From 8d9122dc771a90b7545b0198bcc459dedf1b4685 Mon Sep 17 00:00:00 2001 From: Akshay Nair Date: Mon, 31 Jul 2023 23:02:24 +0530 Subject: [PATCH] feat: certbot auto-verification via dns script --- default.nix | 2 +- scripts/certbot-auth.sh | 15 ++++++++++++++ scripts/certbot.sh | 44 ++++++++--------------------------------- 3 files changed, 24 insertions(+), 37 deletions(-) create mode 100755 scripts/certbot-auth.sh diff --git a/default.nix b/default.nix index 51e03c2d0..b806eb6c4 100644 --- a/default.nix +++ b/default.nix @@ -3,7 +3,7 @@ let inherit (nixpkgs) pkgs; nixPackages = with pkgs; [ - nodejs-16_x + nodejs-18_x yarn docker-compose dnsutils diff --git a/scripts/certbot-auth.sh b/scripts/certbot-auth.sh new file mode 100755 index 000000000..fd0245777 --- /dev/null +++ b/scripts/certbot-auth.sh @@ -0,0 +1,15 @@ +#!/usr/bin/env bash + +echo "$PWD"; + +echo "AUTH ::[$CERTBOT_VALIDATION]::[$CERTBOT_TOKEN]::[$CERTBOT_REMAINING_CHALLENGES]"; +echo "[$CERTBOT_DOMAIN]"; + +sleep 1; + +./scripts/certbot.sh acme_txt "$CERTBOT_VALIDATION"; + +sleep $((5*60)); + +./scripts/certbot.sh check; + diff --git a/scripts/certbot.sh b/scripts/certbot.sh index 3468e7395..451df74b6 100755 --- a/scripts/certbot.sh +++ b/scripts/certbot.sh @@ -13,13 +13,17 @@ generate_certificate() { --logs-dir $outdir/logs \ certonly \ --manual \ + --preferred-challenges=dns \ + --manual-auth-hook=./scripts/certbot-auth.sh \ -m 'phenax5@gmail.com' \ -d '*.is-a.dev,is-a.dev' \ + --agree-tos \ + --dry-run \ $(if_dry_run "--dry-run" ""); echo "+-----------------------------------------------+"; - echo "| Certificates output to: |"; - echo "| $outdir |"; + echo "| Certificate output: |"; + echo "|= $outdir"; echo "+-----------------------------------------------+"; } @@ -61,45 +65,15 @@ update_acme_txt_record() { update_record add TXT '_acme-challenge' "$1"; } -update_www_record() { - update_record remove CNAME 'www' "is-a-dev.github.io"; - sleep 1; - update_record add A 'www' "68.65.123.44"; -} - -upload_acme_file() { - local key="$1"; - local value="$2"; - echo " - const { cpanel } = require('./utils/lib/cpanel'); - const { ENV, DOMAIN_DOMAIN, DOMAIN_USER } = require('./utils/constants'); - - const file = { - dir: '/home/' + DOMAIN_USER + '/public_html/.well-known/acme-challenge', - file: '$key', - content: '$value', - }; - - console.log('Uploading acme validation file to', DOMAIN_DOMAIN, '(', ENV, ')...'); - cpanel.file.write(file).then(console.log).catch(console.error); - " | node -; -} - reset_acme() { - update_record remove A 'www' "68.65.123.44"; sleep 1; - update_record add CNAME 'www' "is-a-dev.github.io"; update_record remove TXT '_acme-challenge' ''; } case "$1" in - check) - echo "TXT record:: $(dig +noall +answer _acme-challenge.is-a.dev TXT | awk '{print $5}')"; - ;; - config_www) update_www_record ;; - acme_txt) update_acme_txt_record "$2" ;; - acme_file) upload_acme_file "$2" "$3" ;; + check) echo "TXT record:: $(dig +noall +answer _acme-challenge.is-a.dev TXT | awk '{print $5}')" ;; cert) generate_certificate ;; + acme_txt) update_acme_txt_record "$2" ;; reset) reset_acme ;; *) echo "Invalid command"; exit 1; ;; esac @@ -108,8 +82,6 @@ esac ### STEPS ### # Run ./scripts/certbot.sh cert # Run ./scripts/certbot.sh acme_txt "" -# Run ./scripts/certbot.sh acme_file "" "" -# Run ./scripts/certbot.sh config_www # cp -r /tmp/is-a-dev-whatever /opt/app/code/is-a-dev-cert # Upload cert.pem and privkey.pem (from config/live/is-a.dev/) contents to SSL > Manage SSL Sites # Run ./scripts/certbot.sh reset