Use the templates below to write your  pre- and post-issuance playbooks.

Pre-issuance playbook templates

See below for templates of pre-issuance playbooks that: 

  • Generate the key pair and CSR on the target host
  • Register the CSR into the configured variable.

To publish a different certificate on each host (default per-host mode).

- name: Generate CSR
...
register: csr_result
 
- name: Set csr_pem fact
ansible.builtin.set_fact:
csr_pem: "{{ csr_result.stdout }}"

To publish the same certificate on all hosts (shared mode).

- name: Generate CSR (shared — run_once)
...
register: csr_result
run_once: true
 
- name: Set csr_pem fact
ansible.builtin.set_fact:
csr_pem: "{{ csr_result.stdout }}"
run_once: true

Post-issuance playbook templates

The following is the template for a post-issuance playbook that receives, imports, and deploys the certificate.

Use block: or always: for cleanup.

tasks:
- block:
# Fires only when the Bulk Destination does NOT have a cert file path configured
- name: Deploy certificate from variable
ansible.builtin.copy:
content: "{{ cert_pem }}"
dest: "{{ cert_file }}"
when: cert_pem is defined and cert_pem | length > 0
 
- name: Import / bind / reload
...
 
- name: Verify
...
 
always:
- name: Clean up temporary files
ansible.builtin.file:
path: "{{ temp_dir }}"
state: absent