<feed xmlns='http://www.w3.org/2005/Atom'>
<title>luke/ansible-roles/certbot-dns-cloudflare/templates, branch main</title>
<subtitle>Ansible roles for nth.io infrastructure
</subtitle>
<id>https://src.nth.io/luke/ansible-roles/atom?h=main</id>
<link rel='self' href='https://src.nth.io/luke/ansible-roles/atom?h=main'/>
<link rel='alternate' type='text/html' href='https://src.nth.io/luke/ansible-roles/'/>
<updated>2026-06-30T02:13:59+00:00</updated>
<entry>
<title>certbot: scoped CF API token; gate prosody deploy hook on RENEWED_LINEAGE</title>
<updated>2026-06-30T02:13:59+00:00</updated>
<author>
<name>Luke Hoersten</name>
<email>luke@hoersten.org</email>
</author>
<published>2026-06-30T02:13:59+00:00</published>
<link rel='alternate' type='text/html' href='https://src.nth.io/luke/ansible-roles/commit/?id=b15bc8b162e9aacd12c7882ddb3c8cc3ca82189b'/>
<id>urn:sha1:b15bc8b162e9aacd12c7882ddb3c8cc3ca82189b</id>
<content type='text'>
cred.conf.j2 now emits the single-line dns_cloudflare_api_token form (scoped
Cloudflare API Token) instead of the legacy account-wide email + global API key.

prosody.sh.j2 deploy hook now no-ops unless $RENEWED_LINEAGE matches the prosody
vhost, so unrelated lineage renewals (haskell.social, etracapital.com) no longer
report a spurious "Hook reported error code 1 / No certificate for host found".

Co-Authored-By: Claude Opus 4.8 (1M context) &lt;noreply@anthropic.com&gt;
</content>
</entry>
<entry>
<title>More cert fixes.</title>
<updated>2025-05-30T02:34:48+00:00</updated>
<author>
<name>Luke Hoersten</name>
<email>luke@hoersten.org</email>
</author>
<published>2025-05-30T02:34:48+00:00</published>
<link rel='alternate' type='text/html' href='https://src.nth.io/luke/ansible-roles/commit/?id=aa78f093b6d298df46b2b39c62f6bec953bea248'/>
<id>urn:sha1:aa78f093b6d298df46b2b39c62f6bec953bea248</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Added certbot dns cloudflare role. Useful for when ISP blocks port 80.</title>
<updated>2020-08-15T22:54:09+00:00</updated>
<author>
<name>Luke Hoersten</name>
<email>luke@hoersten.org</email>
</author>
<published>2020-08-15T22:54:09+00:00</published>
<link rel='alternate' type='text/html' href='https://src.nth.io/luke/ansible-roles/commit/?id=33b5c0fd837f13873dffc8ecb2cc91920bac3ef9'/>
<id>urn:sha1:33b5c0fd837f13873dffc8ecb2cc91920bac3ef9</id>
<content type='text'>
</content>
</entry>
</feed>
