ansible-zero-trust/roles/ssh_step/tasks/ca-bootstrap-host-trust.yml
2025-11-18 22:23:34 -06:00

12 lines
433 B
YAML

# SPDX-License-Identifier: AGPL-3.0-or-later
# SPDX-FileCopyrightText: 2025 Dosh LLC
---
- name: Bootstrap Host into CA
become: true
ansible.builtin.shell: |
STEPPATH={{ STEP_PATH }} {{ STEP_BIN_ABSOLUTE_PATH }} ca bootstrap \
--ca-url {{ STEP_BOOTSTRAP_URL }} \
--fingerprint {{ STEP_BOOTSTRAP_FINGERPRINT }} \
{% if STEP_BOOTSTRAP_HOST_INSTALL %}--install{% endif %} \
--force
changed_when: false