Compare commits

..

6 commits

Author SHA1 Message Date
kjg
a6af2b5f55 [ungleich-certbot] update renew_cert.sh for Task#13204 2024-10-08 08:23:37 +00:00
kjg
217b8c2e95 [ungleich-certbot] update renew_cert.sh for Task#12236 2024-04-23 20:26:46 +09:00
837887a66c update file name for run-parts 2022-07-06 20:55:28 +09:00
kjg
3ae07d4598 [k8s] update Dockerfile for Task#10707 2022-07-06 11:44:22 +00:00
Nico Schottelius
2c03ff46f0 Version update in docs 2022-01-30 21:23:05 +01:00
Nico Schottelius
43672378fb Create directory for certbot / http based root 2022-01-30 21:22:18 +01:00
4 changed files with 23 additions and 8 deletions

View file

@ -1,10 +1,10 @@
FROM nginx:1.21.4-alpine FROM nginx:1.21.4-alpine
RUN mkdir -p /nginx RUN mkdir -p /nginx /www_http
COPY nginx-http-redir.conf /nginx/default.conf COPY nginx-http-redir.conf /nginx/default.conf
# For renewing the certificates # For renewing the certificates
COPY renew_cert.sh /etc/periodic/daily/ COPY renew_cert.sh /etc/periodic/daily/renew_cert
RUN apk update && apk add certbot bind-tools RUN apk update && apk add certbot bind-tools

View file

@ -128,6 +128,17 @@ Added support for nginx webserver, based on official nginx image
- Add missing crond invocation - Add missing crond invocation
### 1.1.3
- Add missing http directory
### 1.1.4
- change renew_cert.sh file name for run-parts
### 1.1.5
- update renew_cert.sh for periodic renew
## Kubernetes ## Kubernetes

View file

@ -3,10 +3,10 @@ server {
listen [::]:80; listen [::]:80;
server_name _; server_name _;
root /var/www/html/; root /www_http;
location /.well-known/acme-challenge/ { location /.well-known/acme-challenge/ {
root /var/www/html; root /www_http;
} }
# Everything else -> ssl # Everything else -> ssl

View file

@ -2,10 +2,11 @@
if [ "$NO_NGINX" ]; then if [ "$NO_NGINX" ]; then
/usr/bin/certbot renew --standalone /usr/bin/certbot renew --standalone
elif [ -n "`grep -r standalone /etc/letsencrypt/renewal`" ]; then
/usr/bin/certbot renew --standalone
/usr/bin/certbot renew --force-renew --webroot --webroot-path /www_http
else else
/usr/bin/certbot renew --webroot --webroot-path /var/www/html /usr/bin/certbot renew --webroot --webroot-path /www_http
# Reload nginx
pkill -1 nginx
fi fi
# Correct permissions if not told otherwise # Correct permissions if not told otherwise
@ -14,4 +15,7 @@ if [ -z "$LEAVE_PERMISSIONS_AS_IS" ]; then
find /etc/letsencrypt -type f -exec chmod 0644 {} \; find /etc/letsencrypt -type f -exec chmod 0644 {} \;
fi fi
# Reload certs
pkill -1 nginx
echo "Last renew: $(date)" > /tmp/last_renew echo "Last renew: $(date)" > /tmp/last_renew