# Gere par Set-OPS (role client_pki). Renouvellement de certificat (Smallstep). [Unit] Description=Certificate renewer for %I After=network-online.target Wants=network-online.target Documentation=https://smallstep.com/docs/step-ca/renewal StartLimitIntervalSec=0 [Service] Type=oneshot User=root Environment=STEPPATH={{ client_pki_steppath }} Environment=CERT_LOCATION={{ client_pki_steppath }}/certs/%i.crt Environment=KEY_LOCATION={{ client_pki_steppath }}/certs/%i.key ExecCondition=/usr/bin/step certificate needs-renewal ${CERT_LOCATION} ExecStart=/usr/bin/step ca renew --force ${CERT_LOCATION} ${KEY_LOCATION} {% if client_pki_reload_services | default([]) | length > 0 %} # Recharge les VRAIS consommateurs du cert (nginx, postfix…), pas un service nomme d'apres le cert. ExecStartPost=/usr/bin/env sh -c "{% for svc in client_pki_reload_services %}systemctl try-reload-or-restart {{ svc }}; {% endfor %}true" {% else %} ExecStartPost=/usr/bin/env sh -c "! systemctl --quiet is-active %i.service || systemctl try-reload-or-restart %i" {% endif %} [Install] WantedBy=multi-user.target