mirror of
https://github.com/nottinghamtec/PyRIGS.git
synced 2026-10-01 10:18:41 +00:00
ci: update compose.yml for prod deployment
- Add Nginx as a reverse proxy - Add cert-selfsign.sh for generating self-signed certificates - Add certbot-issue.sh for Let's Encrypt certificate issuance and renewal - Add cron-install.sh and cron-uninstall.sh for system cron management - Add .env.example as an environment variable template
This commit is contained in:
47
scripts/certbot-issue.sh
Normal file
47
scripts/certbot-issue.sh
Normal file
@@ -0,0 +1,47 @@
|
||||
#!/usr/bin/env bash
|
||||
# Issue the initial certificate (run as root on the deployment server)
|
||||
# Usage: sudo ./scripts/certbot-issue.sh <domain> <email>
|
||||
set -euo pipefail
|
||||
|
||||
DOMAIN="${1:?Usage: $0 <domain> <email>}"
|
||||
EMAIL="${2:?Usage: $0 <domain> <email>}"
|
||||
|
||||
REPO_DIR="$(cd "$(dirname "$0")/.." && pwd)"
|
||||
WEBROOT="$REPO_DIR/nginx/certbot"
|
||||
CERTS_DIR="$REPO_DIR/nginx/certs"
|
||||
HOOK_PATH="/etc/letsencrypt/renewal-hooks/deploy/pyrigs-deploy.sh"
|
||||
|
||||
if ! command -v certbot >/dev/null 2>&1; then
|
||||
echo "certbot not found. Install it first: apt install certbot (or snap install certbot --classic)" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
mkdir -p "$WEBROOT" "$CERTS_DIR" /etc/letsencrypt/renewal-hooks/deploy
|
||||
|
||||
# 1. Initial issuance (certbot skips if the cert already exists and is not due for renewal)
|
||||
certbot certonly \
|
||||
--webroot -w "$WEBROOT" \
|
||||
-d "$DOMAIN" \
|
||||
-m "$EMAIL" \
|
||||
--agree-tos --no-eff-email --non-interactive
|
||||
|
||||
# 2. Install deploy-hook (placed in the official dir, triggered automatically on successful renewal)
|
||||
cat > "$HOOK_PATH" <<EOF
|
||||
#!/bin/sh
|
||||
# Generated by scripts/certbot-issue.sh: copy renewed certs and reload nginx
|
||||
set -e
|
||||
cp -fL "\$RENEWED_LINEAGE/fullchain.pem" "$CERTS_DIR/fullchain.pem"
|
||||
cp -fL "\$RENEWED_LINEAGE/privkey.pem" "$CERTS_DIR/privkey.pem"
|
||||
chmod 600 "$CERTS_DIR/privkey.pem"
|
||||
docker compose -f "$REPO_DIR/compose.yml" exec -T nginx nginx -s reload || true
|
||||
echo "pyrigs deploy-hook: \$(date) renewed [\$RENEWED_DOMAINS] and reloaded nginx"
|
||||
EOF
|
||||
chmod +x "$HOOK_PATH"
|
||||
|
||||
# 3. Deploy the freshly issued certificate right away
|
||||
RENEWED_LINEAGE="/etc/letsencrypt/live/$DOMAIN" \
|
||||
RENEWED_DOMAINS="$DOMAIN" \
|
||||
"$HOOK_PATH"
|
||||
|
||||
echo "Done: certificate for $DOMAIN issued and deployed to $CERTS_DIR; deploy-hook installed."
|
||||
echo "Tip: for scheduled renewal, run sudo ./scripts/cron-install.sh"
|
||||
Reference in New Issue
Block a user