt_srv02: true
nginx_resolver: 80.252.105.162 80.252.105.194
updates_ssl_certificate: /etc/ssl/certsync/updates.hamburg.freifunk.net.crt updates_ssl_certificate: /etc/ssl/certsync/updates.hamburg.freifunk.net.crt
updates_ssl_certificate_key: /etc/ssl/certsync/updates.hamburg.freifunk.net.key updates_ssl_certificate_key: /etc/ssl/certsync/updates.hamburg.freifunk.net.key
nginx_resolver: 80.252.105.162 80.252.105.194

View file

@ -1,4 +1,4 @@
--- ---
- src: https://github.com/7adietri/ansible-basics.git - src: https://github.com/7adietri/ansible-basics.git
version: v1.1.0 version: v1.1.1
name: basics name: basics

View file

@ -0,0 +1,5 @@
location ^~ /.well-known/acme-challenge {
proxy_set_header Host $host;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_pass http://srv02.hamburg.freifunk.net$request_uri;
}

View file

@ -1,4 +1,5 @@
--- ---
letsencrypt_srv02: false
site: updates site: updates
ssl_certificate: /etc/letsencrypt/live/updates.hamburg.freifunk.net/fullchain.pem updates_ssl_certificate: /etc/letsencrypt/live/updates.hamburg.freifunk.net/fullchain.pem
ssl_certificate_key: /etc/letsencrypt/live/updates.hamburg.freifunk.net/privkey.pem updates_ssl_certificate_key: /etc/letsencrypt/live/updates.hamburg.freifunk.net/privkey.pem

View file

@ -27,6 +27,10 @@ server {
location / { location / {
include /etc/nginx/include/listing.conf; include /etc/nginx/include/listing.conf;
} }
{% if letsencrypt_srv02 %}
include /etc/nginx/include/letsencrypt_srv02.conf;
{% endif %}
} }
server { server {