fix
This commit is contained in:
parent
cf929a3a30
commit
a2b8a67eb1
5 changed files with 20 additions and 173 deletions
|
|
@ -58,18 +58,21 @@ jobs:
|
|||
rsync -avz --delete tools/deploy \
|
||||
${{ secrets.SSH_USER }}@${{ secrets.SSH_HOST }}:~/mnemo_cards/tools/
|
||||
|
||||
- name: Ensure SSL Certificates
|
||||
- name: Setup SSL Certificates
|
||||
run: |
|
||||
ssh -o ServerAliveInterval=60 -o ServerAliveCountMax=3 -o ConnectTimeout=30 -o StrictHostKeyChecking=no ${{ secrets.SSH_USER }}@${{ secrets.SSH_HOST }} << 'ENDSSH'
|
||||
set -e
|
||||
echo "🔐 Ensuring SSL certificates are available..."
|
||||
echo "🔐 Setting up SSL certificates for all domains..."
|
||||
|
||||
if [ -d "/etc/letsencrypt/live/mnemo-cards.online" ] && [ -f "/etc/letsencrypt/live/mnemo-cards.online/fullchain.pem" ]; then
|
||||
echo "✅ SSL certificates are present and valid"
|
||||
# Ensure SSL setup script exists and is executable
|
||||
if [ -f "/root/mnemo_cards/tools/ssl/setup_ssl.sh" ]; then
|
||||
chmod +x /root/mnemo_cards/tools/ssl/setup_ssl.sh
|
||||
echo "🔄 Running SSL setup for all domains..."
|
||||
bash /root/mnemo_cards/tools/ssl/setup_ssl.sh
|
||||
echo "✅ SSL certificates setup completed"
|
||||
else
|
||||
echo "⚠️ SSL certificates missing - they should be renewed automatically by cron"
|
||||
echo "Manual certificate renewal can be done with:"
|
||||
echo "sudo certbot renew"
|
||||
echo "❌ SSL setup script not found at /root/mnemo_cards/tools/ssl/setup_ssl.sh"
|
||||
exit 1
|
||||
fi
|
||||
ENDSSH
|
||||
|
||||
|
|
|
|||
Binary file not shown.
|
|
@ -43,37 +43,13 @@ ssh "$SERVER_USER@$SERVER_IP" << EOF
|
|||
chown -R $WEB_USER:$WEB_GROUP $WEB_ROOT
|
||||
chmod -R $WEB_PERMISSIONS $WEB_ROOT
|
||||
|
||||
# Check SSL certificate status and obtain if needed
|
||||
# SSL certificate is managed centrally via setup_ssl.sh during backend deployment
|
||||
if [ -d "/etc/letsencrypt/live/admin.mnemo-cards.online" ] && [ -f "/etc/letsencrypt/live/admin.mnemo-cards.online/fullchain.pem" ]; then
|
||||
echo "✅ Let's Encrypt certificate exists for admin.mnemo-cards.online"
|
||||
else
|
||||
echo "⚠️ SSL certificate not found for admin.mnemo-cards.online"
|
||||
echo "🔐 Attempting to obtain Let's Encrypt certificate..."
|
||||
|
||||
# Try to obtain certificate automatically
|
||||
if [ -f "/root/mnemo_cards/tools/ssl/renew_admin_ssl.sh" ]; then
|
||||
if bash /root/mnemo_cards/tools/ssl/renew_admin_ssl.sh; then
|
||||
echo "✅ SSL certificate obtained successfully!"
|
||||
else
|
||||
echo "❌ Failed to obtain SSL certificate automatically"
|
||||
echo " Falling back to self-signed certificate..."
|
||||
|
||||
# Generate self-signed certificate as fallback
|
||||
if [ ! -f "$SSL_SELF_CERT" ]; then
|
||||
echo " Generating self-signed certificate as fallback..."
|
||||
openssl req -x509 -nodes -days 365 -newkey rsa:2048 \
|
||||
-keyout $SSL_SELF_KEY \
|
||||
-out $SSL_SELF_CERT \
|
||||
-subj "/C=RU/ST=Moscow/L=Moscow/O=MnemoCards/OU=Admin/CN=admin.mnemo-cards.online"
|
||||
echo " ✅ Self-signed certificate generated"
|
||||
echo " ⚠️ WARNING: Using self-signed certificate. HTTPS warnings will appear in browsers."
|
||||
echo " To fix: Run 'bash /root/mnemo_cards/tools/ssl/renew_admin_ssl.sh' manually after deployment"
|
||||
fi
|
||||
fi
|
||||
else
|
||||
echo "❌ SSL renewal script not found!"
|
||||
echo " Falling back to self-signed certificate..."
|
||||
fi
|
||||
echo "❌ SSL certificate not found for admin.mnemo-cards.online"
|
||||
echo " Certificate should be created by setup_ssl.sh during backend deployment"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# Configure nginx
|
||||
|
|
|
|||
|
|
@ -16,12 +16,13 @@ The following domains require SSL certificates:
|
|||
|
||||
## Certificate Issuance
|
||||
|
||||
Certificates are automatically obtained during deployment:
|
||||
Certificates are centrally managed and automatically obtained during backend deployment:
|
||||
|
||||
- **Main site**: `tools/deploy/web-app/deploy.sh`
|
||||
- **Admin panel**: `tools/deploy/admin/deploy.sh`
|
||||
- **API**: Handled by backend deployment
|
||||
- **Forgejo/VSCode**: Handled by their respective deployments
|
||||
- **All domains**: Automatically handled by `setup_ssl.sh` during backend deployment in CI/CD
|
||||
- **Manual setup**: Run `sudo ./setup_ssl.sh` to obtain certificates for all domains
|
||||
- **Individual certificates**: Use `renew_admin_ssl.sh` for admin domain only (fallback)
|
||||
|
||||
The CI/CD pipeline calls `setup_ssl.sh` during backend deployment to ensure all certificates are current.
|
||||
|
||||
## Tools
|
||||
|
||||
|
|
|
|||
|
|
@ -1,133 +0,0 @@
|
|||
#!/bin/bash
|
||||
|
||||
# SSL Certificate Renewal Script for admin.mnemo-cards.online
|
||||
# This script obtains Let's Encrypt SSL certificate for admin panel
|
||||
# Usage: ./renew_admin_ssl.sh
|
||||
|
||||
set -e
|
||||
|
||||
DOMAIN="admin.mnemo-cards.online"
|
||||
EMAIL="admin@mnemo-cards.online"
|
||||
|
||||
echo "🔐 Starting SSL certificate renewal for $DOMAIN..."
|
||||
|
||||
# Colors for output
|
||||
RED='\033[0;31m'
|
||||
GREEN='\033[0;32m'
|
||||
YELLOW='\033[1;33m'
|
||||
BLUE='\033[0;34m'
|
||||
NC='\033[0m' # No Color
|
||||
|
||||
print_status() {
|
||||
echo -e "${GREEN}[INFO]${NC} $1"
|
||||
}
|
||||
|
||||
print_warning() {
|
||||
echo -e "${YELLOW}[WARNING]${NC} $1"
|
||||
}
|
||||
|
||||
print_error() {
|
||||
echo -e "${RED}[ERROR]${NC} $1"
|
||||
}
|
||||
|
||||
print_success() {
|
||||
echo -e "${GREEN}[SUCCESS]${NC} $1"
|
||||
}
|
||||
|
||||
# Check if certbot is installed
|
||||
if ! command -v certbot &> /dev/null; then
|
||||
print_status "Installing certbot..."
|
||||
apt update
|
||||
apt install -y certbot
|
||||
fi
|
||||
|
||||
# Check current nginx status
|
||||
NGINX_RUNNING=false
|
||||
if systemctl is-active --quiet nginx; then
|
||||
NGINX_RUNNING=true
|
||||
print_status "nginx is currently running"
|
||||
else
|
||||
print_status "nginx is currently stopped"
|
||||
fi
|
||||
|
||||
# Stop nginx for standalone mode
|
||||
if [ "$NGINX_RUNNING" = true ]; then
|
||||
print_status "Stopping nginx for certificate renewal..."
|
||||
systemctl stop nginx
|
||||
sleep 2
|
||||
fi
|
||||
|
||||
# Obtain certificate
|
||||
print_status "Obtaining SSL certificate for $DOMAIN..."
|
||||
if certbot certonly --standalone \
|
||||
-d "$DOMAIN" \
|
||||
--email "$EMAIL" \
|
||||
--agree-tos \
|
||||
--non-interactive; then
|
||||
|
||||
print_success "SSL certificate obtained successfully!"
|
||||
|
||||
# Verify certificate files exist
|
||||
if [ -f "/etc/letsencrypt/live/$DOMAIN/fullchain.pem" ] && [ -f "/etc/letsencrypt/live/$DOMAIN/privkey.pem" ]; then
|
||||
print_success "Certificate files verified"
|
||||
|
||||
# Set proper permissions
|
||||
chmod 600 "/etc/letsencrypt/live/$DOMAIN/privkey.pem"
|
||||
chmod 644 "/etc/letsencrypt/live/$DOMAIN/fullchain.pem"
|
||||
|
||||
print_success "Certificate permissions set"
|
||||
else
|
||||
print_error "Certificate files not found after renewal!"
|
||||
exit 1
|
||||
fi
|
||||
else
|
||||
print_error "Failed to obtain SSL certificate!"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# Start nginx back
|
||||
if [ "$NGINX_RUNNING" = true ]; then
|
||||
print_status "Starting nginx..."
|
||||
systemctl start nginx
|
||||
sleep 2
|
||||
|
||||
if systemctl is-active --quiet nginx; then
|
||||
print_success "nginx started successfully"
|
||||
else
|
||||
print_error "Failed to start nginx!"
|
||||
exit 1
|
||||
fi
|
||||
fi
|
||||
|
||||
# Test certificate validity
|
||||
print_status "Testing certificate validity..."
|
||||
if openssl x509 -in "/etc/letsencrypt/live/$DOMAIN/cert.pem" -text -noout | grep -q "Subject:.*$DOMAIN"; then
|
||||
print_success "Certificate is valid for $DOMAIN"
|
||||
else
|
||||
print_error "Certificate validation failed!"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# Test HTTPS connection
|
||||
print_status "Testing HTTPS connection..."
|
||||
if curl -I --max-time 10 "https://$DOMAIN/" 2>/dev/null | grep -q "200\|301\|302"; then
|
||||
print_success "HTTPS connection to $DOMAIN is working"
|
||||
else
|
||||
print_warning "HTTPS connection test failed - this may be normal if nginx config needs reloading"
|
||||
fi
|
||||
|
||||
# Setup auto-renewal cron job
|
||||
print_status "Setting up automatic renewal..."
|
||||
CRON_JOB="0 12 * * * /usr/bin/certbot renew --quiet --post-hook \"systemctl reload nginx\" --cert-name $DOMAIN"
|
||||
|
||||
# Check if cron job already exists
|
||||
if ! crontab -l 2>/dev/null | grep -q "certbot.*$DOMAIN"; then
|
||||
(crontab -l 2>/dev/null; echo "$CRON_JOB") | crontab -
|
||||
print_success "Auto-renewal cron job added"
|
||||
else
|
||||
print_info "Auto-renewal cron job already exists"
|
||||
fi
|
||||
|
||||
print_success "SSL certificate renewal completed successfully! 🎉"
|
||||
print_info "Certificate will auto-renew before expiration"
|
||||
print_info "Admin panel is now available at: https://$DOMAIN"
|
||||
Loading…
Reference in a new issue