From 43672378fb9dab1c591bfe668a8f27ea27729490 Mon Sep 17 00:00:00 2001 From: Nico Schottelius Date: Sun, 30 Jan 2022 21:22:18 +0100 Subject: [PATCH 1/6] Create directory for certbot / http based root --- Dockerfile | 2 +- nginx-http-redir.conf | 4 ++-- renew_cert.sh | 8 +++++--- 3 files changed, 8 insertions(+), 6 deletions(-) diff --git a/Dockerfile b/Dockerfile index b448d17..5e662be 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,6 +1,6 @@ FROM nginx:1.21.4-alpine -RUN mkdir -p /nginx +RUN mkdir -p /nginx /www_http COPY nginx-http-redir.conf /nginx/default.conf # For renewing the certificates diff --git a/nginx-http-redir.conf b/nginx-http-redir.conf index 762973d..7251e56 100644 --- a/nginx-http-redir.conf +++ b/nginx-http-redir.conf @@ -3,10 +3,10 @@ server { listen [::]:80; server_name _; - root /var/www/html/; + root /www_http; location /.well-known/acme-challenge/ { - root /var/www/html; + root /www_http; } # Everything else -> ssl diff --git a/renew_cert.sh b/renew_cert.sh index 3e64ea3..d7e6148 100755 --- a/renew_cert.sh +++ b/renew_cert.sh @@ -3,9 +3,8 @@ if [ "$NO_NGINX" ]; then /usr/bin/certbot renew --standalone else - /usr/bin/certbot renew --webroot --webroot-path /var/www/html - # Reload nginx - pkill -1 nginx + /usr/bin/certbot renew --webroot --webroot-path /www_http + fi # Correct permissions if not told otherwise @@ -14,4 +13,7 @@ if [ -z "$LEAVE_PERMISSIONS_AS_IS" ]; then find /etc/letsencrypt -type f -exec chmod 0644 {} \; fi +# Reload certs +pkill -1 nginx + echo "Last renew: $(date)" > /tmp/last_renew From 2c03ff46f0d778bd5f984016e4b0b8b520040b68 Mon Sep 17 00:00:00 2001 From: Nico Schottelius Date: Sun, 30 Jan 2022 21:23:05 +0100 Subject: [PATCH 2/6] Version update in docs --- README.md | 3 +++ 1 file changed, 3 insertions(+) diff --git a/README.md b/README.md index c8154e1..6624212 100644 --- a/README.md +++ b/README.md @@ -128,6 +128,9 @@ Added support for nginx webserver, based on official nginx image - Add missing crond invocation +### 1.1.3 + +- Add missing http directory ## Kubernetes From 3ae07d45985c003b44a63921c44a91d71206390a Mon Sep 17 00:00:00 2001 From: kjg Date: Wed, 6 Jul 2022 11:44:22 +0000 Subject: [PATCH 3/6] [k8s] update Dockerfile for Task#10707 --- Dockerfile | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Dockerfile b/Dockerfile index 5e662be..d421634 100644 --- a/Dockerfile +++ b/Dockerfile @@ -4,7 +4,7 @@ RUN mkdir -p /nginx /www_http COPY nginx-http-redir.conf /nginx/default.conf # For renewing the certificates -COPY renew_cert.sh /etc/periodic/daily/ +COPY renew_cert.sh /etc/periodic/daily/renew_cert RUN apk update && apk add certbot bind-tools From 837887a66c8988275ef6b505a9739e6020dcda86 Mon Sep 17 00:00:00 2001 From: "jinguk.kwon" Date: Wed, 6 Jul 2022 20:55:28 +0900 Subject: [PATCH 4/6] update file name for run-parts --- README.md | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/README.md b/README.md index 6624212..d06044d 100644 --- a/README.md +++ b/README.md @@ -132,6 +132,10 @@ Added support for nginx webserver, based on official nginx image - Add missing http directory +### 1.1.4 + +- change renew_cert.sh file name for run-parts + ## Kubernetes See https://code.ungleich.ch/ungleich-public/ungleich-k8s/. From 217b8c2e95de73c2145d80e9f0e087acf62bb28b Mon Sep 17 00:00:00 2001 From: kjg Date: Tue, 23 Apr 2024 20:26:46 +0900 Subject: [PATCH 5/6] [ungleich-certbot] update renew_cert.sh for Task#12236 --- README.md | 4 ++++ renew_cert.sh | 3 ++- 2 files changed, 6 insertions(+), 1 deletion(-) diff --git a/README.md b/README.md index d06044d..18ac2c5 100644 --- a/README.md +++ b/README.md @@ -136,6 +136,10 @@ Added support for nginx webserver, based on official nginx image - change renew_cert.sh file name for run-parts +### 1.1.5 + +- update renew_cert.sh for periodic renew + ## Kubernetes See https://code.ungleich.ch/ungleich-public/ungleich-k8s/. diff --git a/renew_cert.sh b/renew_cert.sh index d7e6148..a9e079e 100755 --- a/renew_cert.sh +++ b/renew_cert.sh @@ -2,9 +2,10 @@ if [ "$NO_NGINX" ]; then /usr/bin/certbot renew --standalone +elif [ -n "`grep -r standalone /etc/letsencrypt/renewal`" ]; then + /usr/bin/certbot renew --force-renew --webroot --webroot-path /www_http else /usr/bin/certbot renew --webroot --webroot-path /www_http - fi # Correct permissions if not told otherwise From a6af2b5f55af43a5466c343da9f58848ba2ef0ea Mon Sep 17 00:00:00 2001 From: kjg Date: Tue, 8 Oct 2024 08:23:37 +0000 Subject: [PATCH 6/6] [ungleich-certbot] update renew_cert.sh for Task#13204 --- renew_cert.sh | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/renew_cert.sh b/renew_cert.sh index a9e079e..8196910 100755 --- a/renew_cert.sh +++ b/renew_cert.sh @@ -3,6 +3,7 @@ if [ "$NO_NGINX" ]; then /usr/bin/certbot renew --standalone elif [ -n "`grep -r standalone /etc/letsencrypt/renewal`" ]; then + /usr/bin/certbot renew --standalone /usr/bin/certbot renew --force-renew --webroot --webroot-path /www_http else /usr/bin/certbot renew --webroot --webroot-path /www_http @@ -17,4 +18,4 @@ fi # Reload certs pkill -1 nginx -echo "Last renew: $(date)" > /tmp/last_renew +echo "Last renew: $(date)" > /tmp/last_renew \ No newline at end of file