Files
NagyZoltanPeter d3c0979dd5 chore(docker): rename compose folder and fix review follow-ups from #4057 (#4129)
Follow-up to the review of #4057.

- Rename apps/logos_delivery_node/compose -> apps/logos_delivery_node/docker
  (review request); the only path reference was in the folder's own README.
- run_certbot.sh: pass the configured EMAIL to certbot instead of the
  hardcoded admin@$DOMAIN, and forward EMAIL to the certbot container so
  setting it in .env takes effect. Empty still falls back to admin@$DOMAIN.
- set_storage_retention.sh: `grep -c` always prints a count, so the old
  sudo test was always true and sudo was used whenever ./postgresql existed.
  Test readability of the data directory directly instead.
- chkhealth.sh: drop the stray `GET` argument, which curl treated as an
  extra (failing) URL.
- docker-compose.yml: put certbot behind the `wss` profile so it no longer
  publishes host port 80 on deployments that do not use WebSocket-Secure,
  and drop the node's meaningless `depends_on: certbot` (run_node.sh polls
  for the certificate on disk anyway).
2026-08-18 18:03:04 +02:00

61 lines
1.6 KiB
Bash
Executable File

#!/bin/sh
set -e
if [ -z "$DOMAIN" ]; then
echo "DOMAIN not set, skipping certbot"
exit 0
fi
# -------------------------------
# Configuration
# -------------------------------
EMAIL="${EMAIL:-admin@${DOMAIN}}" # Certbot email
WEBROOT="${WEBROOT:-/var/www/certbot}" # Path served by HTTP for ACME
SLEEP_INTERVAL="${SLEEP_INTERVAL:-12h}" # Renewal check interval
# Ensure webroot directory exists
mkdir -p "${WEBROOT}/.well-known/acme-challenge"
# Path to cert folder
LETSENCRYPT_PATH="/etc/letsencrypt/live/${DOMAIN}"
# -------------------------------
# Initial certificate issuance
# -------------------------------
if [ ! -d "${LETSENCRYPT_PATH}" ]; then
echo "[INFO] No certificate found for ${DOMAIN}, issuing a new one..."
# Install certbot if needed (Alpine example)
if ! command -v certbot >/dev/null 2>&1; then
echo "[INFO] Installing certbot..."
apk add --no-cache certbot
fi
certbot certonly\
--non-interactive\
--agree-tos\
--no-eff-email\
--no-redirect\
--email "${EMAIL}"\
-d ${DOMAIN}\
--standalone
echo "[INFO] Certificate issued successfully."
else
echo "[INFO] Certificate already exists for ${DOMAIN}."
fi
# -------------------------------
# Renewal loop
# -------------------------------
echo "[INFO] Starting renewal loop every ${SLEEP_INTERVAL}..."
while true; do
echo "[INFO] Checking certificate renewal..."
certbot renew --standalone --quiet
# certbot renew --standalone ## Use this line instead to debug the output
echo "[INFO] Renewal check complete. Sleeping..."
sleep "${SLEEP_INTERVAL}"
done