--- - name: install certbot ansible.builtin.apt: name: certbot state: present update_cache: true - name: issue certificate if missing ansible.builtin.command: cmd: > certbot certonly --standalone --non-interactive --agree-tos --register-unsafely-without-email --pre-hook "{{ item.pre_hook }}" --post-hook "{{ item.post_hook }}" {{ item.domains | map('regex_replace', '^(.*)$', '-d \1') | join(' ') }} creates: "/etc/letsencrypt/live/{{ item.domains[0] }}/fullchain.pem" loop: "{{ certbot_certs }}" loop_control: label: "{{ item.domains | join(',') }}"