Split the certificate keys by primary domain

This commit is contained in:
2026-02-09 09:25:41 +00:00
parent d7c18b747e
commit 557571c9fd
3 changed files with 17 additions and 9 deletions

View File

@@ -14,8 +14,8 @@ server {
listen [::]:443 ssl; listen [::]:443 ssl;
server_name m5p3nc3r.co.uk www.m5p3nc3r.co.uk; server_name m5p3nc3r.co.uk www.m5p3nc3r.co.uk;
ssl_certificate /etc/letsencrypt/live/apptabulous.co.uk/fullchain.pem; ssl_certificate /etc/letsencrypt/live/m5p3nc3r.co.uk/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/apptabulous.co.uk/privkey.pem; ssl_certificate_key /etc/letsencrypt/live/m5p3nc3r.co.uk/privkey.pem;
if ($block_uri = 1) { if ($block_uri = 1) {
return 403; return 403;
@@ -34,8 +34,8 @@ server {
listen [::]:443 ssl; listen [::]:443 ssl;
server_name gitea.m5p3nc3r.co.uk; server_name gitea.m5p3nc3r.co.uk;
ssl_certificate /etc/letsencrypt/live/apptabulous.co.uk/fullchain.pem; ssl_certificate /etc/letsencrypt/live/m5p3nc3r.co.uk/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/apptabulous.co.uk/privkey.pem; ssl_certificate_key /etc/letsencrypt/live/m5p3nc3r.co.uk/privkey.pem;
# if ($block_uri = 1) { # if ($block_uri = 1) {
# return 403; # return 403;

View File

@@ -14,15 +14,18 @@
certbot_admin_email: matthew@thespencers.me.uk certbot_admin_email: matthew@thespencers.me.uk
certbot_certs: certbot_certs:
- webroot: "/var/www/html" - domains:
domains:
- "apptabulous.co.uk" - "apptabulous.co.uk"
- "www.apptabulous.co.uk" - "www.apptabulous.co.uk"
- "hub.apptabulous.co.uk" - "hub.apptabulous.co.uk"
- "watchtower.apptabulous.co.uk" - "watchtower.apptabulous.co.uk"
webroot: "/var/www/html"
- domains:
- "m5p3nc3r.co.uk" - "m5p3nc3r.co.uk"
- "www.m5p3nc3r.co.uk" - "www.m5p3nc3r.co.uk"
- "gitea.m5p3nc3r.co.uk" - "gitea.m5p3nc3r.co.uk"
webroot: "/var/www/html"
certbot_repo: https://github.com/certbot/certbot.git certbot_repo: https://github.com/certbot/certbot.git
certbot_version: master certbot_version: master

View File

@@ -1,8 +1,13 @@
[all:vars]
ansible_user=matt
[frontend] [frontend]
rpi4-2.localdomain rpi4-2.local
[github-runners] [github-runners]
rpi5-1.localdomain rpi5-1.local
[gitea] [gitea]
rpi5-2.localdomain rpi5-2.local