diff --git a/Dockerfile b/Dockerfile index b448d17..d421634 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,10 +1,10 @@ FROM nginx:1.21.4-alpine -RUN mkdir -p /nginx +RUN mkdir -p /nginx /www_http COPY nginx-http-redir.conf /nginx/default.conf # For renewing the certificates -COPY renew_cert.sh /etc/periodic/daily/ +COPY renew_cert.sh /etc/periodic/daily/renew_cert RUN apk update && apk add certbot bind-tools diff --git a/README.md b/README.md index c8154e1..18ac2c5 100644 --- a/README.md +++ b/README.md @@ -128,6 +128,17 @@ Added support for nginx webserver, based on official nginx image - Add missing crond invocation +### 1.1.3 + +- Add missing http directory + +### 1.1.4 + +- change renew_cert.sh file name for run-parts + +### 1.1.5 + +- update renew_cert.sh for periodic renew ## Kubernetes diff --git a/nginx-http-redir.conf b/nginx-http-redir.conf index 762973d..7251e56 100644 --- a/nginx-http-redir.conf +++ b/nginx-http-redir.conf @@ -3,10 +3,10 @@ server { listen [::]:80; server_name _; - root /var/www/html/; + root /www_http; location /.well-known/acme-challenge/ { - root /var/www/html; + root /www_http; } # Everything else -> ssl diff --git a/renew_cert.sh b/renew_cert.sh index 3e64ea3..8196910 100755 --- a/renew_cert.sh +++ b/renew_cert.sh @@ -2,10 +2,11 @@ if [ "$NO_NGINX" ]; then /usr/bin/certbot renew --standalone +elif [ -n "`grep -r standalone /etc/letsencrypt/renewal`" ]; then + /usr/bin/certbot renew --standalone + /usr/bin/certbot renew --force-renew --webroot --webroot-path /www_http else - /usr/bin/certbot renew --webroot --webroot-path /var/www/html - # Reload nginx - pkill -1 nginx + /usr/bin/certbot renew --webroot --webroot-path /www_http fi # Correct permissions if not told otherwise @@ -14,4 +15,7 @@ if [ -z "$LEAVE_PERMISSIONS_AS_IS" ]; then find /etc/letsencrypt -type f -exec chmod 0644 {} \; fi -echo "Last renew: $(date)" > /tmp/last_renew +# Reload certs +pkill -1 nginx + +echo "Last renew: $(date)" > /tmp/last_renew \ No newline at end of file