Don't use set_fact

This commit is contained in:
nemunaire 2024-07-07 14:07:51 +02:00
parent 7a1897b0cb
commit fd3d818b6e
2 changed files with 22 additions and 15 deletions

View File

@ -1,19 +1,11 @@
---
- ansible.builtin.set_fact:
unsecure_server: |
location @{{ instance_name | default(ansible_play_name) | replace(" ", "_") }}_neighbor {
proxy_pass http://{{ neighbor.host }};
proxy_set_header Host {{ neighbor.target }};
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
}
nginx_acme_challenge: |
try_files $uri $uri/ @{{ instance_name | default(ansible_play_name) | replace(" ", "_") }}_neighbor;
- ansible.builtin.set_fact:
onlyifnotexist: true
server: ""
when: notls
- ansible.builtin.include_role:
name: "{{ next_role }}"
when: not notls
- ansible.builtin.include_role:
name: "{{ next_role }}"
vars:
onlyifnotexist: true
server: ""
when: notls

View File

@ -1,2 +1,17 @@
---
next_role: re.nemunai.nginx-config-svc
unsecure_server: |
location @{{ instance_name | default(ansible_play_name) | replace(" ", "_") }}_neighbor {
proxy_pass http://{{ neighbor.host }};
{% if "target" in neighbor %}proxy_set_header Host {{ neighbor.target }};{% endif %}
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
}
location / {
# enforce https
return 301 https://$server_name:443$request_uri;
}
nginx_acme_challenge: |
try_files $uri $uri/ @{{ instance_name | default(ansible_play_name) | replace(" ", "_") }}_neighbor;