This commit is contained in:
Dmitry 2025-12-03 04:22:59 +03:00
parent cf929a3a30
commit a2b8a67eb1
5 changed files with 20 additions and 173 deletions

View file

@ -58,18 +58,21 @@ jobs:
rsync -avz --delete tools/deploy \
${{ secrets.SSH_USER }}@${{ secrets.SSH_HOST }}:~/mnemo_cards/tools/
- name: Ensure SSL Certificates
- name: Setup SSL Certificates
run: |
ssh -o ServerAliveInterval=60 -o ServerAliveCountMax=3 -o ConnectTimeout=30 -o StrictHostKeyChecking=no ${{ secrets.SSH_USER }}@${{ secrets.SSH_HOST }} << 'ENDSSH'
set -e
echo "🔐 Ensuring SSL certificates are available..."
echo "🔐 Setting up SSL certificates for all domains..."
if [ -d "/etc/letsencrypt/live/mnemo-cards.online" ] && [ -f "/etc/letsencrypt/live/mnemo-cards.online/fullchain.pem" ]; then
echo "✅ SSL certificates are present and valid"
# Ensure SSL setup script exists and is executable
if [ -f "/root/mnemo_cards/tools/ssl/setup_ssl.sh" ]; then
chmod +x /root/mnemo_cards/tools/ssl/setup_ssl.sh
echo "🔄 Running SSL setup for all domains..."
bash /root/mnemo_cards/tools/ssl/setup_ssl.sh
echo "✅ SSL certificates setup completed"
else
echo "⚠️ SSL certificates missing - they should be renewed automatically by cron"
echo "Manual certificate renewal can be done with:"
echo "sudo certbot renew"
echo "❌ SSL setup script not found at /root/mnemo_cards/tools/ssl/setup_ssl.sh"
exit 1
fi
ENDSSH

Binary file not shown.

View file

@ -43,37 +43,13 @@ ssh "$SERVER_USER@$SERVER_IP" << EOF
chown -R $WEB_USER:$WEB_GROUP $WEB_ROOT
chmod -R $WEB_PERMISSIONS $WEB_ROOT
# Check SSL certificate status and obtain if needed
# SSL certificate is managed centrally via setup_ssl.sh during backend deployment
if [ -d "/etc/letsencrypt/live/admin.mnemo-cards.online" ] && [ -f "/etc/letsencrypt/live/admin.mnemo-cards.online/fullchain.pem" ]; then
echo "✅ Let's Encrypt certificate exists for admin.mnemo-cards.online"
else
echo "⚠️ SSL certificate not found for admin.mnemo-cards.online"
echo "🔐 Attempting to obtain Let's Encrypt certificate..."
# Try to obtain certificate automatically
if [ -f "/root/mnemo_cards/tools/ssl/renew_admin_ssl.sh" ]; then
if bash /root/mnemo_cards/tools/ssl/renew_admin_ssl.sh; then
echo "✅ SSL certificate obtained successfully!"
else
echo "❌ Failed to obtain SSL certificate automatically"
echo " Falling back to self-signed certificate..."
# Generate self-signed certificate as fallback
if [ ! -f "$SSL_SELF_CERT" ]; then
echo " Generating self-signed certificate as fallback..."
openssl req -x509 -nodes -days 365 -newkey rsa:2048 \
-keyout $SSL_SELF_KEY \
-out $SSL_SELF_CERT \
-subj "/C=RU/ST=Moscow/L=Moscow/O=MnemoCards/OU=Admin/CN=admin.mnemo-cards.online"
echo " ✅ Self-signed certificate generated"
echo " ⚠️ WARNING: Using self-signed certificate. HTTPS warnings will appear in browsers."
echo " To fix: Run 'bash /root/mnemo_cards/tools/ssl/renew_admin_ssl.sh' manually after deployment"
fi
fi
else
echo "❌ SSL renewal script not found!"
echo " Falling back to self-signed certificate..."
fi
echo "❌ SSL certificate not found for admin.mnemo-cards.online"
echo " Certificate should be created by setup_ssl.sh during backend deployment"
exit 1
fi
# Configure nginx

View file

@ -16,12 +16,13 @@ The following domains require SSL certificates:
## Certificate Issuance
Certificates are automatically obtained during deployment:
Certificates are centrally managed and automatically obtained during backend deployment:
- **Main site**: `tools/deploy/web-app/deploy.sh`
- **Admin panel**: `tools/deploy/admin/deploy.sh`
- **API**: Handled by backend deployment
- **Forgejo/VSCode**: Handled by their respective deployments
- **All domains**: Automatically handled by `setup_ssl.sh` during backend deployment in CI/CD
- **Manual setup**: Run `sudo ./setup_ssl.sh` to obtain certificates for all domains
- **Individual certificates**: Use `renew_admin_ssl.sh` for admin domain only (fallback)
The CI/CD pipeline calls `setup_ssl.sh` during backend deployment to ensure all certificates are current.
## Tools

View file

@ -1,133 +0,0 @@
#!/bin/bash
# SSL Certificate Renewal Script for admin.mnemo-cards.online
# This script obtains Let's Encrypt SSL certificate for admin panel
# Usage: ./renew_admin_ssl.sh
set -e
DOMAIN="admin.mnemo-cards.online"
EMAIL="admin@mnemo-cards.online"
echo "🔐 Starting SSL certificate renewal for $DOMAIN..."
# Colors for output
RED='\033[0;31m'
GREEN='\033[0;32m'
YELLOW='\033[1;33m'
BLUE='\033[0;34m'
NC='\033[0m' # No Color
print_status() {
echo -e "${GREEN}[INFO]${NC} $1"
}
print_warning() {
echo -e "${YELLOW}[WARNING]${NC} $1"
}
print_error() {
echo -e "${RED}[ERROR]${NC} $1"
}
print_success() {
echo -e "${GREEN}[SUCCESS]${NC} $1"
}
# Check if certbot is installed
if ! command -v certbot &> /dev/null; then
print_status "Installing certbot..."
apt update
apt install -y certbot
fi
# Check current nginx status
NGINX_RUNNING=false
if systemctl is-active --quiet nginx; then
NGINX_RUNNING=true
print_status "nginx is currently running"
else
print_status "nginx is currently stopped"
fi
# Stop nginx for standalone mode
if [ "$NGINX_RUNNING" = true ]; then
print_status "Stopping nginx for certificate renewal..."
systemctl stop nginx
sleep 2
fi
# Obtain certificate
print_status "Obtaining SSL certificate for $DOMAIN..."
if certbot certonly --standalone \
-d "$DOMAIN" \
--email "$EMAIL" \
--agree-tos \
--non-interactive; then
print_success "SSL certificate obtained successfully!"
# Verify certificate files exist
if [ -f "/etc/letsencrypt/live/$DOMAIN/fullchain.pem" ] && [ -f "/etc/letsencrypt/live/$DOMAIN/privkey.pem" ]; then
print_success "Certificate files verified"
# Set proper permissions
chmod 600 "/etc/letsencrypt/live/$DOMAIN/privkey.pem"
chmod 644 "/etc/letsencrypt/live/$DOMAIN/fullchain.pem"
print_success "Certificate permissions set"
else
print_error "Certificate files not found after renewal!"
exit 1
fi
else
print_error "Failed to obtain SSL certificate!"
exit 1
fi
# Start nginx back
if [ "$NGINX_RUNNING" = true ]; then
print_status "Starting nginx..."
systemctl start nginx
sleep 2
if systemctl is-active --quiet nginx; then
print_success "nginx started successfully"
else
print_error "Failed to start nginx!"
exit 1
fi
fi
# Test certificate validity
print_status "Testing certificate validity..."
if openssl x509 -in "/etc/letsencrypt/live/$DOMAIN/cert.pem" -text -noout | grep -q "Subject:.*$DOMAIN"; then
print_success "Certificate is valid for $DOMAIN"
else
print_error "Certificate validation failed!"
exit 1
fi
# Test HTTPS connection
print_status "Testing HTTPS connection..."
if curl -I --max-time 10 "https://$DOMAIN/" 2>/dev/null | grep -q "200\|301\|302"; then
print_success "HTTPS connection to $DOMAIN is working"
else
print_warning "HTTPS connection test failed - this may be normal if nginx config needs reloading"
fi
# Setup auto-renewal cron job
print_status "Setting up automatic renewal..."
CRON_JOB="0 12 * * * /usr/bin/certbot renew --quiet --post-hook \"systemctl reload nginx\" --cert-name $DOMAIN"
# Check if cron job already exists
if ! crontab -l 2>/dev/null | grep -q "certbot.*$DOMAIN"; then
(crontab -l 2>/dev/null; echo "$CRON_JOB") | crontab -
print_success "Auto-renewal cron job added"
else
print_info "Auto-renewal cron job already exists"
fi
print_success "SSL certificate renewal completed successfully! 🎉"
print_info "Certificate will auto-renew before expiration"
print_info "Admin panel is now available at: https://$DOMAIN"