aboutsummaryrefslogtreecommitdiff
path: root/roles/nginx
diff options
context:
space:
mode:
authorKumar <kumar@kumardamani.xyz>2021-11-23 14:59:08 +0000
committerKumar Damani <me@kumardamani.net>2022-03-25 19:45:25 +0000
commita857eb82ec9c4a79ad5e41462e2ab82c2660982e (patch)
tree9ca51ddfb551322bd4d2fa3f949fa8898032632d /roles/nginx
initial commit
Diffstat (limited to 'roles/nginx')
-rw-r--r--roles/nginx/defaults/main.yaml7
-rw-r--r--roles/nginx/handlers/main.yaml7
-rw-r--r--roles/nginx/tasks/main.yaml67
-rw-r--r--roles/nginx/templates/app.nginx.conf.j221
-rw-r--r--roles/nginx/templates/http.nginx.conf.j224
5 files changed, 126 insertions, 0 deletions
diff --git a/roles/nginx/defaults/main.yaml b/roles/nginx/defaults/main.yaml
new file mode 100644
index 0000000..af90628
--- /dev/null
+++ b/roles/nginx/defaults/main.yaml
@@ -0,0 +1,7 @@
+# Default Values
+---
+
+nginx_port: '80'
+nginx_website_domains: []
+nginx_global_apps_domain: ''
+nginx_apps_confs: {}
diff --git a/roles/nginx/handlers/main.yaml b/roles/nginx/handlers/main.yaml
new file mode 100644
index 0000000..7613b54
--- /dev/null
+++ b/roles/nginx/handlers/main.yaml
@@ -0,0 +1,7 @@
+---
+
+- name: 'Restart nginx'
+ systemd:
+ name: 'nginx'
+ state: 'restarted'
+ listen: 'nginx_restart'
diff --git a/roles/nginx/tasks/main.yaml b/roles/nginx/tasks/main.yaml
new file mode 100644
index 0000000..91fd8a5
--- /dev/null
+++ b/roles/nginx/tasks/main.yaml
@@ -0,0 +1,67 @@
+# References
+# https://www.digitalocean.com/community/tutorials/how-to-install-nginx-on-debian-10
+
+---
+
+- name: 'Install nginx'
+ apt:
+ name:
+ - 'nginx'
+ state: 'present'
+ update_cache: true
+ notify:
+ - 'nginx_restart'
+
+- name: 'Copy the http nginx.conf files'
+ template:
+ src: 'http.nginx.conf.j2'
+ dest: '/etc/nginx/sites-available/{{ item }}'
+ mode: '644'
+ loop:
+ - 'default'
+ - 'kumardamani.xyz'
+ - 'amayastuff.com'
+ register: '_config_copy'
+ notify:
+ - 'nginx_restart'
+
+- name: 'Remove the old symbolic link'
+ file:
+ path: '/etc/nginx/sites-enabled/{{ item }}'
+ state: 'absent'
+ loop: '{{ nginx_website_domains }}'
+
+- name: 'Create a http symbolic link'
+ file:
+ src: '/etc/nginx/sites-available/{{ item }}'
+ dest: '/etc/nginx/sites-enabled/{{ item }}'
+ state: 'link'
+ loop: '{{ nginx_website_domains }}'
+
+- name: 'Check nginx config' # noqa no-changed-when
+ command: 'nginx -t'
+
+- name: 'Copy the http nginx.conf for apps'
+ template:
+ src: 'app.nginx.conf.j2'
+ dest: '/etc/nginx/sites-available/{{ item.app }}'
+ mode: '644'
+ loop: '{{ nginx_apps_confs }}'
+ notify:
+ - 'nginx_restart'
+
+- name: 'Remove the old symbolic link for apps'
+ file:
+ path: '/etc/nginx/sites-enabled/{{ item.app }}'
+ state: 'absent'
+ loop: '{{ nginx_apps_confs }}'
+
+- name: 'Create a http symbolic link for apps'
+ file:
+ src: '/etc/nginx/sites-available/{{ item.app }}'
+ dest: '/etc/nginx/sites-enabled/{{ item.app }}'
+ state: 'link'
+ loop: '{{ nginx_apps_confs }}'
+
+- name: 'Check nginx config' # noqa no-changed-when
+ command: 'nginx -t'
diff --git a/roles/nginx/templates/app.nginx.conf.j2 b/roles/nginx/templates/app.nginx.conf.j2
new file mode 100644
index 0000000..c87fe29
--- /dev/null
+++ b/roles/nginx/templates/app.nginx.conf.j2
@@ -0,0 +1,21 @@
+server {
+ listen 443 ssl;
+ root _;
+ server_name {{ item.conf.access_domain }};
+ ssl_certificate /etc/letsencrypt/live/{{ nginx_global_apps_domain }}/fullchain.pem;
+ ssl_certificate_key /etc/letsencrypt/live/{{ nginx_global_apps_domain }}/privkey.pem;
+ ssl_protocols TLSv1.1 TLSv1.2;
+ ssl_ciphers HIGH:!aNULL:!MD5;
+
+ location / {
+ proxy_pass http://127.0.0.1:{{ item.conf.port }};
+ proxy_set_header Host $host;
+ proxy_set_header X-Real-IP $remote_addr;
+ proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
+ proxy_set_header X-Forwarded-Host $server_name;
+ proxy_set_header X-Forwarded-Proto https;
+ proxy_read_timeout 1200s;
+ client_max_body_size 0;
+ error_log /var/log/nginx/{{ item.app }}.error.log;
+ }
+}
diff --git a/roles/nginx/templates/http.nginx.conf.j2 b/roles/nginx/templates/http.nginx.conf.j2
new file mode 100644
index 0000000..2d4c61b
--- /dev/null
+++ b/roles/nginx/templates/http.nginx.conf.j2
@@ -0,0 +1,24 @@
+server {
+ {% if item == "default" %}
+ listen 80 default_server;
+ server_name _;
+ return 301 https://$host$request_uri;
+ {% else %}
+ listen 443 ssl;
+ root /var/www/{{ item }}/html;
+ server_name {{ item }} www.{{ item }};
+ ssl_certificate /etc/letsencrypt/live/{{ item }}/fullchain.pem;
+ ssl_certificate_key /etc/letsencrypt/live/{{ item }}/privkey.pem;
+ ssl_protocols TLSv1.1 TLSv1.2;
+ ssl_ciphers HIGH:!aNULL:!MD5;
+ index index.html index.htm index.nginx-debian.html;
+
+ location ~ /.well-known {
+ allow all;
+ }
+
+ location / {
+ try_files $uri $uri/ =404;
+ }
+ {% endif %}
+}