#!/bin/env bash # run this script daily to renew any letsencrypt certs that need renewing # renew cert if it expires within 30 days export LEGO_SERVER="{{ lego_acme_server }}/directory" export LEGO_PATH="{{ __lego_base_dir }}/.lego" export CLOUDFLARE_DNS_API_TOKEN="{{ lego_cloudflare_api_token }}" {% for cert in lego_certificates %} echo "$(date) checking for cert update for {{ ', '.join(cert.domains) }}." {{ __lego_bin_file }} --email="{{ lego_acme_account_email }}" --domains {{ ' --domains '.join(cert.domains) }} --key-type="{{ lego_key_type }}" --dns="cloudflare" renew {{ '--run-hook="hook-{{ item.name }}.sh"' if item.hook is defined else '' }} --days 30 {% endfor %}