mirror of
https://github.com/nottinghamtec/PyRIGS.git
synced 2026-09-30 17:58:11 +00:00
- Add Nginx as a reverse proxy - Add cert-selfsign.sh for generating self-signed certificates - Add certbot-issue.sh for Let's Encrypt certificate issuance and renewal - Add cron-install.sh and cron-uninstall.sh for system cron management - Add .env.example as an environment variable template
48 lines
1.8 KiB
Bash
48 lines
1.8 KiB
Bash
#!/usr/bin/env bash
|
|
# Issue the initial certificate (run as root on the deployment server)
|
|
# Usage: sudo ./scripts/certbot-issue.sh <domain> <email>
|
|
set -euo pipefail
|
|
|
|
DOMAIN="${1:?Usage: $0 <domain> <email>}"
|
|
EMAIL="${2:?Usage: $0 <domain> <email>}"
|
|
|
|
REPO_DIR="$(cd "$(dirname "$0")/.." && pwd)"
|
|
WEBROOT="$REPO_DIR/nginx/certbot"
|
|
CERTS_DIR="$REPO_DIR/nginx/certs"
|
|
HOOK_PATH="/etc/letsencrypt/renewal-hooks/deploy/pyrigs-deploy.sh"
|
|
|
|
if ! command -v certbot >/dev/null 2>&1; then
|
|
echo "certbot not found. Install it first: apt install certbot (or snap install certbot --classic)" >&2
|
|
exit 1
|
|
fi
|
|
|
|
mkdir -p "$WEBROOT" "$CERTS_DIR" /etc/letsencrypt/renewal-hooks/deploy
|
|
|
|
# 1. Initial issuance (certbot skips if the cert already exists and is not due for renewal)
|
|
certbot certonly \
|
|
--webroot -w "$WEBROOT" \
|
|
-d "$DOMAIN" \
|
|
-m "$EMAIL" \
|
|
--agree-tos --no-eff-email --non-interactive
|
|
|
|
# 2. Install deploy-hook (placed in the official dir, triggered automatically on successful renewal)
|
|
cat > "$HOOK_PATH" <<EOF
|
|
#!/bin/sh
|
|
# Generated by scripts/certbot-issue.sh: copy renewed certs and reload nginx
|
|
set -e
|
|
cp -fL "\$RENEWED_LINEAGE/fullchain.pem" "$CERTS_DIR/fullchain.pem"
|
|
cp -fL "\$RENEWED_LINEAGE/privkey.pem" "$CERTS_DIR/privkey.pem"
|
|
chmod 600 "$CERTS_DIR/privkey.pem"
|
|
docker compose -f "$REPO_DIR/compose.yml" exec -T nginx nginx -s reload || true
|
|
echo "pyrigs deploy-hook: \$(date) renewed [\$RENEWED_DOMAINS] and reloaded nginx"
|
|
EOF
|
|
chmod +x "$HOOK_PATH"
|
|
|
|
# 3. Deploy the freshly issued certificate right away
|
|
RENEWED_LINEAGE="/etc/letsencrypt/live/$DOMAIN" \
|
|
RENEWED_DOMAINS="$DOMAIN" \
|
|
"$HOOK_PATH"
|
|
|
|
echo "Done: certificate for $DOMAIN issued and deployed to $CERTS_DIR; deploy-hook installed."
|
|
echo "Tip: for scheduled renewal, run sudo ./scripts/cron-install.sh"
|