From f5ab739c9ef049d05363f4cdca6181c969a6b444 Mon Sep 17 00:00:00 2001 From: "Dustin C. Hatch" Date: Mon, 11 Aug 2025 10:34:30 -0500 Subject: [PATCH] websites: dustinandtabitha: Switch to mod_md for cert The _dustinandtabitha.com_ site now obtains its certificate from Let's Encrypt using the Apache _mod_md_ (managed domain) module. This dramatically simplifies the deployment of this certificate, eliminating the need for _cert-manager_ to obtain it, _cert-exporter_ to add it to _certs.git_, and Jenkins to push it out to the web server. --- certs/websites/dustinandtabitha.com.cer | 1 - certs/websites/dustinandtabitha.com.key | 1 - .../files/dustinandtabitha.httpd.conf | 4 ++-- roles/websites/dustinandtabitha.com/meta/main.yml | 9 --------- 4 files changed, 2 insertions(+), 13 deletions(-) delete mode 120000 certs/websites/dustinandtabitha.com.cer delete mode 120000 certs/websites/dustinandtabitha.com.key delete mode 100644 roles/websites/dustinandtabitha.com/meta/main.yml diff --git a/certs/websites/dustinandtabitha.com.cer b/certs/websites/dustinandtabitha.com.cer deleted file mode 120000 index c8c320c..0000000 --- a/certs/websites/dustinandtabitha.com.cer +++ /dev/null @@ -1 +0,0 @@ -../lego/dustinandtabitha.com.crt \ No newline at end of file diff --git a/certs/websites/dustinandtabitha.com.key b/certs/websites/dustinandtabitha.com.key deleted file mode 120000 index 297d9f5..0000000 --- a/certs/websites/dustinandtabitha.com.key +++ /dev/null @@ -1 +0,0 @@ -../lego/dustinandtabitha.com.key \ No newline at end of file diff --git a/roles/websites/dustinandtabitha.com/files/dustinandtabitha.httpd.conf b/roles/websites/dustinandtabitha.com/files/dustinandtabitha.httpd.conf index ea267b8..ab9e1fe 100644 --- a/roles/websites/dustinandtabitha.com/files/dustinandtabitha.httpd.conf +++ b/roles/websites/dustinandtabitha.com/files/dustinandtabitha.httpd.conf @@ -1,3 +1,5 @@ +MDomain dustinandtabitha.com + ServerName dustinandtabitha.com ServerAlias www.dustinandtabitha.com @@ -11,8 +13,6 @@ ServerName dustinandtabitha.com ServerAlias www.dustinandtabitha.com Include conf.d/ssl.include -SSLCertificateKeyFile /etc/pki/tls/private/dustinandtabitha.com.key -SSLCertificateFile /etc/pki/tls/certs/dustinandtabitha.com.cer Header always set \ diff --git a/roles/websites/dustinandtabitha.com/meta/main.yml b/roles/websites/dustinandtabitha.com/meta/main.yml deleted file mode 100644 index b3c7823..0000000 --- a/roles/websites/dustinandtabitha.com/meta/main.yml +++ /dev/null @@ -1,9 +0,0 @@ -dependencies: -- role: cert - vars: - cert_src: websites/dustinandtabitha.com.cer - cert_dest: /etc/pki/tls/certs/dustinandtabitha.com.cer - cert_key_src: websites/dustinandtabitha.com.key - cert_key_dest: /etc/pki/tls/private/dustinandtabitha.com.key - tags: - - websites/dustinandtabitha