---

- name: Install dependencies
  apt: name={{ item }}
  with_items:
  - php7.0-fpm
  - php7.0-ldap
  - php7.0-sqlite3
  - php7.0-xml

- name: Create vhost directory
  file: path=/var/www/kitchen state=directory owner=www-data group=www-data

- name: Ensure (BK) certificates are available
  command: openssl req -x509 -nodes -newkey rsa:2048 -keyout /etc/nginx/ssl/www.binary-kitchen.de.key -out /etc/nginx/ssl/www.binary-kitchen.de.crt -days 730 -subj "/CN=www.binary-kitchen.de" creates=/etc/nginx/ssl/www.binary-kitchen.de.crt
  notify: Restart nginx

- name: Ensure (CCC-R) certificates are available
  command: openssl req -x509 -nodes -newkey rsa:2048 -keyout /etc/nginx/ssl/www.ccc-r.de.key -out /etc/nginx/ssl/www.ccc-r.de.crt -days 730 -subj "/CN=www.ccc-r.de" creates=/etc/nginx/ssl/www.ccc-r.de.crt
  notify: Restart nginx

- name: Ensure (MS-R) certificates are available
  command: openssl req -x509 -nodes -newkey rsa:2048 -keyout /etc/nginx/ssl/www.makerspace-regensburg.de.key -out /etc/nginx/ssl/www.makerspace-regensburg.de.crt -days 730 -subj "/CN=www.makerspace-regensburg.de" creates=/etc/nginx/ssl/www.makerspace-regensburg.de.crt
  notify: Restart nginx

- name: Configure certificate manager
  copy: src=certs dest=/etc/acme/domains.d/www.binary-kitchen.de.conf
  notify: Run certmgr

- name: Configure vhosts
  copy: src=vhost dest=/etc/nginx/sites-available/www
  notify: Restart nginx

- name: Enable vhosts
  file: src=/etc/nginx/sites-available/www dest=/etc/nginx/sites-enabled/www state=link
  notify: Restart nginx

- name: Start php7.0-fpm
  service: name=php7.0-fpm state=started enabled=yes