2026-06-24 20:17:46 -04:00
|
|
|
# Gere par Set-OPS (role client_pki). Renouvellement de certificat (Smallstep).
|
|
|
|
|
[Unit]
|
|
|
|
|
Description=Certificate renewer for %I
|
|
|
|
|
After=network-online.target
|
|
|
|
|
Wants=network-online.target
|
|
|
|
|
Documentation=https://smallstep.com/docs/step-ca/renewal
|
|
|
|
|
StartLimitIntervalSec=0
|
|
|
|
|
|
|
|
|
|
[Service]
|
|
|
|
|
Type=oneshot
|
|
|
|
|
User=root
|
|
|
|
|
Environment=STEPPATH={{ client_pki_steppath }}
|
|
|
|
|
Environment=CERT_LOCATION={{ client_pki_steppath }}/certs/%i.crt
|
|
|
|
|
Environment=KEY_LOCATION={{ client_pki_steppath }}/certs/%i.key
|
|
|
|
|
ExecCondition=/usr/bin/step certificate needs-renewal ${CERT_LOCATION}
|
|
|
|
|
ExecStart=/usr/bin/step ca renew --force ${CERT_LOCATION} ${KEY_LOCATION}
|
2026-07-04 17:18:13 -04:00
|
|
|
{% if client_pki_reload_services | default([]) | length > 0 %}
|
|
|
|
|
# Recharge les VRAIS consommateurs du cert (nginx, postfix…), pas un service nomme d'apres le cert.
|
|
|
|
|
ExecStartPost=/usr/bin/env sh -c "{% for svc in client_pki_reload_services %}systemctl try-reload-or-restart {{ svc }}; {% endfor %}true"
|
|
|
|
|
{% else %}
|
2026-06-24 20:17:46 -04:00
|
|
|
ExecStartPost=/usr/bin/env sh -c "! systemctl --quiet is-active %i.service || systemctl try-reload-or-restart %i"
|
2026-07-04 17:18:13 -04:00
|
|
|
{% endif %}
|
2026-06-24 20:17:46 -04:00
|
|
|
|
|
|
|
|
[Install]
|
|
|
|
|
WantedBy=multi-user.target
|