]> freie-schul-it.de Git - fsit_smgt.git/blobdiff - tasks/kivitendo.yml
added kivitendo task server as service
[fsit_smgt.git] / tasks / kivitendo.yml
index 7c288ff03954a6ab9042036f4c677d06271677ba..836cf9bcb423e8317e0e2eb186b18be70a10e5a0 100644 (file)
@@ -89,7 +89,7 @@
 
 - name: Copy over Kivitendo.conf.
   ansible.builtin.copy:
-    src: files/kivitendo.conf
+    src: files/kivitendo/kivitendo.conf
     dest: /var/www/kivitendo-erp/config/kivitendo.conf
     owner: www-data
     mode: 'u=rw,g=rw,o='
     state: directory
     mode:  'u=Xrw,g=Xrw,o='
 
-
 - name: Make kivi_documents directory.
   ansible.builtin.file:
     path: /var/www/kivitendo-erp/kivi_documents
     - templates
     - webdav
 
+# postrgesql for kivi
+- name: Remove existing rules to ensure correct ordering of the rules
+  ansible.builtin.postgresql_pg_hba:
+    dest:      /etc/postgresql/17/main/pg_hba.conf
+    overwrite: true
+    contype:   local
+    users:     all
+    databases: all
+    method:    peer
+
+- name: Allow access from localhost to Postgresql.
+  ansible.builtin.postgresql_pg_hba:
+    dest:      /etc/postgresql/17/main/pg_hba.conf
+    contype:   host
+    users:     postgres
+    databases: all
+    address:   127.0.0.1/32
+    method:    trust
+  notify: Restart postgresql
+
+# apache server for kivi
+- name: Activate apache fastcgi, headers and ssl modules.
+  community.general.apache2_module:
+    state: present
+    name: "{{ item }}"
+  loop:
+    - fcgid
+    - headers
+    - ssl
+    - rewrite
+    - socache_shmcb
+  notify: Restart apache
+
+- name: Copy over apacha ssl-conf
+  ansible.builtin.copy:
+    src: files/kivitendo/default-ssl.conf
+    dest: /etc/apache2/sites-available/default-ssl.conf
+    mode: '640'
+  notify: Restart apache
+
+- name: Disable 000-default.conf
+  ansible.builtin.command: a2dissite 000-default.conf
+  notify: Restart apache
+
+- name: Enable SSL
+  ansible.builtin.command: a2ensite default-ssl
+  notify: Restart apache
+
+- name: Install kivitendo-task-server
+  ansible.builtin.copy:
+    src: files/kivitendo/kivitendo-task-server.service
+    dest: /etc/systemd/system/kivitendo-task-server.service
+    owner: root
+    mode: 'u=rw,g=rw,o='
+  notify: systemd_daemon_reload
+
+- name: Start kivitendo-task-server
+  ansible.builtin.systemd:
+    name: kivitendo-task-server
+    state: started
+    enabled: true
 
 # Anleitung adaptiert
 # https://github.com/kivitendo/kivitendo-ansible/blob/master/main.yml