mirror of
https://github.com/fscotto/infra.git
synced 2026-10-03 13:29:58 +00:00
59 lines
2.2 KiB
YAML
59 lines
2.2 KiB
YAML
---
|
|
- name: Manage the public domain of the restored production Gitea
|
|
tags: [atlas, gitea, gitea_public_domain]
|
|
when:
|
|
- atlas_manage_gitea | bool
|
|
- atlas_gitea_production_enabled | bool
|
|
- atlas_gitea_public_domain | length > 0
|
|
block:
|
|
- name: Require an explicit public Gitea hostname
|
|
ansible.builtin.assert:
|
|
that:
|
|
- atlas_gitea_public_domain is match('^[a-zA-Z0-9][a-zA-Z0-9.-]*\.[a-zA-Z]{2,}$')
|
|
|
|
- name: Inspect the restored private Gitea configuration
|
|
ansible.builtin.stat:
|
|
path: "{{ atlas_gitea_mountpoint }}/config/app.ini"
|
|
follow: false
|
|
register: atlas_gitea_public_config
|
|
|
|
- name: Refuse to create or replace an unprepared Gitea configuration
|
|
ansible.builtin.assert:
|
|
that:
|
|
- atlas_gitea_public_config.stat.isreg | default(false)
|
|
- atlas_gitea_public_config.stat.uid | int == atlas_gitea_uid | int
|
|
- atlas_gitea_public_config.stat.mode == '0600'
|
|
|
|
# app.ini contains secrets: preserve all unrelated settings and suppress diffs.
|
|
- name: Set only the declared public Gitea server fields
|
|
community.general.ini_file:
|
|
path: "{{ atlas_gitea_mountpoint }}/config/app.ini"
|
|
section: server
|
|
option: "{{ item.option }}"
|
|
value: "{{ item.value }}"
|
|
create: false
|
|
backup: true
|
|
owner: "{{ atlas_gitea_username }}"
|
|
group: "{{ atlas_gitea_group }}"
|
|
mode: "0600"
|
|
loop:
|
|
- { option: DOMAIN, value: "{{ atlas_gitea_public_domain }}" }
|
|
- { option: ROOT_URL, value: "https://{{ atlas_gitea_public_domain }}/" }
|
|
- { option: SSH_DOMAIN, value: "{{ atlas_gitea_public_domain }}" }
|
|
register: atlas_gitea_public_domain_update
|
|
no_log: true
|
|
diff: false
|
|
|
|
- name: Restart only Gitea when its public configuration changes
|
|
become_user: "{{ atlas_gitea_username }}"
|
|
ansible.builtin.systemd:
|
|
name: atlas-gitea.service
|
|
scope: user
|
|
state: restarted
|
|
environment:
|
|
XDG_RUNTIME_DIR: "/run/user/{{ atlas_gitea_uid }}"
|
|
DBUS_SESSION_BUS_ADDRESS: "unix:path=/run/user/{{ atlas_gitea_uid }}/bus"
|
|
when:
|
|
- atlas_gitea_public_domain_update is changed
|
|
- not ansible_check_mode
|