Before the advent of `ansible-vault`, and long before `certbot`/`lego`, I used to keep certificate files (and especially private key files) out of the Git repository. Now that certificates are stored in a separate repository, and only symlinks are stored in the configuration policy, this no longer makes any sense. In particular, it prevents the continuous enforcement process from installing Let's Encrypt certificates that have been automatically renewed. |
||
---|---|---|
.. | ||
defaults | ||
files | ||
handlers | ||
meta | ||
tasks | ||
templates |