mirror of
https://github.com/nottinghamtec/PyRIGS.git
synced 2026-09-30 17:58:11 +00:00
- Add Nginx as a reverse proxy - Add cert-selfsign.sh for generating self-signed certificates - Add certbot-issue.sh for Let's Encrypt certificate issuance and renewal - Add cron-install.sh and cron-uninstall.sh for system cron management - Add .env.example as an environment variable template
29 lines
897 B
Bash
29 lines
897 B
Bash
#!/usr/bin/env bash
|
|
# Usage: ./scripts/cert-selfsign.sh [domain] (no root required)
|
|
set -euo pipefail
|
|
|
|
DOMAIN="${1:-localhost}"
|
|
REPO_DIR="$(cd "$(dirname "$0")/.." && pwd)"
|
|
CERTS_DIR="$REPO_DIR/nginx/certs"
|
|
|
|
mkdir -p "$CERTS_DIR"
|
|
|
|
if [ -f "$CERTS_DIR/fullchain.pem" ]; then
|
|
read -rp "$CERTS_DIR/fullchain.pem already exists, overwrite? [y/N] " ans
|
|
case "$ans" in
|
|
y|Y) ;;
|
|
*) echo "Aborted"; exit 0 ;;
|
|
esac
|
|
fi
|
|
|
|
openssl req -x509 -nodes -newkey rsa:2048 -days 30 \
|
|
-keyout "$CERTS_DIR/privkey.pem" \
|
|
-out "$CERTS_DIR/fullchain.pem" \
|
|
-subj "/CN=$DOMAIN" \
|
|
-addext "subjectAltName=DNS:$DOMAIN" \
|
|
2>/dev/null
|
|
chmod 600 "$CERTS_DIR/privkey.pem"
|
|
|
|
echo "Done: self-signed certificate (valid for 30 days) generated in $CERTS_DIR"
|
|
echo "Next: start the stack with 'docker compose up -d', then run scripts/certbot-issue.sh to switch to the real certificate"
|