Skip to main content

Lego Role

Issue and renew ACME certificates with Lego on Linux or Windows.


Variables​

VariableTypeOptionsDefaultDescription
lego_state_pathpath---{{ 'C:\\ProgramData\\lego' if ansible_os_family == 'Windows' else '/var/lib/lego' }}private shared Lego state directory containing account keys and certificates
lego_service_userstring---legoLinux account used to run Lego
lego_service_groupstring---legoLinux group used to run Lego
lego_tagstring---5.4.1Lego release version
lego_archstring---amd64Lego release architecture
lego_pathpath---{{ 'C:\\ProgramData\\lego\\bin' if ansible_os_family == 'Windows' else '/usr/local/bin' }}Lego installation directory
lego_urlstring---https://github.com/go-acme/lego/releases/download/v{{ lego_tag }}/lego_v{{ lego_tag }}_linux_{{ lego_arch }}.tar.gzLinux Lego archive URL
lego_windows_urlstring---https://github.com/go-acme/lego/releases/download/v{{ lego_tag }}/lego_v{{ lego_tag }}_windows_{{ lego_arch }}.zipWindows Lego archive URL
lego_windows_state_acllist of dict---[{"user":"SYSTEM","rights":"FullControl"},{"user":"Administrators","rights":"FullControl"}]Windows identities allowed to access private Lego state
lego_windows_state_acl.userstring---Windows identity receiving access
lego_windows_state_acl.rightsstring---Windows filesystem rights to grant
lego_binarypath---{{ lego_path }}/legoLego executable path
lego_bin_statestringpresent, skippresentwhether to install Lego or use an existing binary
lego_issue_on_deploybooltrue, falsefalseissue missing certificates immediately when the role is applied
lego_renewal_thresholdinteger---30renew certificates when fewer than this many days remain
lego_acme_emailstring---""ACME account email address
lego_acme_serverstring---https://acme-v02.api.letsencrypt.org/directoryACME directory URL
lego_acme_dns_resolverslist of string---[]DNS resolvers passed to Lego for DNS-01 validation
lego_certificateslist of dict---[]certificates to issue; each entry must define domains and a challenge
lego_certificates.namestring---unique identifier used for generated environment files and deployment markers
lego_certificates.domainslist of string---domain names included in the certificate; the first domain names the output files
lego_certificates.key_typestringRSA2048, RSA3072, RSA4096, EC256, EC384, EC521Lego private-key type
lego_certificates.account_idstring---optional ACME account directory identifier when one email uses multiple accounts
lego_certificates.renewaldict---per-certificate renewal settings
lego_certificates.challengedict---ACME challenge method and provider credentials
lego_certificates.deploydict---optional certificate deployment targets
lego_certificates.hooksdict---commands run only after a changed certificate is deployed
lego_certificates.extra_argslist of string---additional Lego arguments for this certificate
lego_default_deploy_directory_modestring---0750default mode for Linux certificate deployment directories
lego_default_deploy_file_modestring---0640default mode for Linux deployed certificate files
lego_default_deploy_private_key_modestring---0640default mode for Linux deployed private keys
lego_extra_argslist of string---[]additional Lego arguments passed to every certificate