Files
PyRIGS/scripts/certbot-issue.sh
Hang c1ac0065ee ci: update compose.yml for prod deployment
- Add Nginx as a reverse proxy
- Add cert-selfsign.sh for generating self-signed certificates
- Add certbot-issue.sh for Let's Encrypt certificate issuance and renewal
- Add cron-install.sh and cron-uninstall.sh for system cron management
- Add .env.example as an environment variable template
2026-08-23 23:10:30 +01:00

48 lines
1.8 KiB
Bash

#!/usr/bin/env bash
# Issue the initial certificate (run as root on the deployment server)
# Usage: sudo ./scripts/certbot-issue.sh <domain> <email>
set -euo pipefail
DOMAIN="${1:?Usage: $0 <domain> <email>}"
EMAIL="${2:?Usage: $0 <domain> <email>}"
REPO_DIR="$(cd "$(dirname "$0")/.." && pwd)"
WEBROOT="$REPO_DIR/nginx/certbot"
CERTS_DIR="$REPO_DIR/nginx/certs"
HOOK_PATH="/etc/letsencrypt/renewal-hooks/deploy/pyrigs-deploy.sh"
if ! command -v certbot >/dev/null 2>&1; then
echo "certbot not found. Install it first: apt install certbot (or snap install certbot --classic)" >&2
exit 1
fi
mkdir -p "$WEBROOT" "$CERTS_DIR" /etc/letsencrypt/renewal-hooks/deploy
# 1. Initial issuance (certbot skips if the cert already exists and is not due for renewal)
certbot certonly \
--webroot -w "$WEBROOT" \
-d "$DOMAIN" \
-m "$EMAIL" \
--agree-tos --no-eff-email --non-interactive
# 2. Install deploy-hook (placed in the official dir, triggered automatically on successful renewal)
cat > "$HOOK_PATH" <<EOF
#!/bin/sh
# Generated by scripts/certbot-issue.sh: copy renewed certs and reload nginx
set -e
cp -fL "\$RENEWED_LINEAGE/fullchain.pem" "$CERTS_DIR/fullchain.pem"
cp -fL "\$RENEWED_LINEAGE/privkey.pem" "$CERTS_DIR/privkey.pem"
chmod 600 "$CERTS_DIR/privkey.pem"
docker compose -f "$REPO_DIR/compose.yml" exec -T nginx nginx -s reload || true
echo "pyrigs deploy-hook: \$(date) renewed [\$RENEWED_DOMAINS] and reloaded nginx"
EOF
chmod +x "$HOOK_PATH"
# 3. Deploy the freshly issued certificate right away
RENEWED_LINEAGE="/etc/letsencrypt/live/$DOMAIN" \
RENEWED_DOMAINS="$DOMAIN" \
"$HOOK_PATH"
echo "Done: certificate for $DOMAIN issued and deployed to $CERTS_DIR; deploy-hook installed."
echo "Tip: for scheduled renewal, run sudo ./scripts/cron-install.sh"