#!/usr/bin/env bash # Issue the initial certificate (run as root on the deployment server) # Usage: sudo ./scripts/certbot-issue.sh set -euo pipefail DOMAIN="${1:?Usage: $0 }" EMAIL="${2:?Usage: $0 }" REPO_DIR="$(cd "$(dirname "$0")/.." && pwd)" WEBROOT="$REPO_DIR/nginx/certbot" CERTS_DIR="$REPO_DIR/nginx/certs" HOOK_PATH="/etc/letsencrypt/renewal-hooks/deploy/pyrigs-deploy.sh" if ! command -v certbot >/dev/null 2>&1; then echo "certbot not found. Install it first: apt install certbot (or snap install certbot --classic)" >&2 exit 1 fi mkdir -p "$WEBROOT" "$CERTS_DIR" /etc/letsencrypt/renewal-hooks/deploy # 1. Initial issuance (certbot skips if the cert already exists and is not due for renewal) certbot certonly \ --webroot -w "$WEBROOT" \ -d "$DOMAIN" \ -m "$EMAIL" \ --agree-tos --no-eff-email --non-interactive # 2. Install deploy-hook (placed in the official dir, triggered automatically on successful renewal) cat > "$HOOK_PATH" <