mirror of
https://github.com/logos-messaging/logos-messaging-nim.git
synced 2026-08-25 23:41:06 +00:00
Follow-up to the review of #4057. - Rename apps/logos_delivery_node/compose -> apps/logos_delivery_node/docker (review request); the only path reference was in the folder's own README. - run_certbot.sh: pass the configured EMAIL to certbot instead of the hardcoded admin@$DOMAIN, and forward EMAIL to the certbot container so setting it in .env takes effect. Empty still falls back to admin@$DOMAIN. - set_storage_retention.sh: `grep -c` always prints a count, so the old sudo test was always true and sudo was used whenever ./postgresql existed. Test readability of the data directory directly instead. - chkhealth.sh: drop the stray `GET` argument, which curl treated as an extra (failing) URL. - docker-compose.yml: put certbot behind the `wss` profile so it no longer publishes host port 80 on deployments that do not use WebSocket-Secure, and drop the node's meaningless `depends_on: certbot` (run_node.sh polls for the certificate on disk anyway).
61 lines
1.6 KiB
Bash
Executable File
61 lines
1.6 KiB
Bash
Executable File
#!/bin/sh
|
|
set -e
|
|
|
|
if [ -z "$DOMAIN" ]; then
|
|
echo "DOMAIN not set, skipping certbot"
|
|
exit 0
|
|
fi
|
|
|
|
# -------------------------------
|
|
# Configuration
|
|
# -------------------------------
|
|
EMAIL="${EMAIL:-admin@${DOMAIN}}" # Certbot email
|
|
WEBROOT="${WEBROOT:-/var/www/certbot}" # Path served by HTTP for ACME
|
|
SLEEP_INTERVAL="${SLEEP_INTERVAL:-12h}" # Renewal check interval
|
|
|
|
# Ensure webroot directory exists
|
|
mkdir -p "${WEBROOT}/.well-known/acme-challenge"
|
|
|
|
# Path to cert folder
|
|
LETSENCRYPT_PATH="/etc/letsencrypt/live/${DOMAIN}"
|
|
|
|
# -------------------------------
|
|
# Initial certificate issuance
|
|
# -------------------------------
|
|
if [ ! -d "${LETSENCRYPT_PATH}" ]; then
|
|
echo "[INFO] No certificate found for ${DOMAIN}, issuing a new one..."
|
|
|
|
# Install certbot if needed (Alpine example)
|
|
if ! command -v certbot >/dev/null 2>&1; then
|
|
echo "[INFO] Installing certbot..."
|
|
apk add --no-cache certbot
|
|
fi
|
|
|
|
certbot certonly\
|
|
--non-interactive\
|
|
--agree-tos\
|
|
--no-eff-email\
|
|
--no-redirect\
|
|
--email "${EMAIL}"\
|
|
-d ${DOMAIN}\
|
|
--standalone
|
|
|
|
echo "[INFO] Certificate issued successfully."
|
|
else
|
|
echo "[INFO] Certificate already exists for ${DOMAIN}."
|
|
fi
|
|
|
|
# -------------------------------
|
|
# Renewal loop
|
|
# -------------------------------
|
|
echo "[INFO] Starting renewal loop every ${SLEEP_INTERVAL}..."
|
|
while true; do
|
|
echo "[INFO] Checking certificate renewal..."
|
|
certbot renew --standalone --quiet
|
|
# certbot renew --standalone ## Use this line instead to debug the output
|
|
echo "[INFO] Renewal check complete. Sleeping..."
|
|
sleep "${SLEEP_INTERVAL}"
|
|
done
|
|
|
|
|