diff --git a/tasks/node-certs.yml b/tasks/node-certs.yml index 3c3e92bc47722b523e643de2c7b9c11f942b8997..7243af9b515aa06b6de7e63112291f3eeac5e8b0 100644 --- a/tasks/node-certs.yml +++ b/tasks/node-certs.yml @@ -55,18 +55,17 @@ ownca_not_after: "+{{ cert_valid_days }}d" ownca_not_before: "-1d" # valid since yesterday -- name: Node Certificates | Copy Certificates - block: - - name: Node Certificates | Copy Node certificates - ansible.builtin.copy: - src: "{{ tmp_cert_dir }}/{{ item.file }}" - dest: "{{ sidecar_cert_dir }}" - mode: "{{ item.mode }}" - with_items: - - { file: "sidecar-{{ inventory_hostname }}.key", mode: "0600" } - - { file: "sidecar-{{ inventory_hostname }}.pem", mode: "0644" } - - { file: "sidecar-ca.pem", mode: "0644" } - - { file: "graylog-ca.pem", mode: "0644" } +- name: Node Certificates | Copy Node certificates + ansible.builtin.copy: + src: "{{ tmp_cert_dir }}/{{ item.file }}" + dest: "{{ sidecar_cert_dir }}" + mode: "{{ item.mode }}" + with_items: + - { file: "sidecar-{{ inventory_hostname }}.key", mode: "0600" } + - { file: "sidecar-{{ inventory_hostname }}.pem", mode: "0644" } + - { file: "sidecar-ca.pem", mode: "0644" } + - { file: "graylog-ca.pem", mode: "0644" } + become: true - name: Node Certificates | Cleanup tmp directory ansible.builtin.file: