---
- name: Copy old certs to the kubeadm expected path
  copy:
    src: "{{ kube_cert_dir }}/{{ item.src }}"
    dest: "{{ kube_cert_dir }}/{{ item.dest }}"
    mode: 0640
    remote_src: yes
  with_items:
    - {src: apiserver.pem, dest: apiserver.crt}
    - {src: apiserver-key.pem, dest: apiserver.key}
    - {src: ca.pem, dest: ca.crt}
    - {src: ca-key.pem, dest: ca.key}
    - {src: front-proxy-ca.pem, dest: front-proxy-ca.crt}
    - {src: front-proxy-ca-key.pem, dest: front-proxy-ca.key}
    - {src: front-proxy-client.pem, dest: front-proxy-client.crt}
    - {src: front-proxy-client-key.pem, dest: front-proxy-client.key}
    - {src: service-account-key.pem, dest: sa.pub}
    - {src: service-account-key.pem, dest: sa.key}
    - {src: "node-{{ inventory_hostname }}.pem", dest: apiserver-kubelet-client.crt}
    - {src: "node-{{ inventory_hostname }}-key.pem", dest: apiserver-kubelet-client.key}
  register: kubeadm_copy_old_certs