LAN/local deployment support, OS compat, Cloudflare Tunnel
- Smart TLS: skip certbot for IPs/.local/.lan, self-signed with SAN, HSTS max-age=0 for self-signed certs, split LAN vs public messages - Dynamic PHP: versionless meta-packages, runtime detection via php_ver fact - Vaultwarden: fail-fast on armv7l (32-bit ARM not supported upstream) - Module prompts: accept IPs for matrix/cloud/vault/media, hard error on email with IP, all_in_one skips certbot email for LAN - Matrix: skip matrix. prefix strip for IPs, warn about immutable server_name - OS family guards: ansible_os_family == Debian on all apt tasks - SSH key path: expanduser().resolve() on user-provided key paths - Cloudflare Tunnel: post-deploy script (setup-tunnel.sh) using CF API token — no browser auth needed, creates tunnel + credentials + DNS + systemd Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
@@ -64,12 +64,12 @@
|
||||
|
||||
- name: Configure PHP-FPM pool for Nextcloud
|
||||
copy:
|
||||
dest: /etc/php/8.2/fpm/pool.d/nextcloud.conf
|
||||
dest: "/etc/php/{{ php_ver }}/fpm/pool.d/nextcloud.conf"
|
||||
content: |
|
||||
[nextcloud]
|
||||
user = www-data
|
||||
group = www-data
|
||||
listen = /run/php/php8.2-fpm-nextcloud.sock
|
||||
listen = /run/php/php{{ php_ver }}-fpm-nextcloud.sock
|
||||
listen.owner = www-data
|
||||
listen.group = www-data
|
||||
pm = dynamic
|
||||
|
||||
Reference in New Issue
Block a user