9a950524eb
- deploy.sh: add cert-<domain> command for zero-downtime SSL issuance - new-app.sh: SSH as deploy user with key from Bitwarden instead of personal user - remove DEPLOY_USER/DEPLOY_HOST env var requirements - update all docs to reflect new flow
58 lines
1.4 KiB
Bash
Executable File
58 lines
1.4 KiB
Bash
Executable File
#!/bin/bash
|
|
set -euo pipefail
|
|
|
|
CMD="${SSH_ORIGINAL_COMMAND:-${1:-}}"
|
|
|
|
if [[ "$CMD" =~ ^cert-[a-zA-Z0-9._-]+$ ]]; then
|
|
APP="${CMD#cert-}"
|
|
|
|
# Write temporary HTTP-only config so nginx can serve ACME challenges
|
|
cat > "/opt/hantim/docker/nginx/conf.d/$APP.conf" <<NGINXCONF
|
|
server {
|
|
listen 80;
|
|
listen [::]:80;
|
|
server_name $APP www.$APP;
|
|
|
|
location /.well-known/acme-challenge/ {
|
|
root /var/www/certbot;
|
|
}
|
|
|
|
location / {
|
|
return 444;
|
|
}
|
|
}
|
|
NGINXCONF
|
|
|
|
docker exec nginx nginx -t && docker exec nginx nginx -s reload
|
|
certbot certonly --webroot -w /opt/hantim/docker/nginx/certbot/www \
|
|
--non-interactive --agree-tos --register-unsafely-without-email \
|
|
--cert-name "$APP" -d "$APP" -d "www.$APP"
|
|
echo "Certificate issued for $APP"
|
|
exit 0
|
|
fi
|
|
|
|
if ! [[ "$CMD" =~ ^deploy-[a-zA-Z0-9._-]+$ ]]; then
|
|
echo "Unknown command: $CMD"
|
|
exit 1
|
|
fi
|
|
|
|
APP="${CMD#deploy-}"
|
|
cd /opt/hantim
|
|
git pull
|
|
cd "docker/$APP"
|
|
if ! docker compose pull; then
|
|
echo "Image not yet available for $APP — skipping. It will deploy when the app repo is first pushed."
|
|
exit 0
|
|
fi
|
|
|
|
if [ "$APP" = "nginx" ]; then
|
|
# Test config before applying — a bad config (e.g. missing cert) would take down all sites
|
|
docker compose run --rm -T nginx nginx -t
|
|
fi
|
|
|
|
docker compose up -d
|
|
|
|
if [ "$APP" = "nginx" ]; then
|
|
docker exec nginx nginx -s reload
|
|
fi
|