Lego Role
Issue and renew ACME certificates with Lego on Linux or Windows.
Variables
| Variable | Type | Options | Default | Description |
|---|---|---|---|---|
lego_state_path | path | --- | {{ 'C:\\ProgramData\\lego' if ansible_os_family == 'Windows' else '/var/lib/lego' }} | private shared Lego state directory containing account keys and certificates |
lego_service_user | string | --- | lego | Linux account used to run Lego |
lego_service_group | string | --- | lego | Linux group used to run Lego |
lego_tag | string | --- | 5.4.1 | Lego release version |
lego_arch | string | --- | amd64 | Lego release architecture |
lego_path | path | --- | {{ 'C:\\ProgramData\\lego\\bin' if ansible_os_family == 'Windows' else '/usr/local/bin' }} | Lego installation directory |
lego_url | string | --- | https://github.com/go-acme/lego/releases/download/v{{ lego_tag }}/lego_v{{ lego_tag }}_linux_{{ lego_arch }}.tar.gz | Linux Lego archive URL |
lego_windows_url | string | --- | https://github.com/go-acme/lego/releases/download/v{{ lego_tag }}/lego_v{{ lego_tag }}_windows_{{ lego_arch }}.zip | Windows Lego archive URL |
lego_windows_state_acl | list of dict | --- | [{"user":"SYSTEM","rights":"FullControl"},{"user":"Administrators","rights":"FullControl"}] | Windows identities allowed to access private Lego state |
lego_windows_state_acl.user | string | --- | Windows identity receiving access | |
lego_windows_state_acl.rights | string | --- | Windows filesystem rights to grant | |
lego_binary | path | --- | {{ lego_path }}/lego | Lego executable path |
lego_bin_state | string | present, skip | present | whether to install Lego or use an existing binary |
lego_issue_on_deploy | bool | true, false | false | issue missing certificates immediately when the role is applied |
lego_renewal_threshold | integer | --- | 30 | renew certificates when fewer than this many days remain |
lego_acme_email | string | --- | "" | ACME account email address |
lego_acme_server | string | --- | https://acme-v02.api.letsencrypt.org/directory | ACME directory URL |
lego_acme_dns_resolvers | list of string | --- | [] | DNS resolvers passed to Lego for DNS-01 validation |
lego_certificates | list of dict | --- | [] | certificates to issue; each entry must define domains and a challenge |
lego_certificates.name | string | --- | unique identifier used for generated environment files and deployment markers | |
lego_certificates.domains | list of string | --- | domain names included in the certificate; the first domain names the output files | |
lego_certificates.key_type | string | RSA2048, RSA3072, RSA4096, EC256, EC384, EC521 | Lego private-key type | |
lego_certificates.account_id | string | --- | optional ACME account directory identifier when one email uses multiple accounts | |
lego_certificates.renewal | dict | --- | per-certificate renewal settings | |
lego_certificates.challenge | dict | --- | ACME challenge method and provider credentials | |
lego_certificates.deploy | dict | --- | optional certificate deployment targets | |
lego_certificates.hooks | dict | --- | commands run only after a changed certificate is deployed | |
lego_certificates.extra_args | list of string | --- | additional Lego arguments for this certificate | |
lego_default_deploy_directory_mode | string | --- | 0750 | default mode for Linux certificate deployment directories |
lego_default_deploy_file_mode | string | --- | 0640 | default mode for Linux deployed certificate files |
lego_default_deploy_private_key_mode | string | --- | 0640 | default mode for Linux deployed private keys |
lego_extra_args | list of string | --- | [] | additional Lego arguments passed to every certificate |