diff --git a/.forgejo/workflows/deploy.yaml b/.forgejo/workflows/deploy.yaml index 00b8f20..2d3f100 100644 --- a/.forgejo/workflows/deploy.yaml +++ b/.forgejo/workflows/deploy.yaml @@ -58,18 +58,21 @@ jobs: rsync -avz --delete tools/deploy \ ${{ secrets.SSH_USER }}@${{ secrets.SSH_HOST }}:~/mnemo_cards/tools/ - - name: Ensure SSL Certificates + - name: Setup SSL Certificates run: | ssh -o ServerAliveInterval=60 -o ServerAliveCountMax=3 -o ConnectTimeout=30 -o StrictHostKeyChecking=no ${{ secrets.SSH_USER }}@${{ secrets.SSH_HOST }} << 'ENDSSH' set -e - echo "🔐 Ensuring SSL certificates are available..." + echo "🔐 Setting up SSL certificates for all domains..." - if [ -d "/etc/letsencrypt/live/mnemo-cards.online" ] && [ -f "/etc/letsencrypt/live/mnemo-cards.online/fullchain.pem" ]; then - echo "✅ SSL certificates are present and valid" + # Ensure SSL setup script exists and is executable + if [ -f "/root/mnemo_cards/tools/ssl/setup_ssl.sh" ]; then + chmod +x /root/mnemo_cards/tools/ssl/setup_ssl.sh + echo "🔄 Running SSL setup for all domains..." + bash /root/mnemo_cards/tools/ssl/setup_ssl.sh + echo "✅ SSL certificates setup completed" else - echo "⚠️ SSL certificates missing - they should be renewed automatically by cron" - echo "Manual certificate renewal can be done with:" - echo "sudo certbot renew" + echo "❌ SSL setup script not found at /root/mnemo_cards/tools/ssl/setup_ssl.sh" + exit 1 fi ENDSSH diff --git a/mnemo_cards_backend/isar/db.isar b/mnemo_cards_backend/isar/db.isar index 4411246..edc8559 100644 Binary files a/mnemo_cards_backend/isar/db.isar and b/mnemo_cards_backend/isar/db.isar differ diff --git a/tools/deploy/admin/deploy.sh b/tools/deploy/admin/deploy.sh index 5154088..20491ba 100755 --- a/tools/deploy/admin/deploy.sh +++ b/tools/deploy/admin/deploy.sh @@ -43,37 +43,13 @@ ssh "$SERVER_USER@$SERVER_IP" << EOF chown -R $WEB_USER:$WEB_GROUP $WEB_ROOT chmod -R $WEB_PERMISSIONS $WEB_ROOT - # Check SSL certificate status and obtain if needed + # SSL certificate is managed centrally via setup_ssl.sh during backend deployment if [ -d "/etc/letsencrypt/live/admin.mnemo-cards.online" ] && [ -f "/etc/letsencrypt/live/admin.mnemo-cards.online/fullchain.pem" ]; then echo "✅ Let's Encrypt certificate exists for admin.mnemo-cards.online" else - echo "⚠️ SSL certificate not found for admin.mnemo-cards.online" - echo "🔐 Attempting to obtain Let's Encrypt certificate..." - - # Try to obtain certificate automatically - if [ -f "/root/mnemo_cards/tools/ssl/renew_admin_ssl.sh" ]; then - if bash /root/mnemo_cards/tools/ssl/renew_admin_ssl.sh; then - echo "✅ SSL certificate obtained successfully!" - else - echo "❌ Failed to obtain SSL certificate automatically" - echo " Falling back to self-signed certificate..." - - # Generate self-signed certificate as fallback - if [ ! -f "$SSL_SELF_CERT" ]; then - echo " Generating self-signed certificate as fallback..." - openssl req -x509 -nodes -days 365 -newkey rsa:2048 \ - -keyout $SSL_SELF_KEY \ - -out $SSL_SELF_CERT \ - -subj "/C=RU/ST=Moscow/L=Moscow/O=MnemoCards/OU=Admin/CN=admin.mnemo-cards.online" - echo " ✅ Self-signed certificate generated" - echo " ⚠️ WARNING: Using self-signed certificate. HTTPS warnings will appear in browsers." - echo " To fix: Run 'bash /root/mnemo_cards/tools/ssl/renew_admin_ssl.sh' manually after deployment" - fi - fi - else - echo "❌ SSL renewal script not found!" - echo " Falling back to self-signed certificate..." - fi + echo "❌ SSL certificate not found for admin.mnemo-cards.online" + echo " Certificate should be created by setup_ssl.sh during backend deployment" + exit 1 fi # Configure nginx diff --git a/tools/ssl/README.md b/tools/ssl/README.md index e8f0dcb..4570397 100644 --- a/tools/ssl/README.md +++ b/tools/ssl/README.md @@ -16,12 +16,13 @@ The following domains require SSL certificates: ## Certificate Issuance -Certificates are automatically obtained during deployment: +Certificates are centrally managed and automatically obtained during backend deployment: -- **Main site**: `tools/deploy/web-app/deploy.sh` -- **Admin panel**: `tools/deploy/admin/deploy.sh` -- **API**: Handled by backend deployment -- **Forgejo/VSCode**: Handled by their respective deployments +- **All domains**: Automatically handled by `setup_ssl.sh` during backend deployment in CI/CD +- **Manual setup**: Run `sudo ./setup_ssl.sh` to obtain certificates for all domains +- **Individual certificates**: Use `renew_admin_ssl.sh` for admin domain only (fallback) + +The CI/CD pipeline calls `setup_ssl.sh` during backend deployment to ensure all certificates are current. ## Tools diff --git a/tools/ssl/renew_admin_ssl.sh b/tools/ssl/renew_admin_ssl.sh deleted file mode 100755 index 51504b2..0000000 --- a/tools/ssl/renew_admin_ssl.sh +++ /dev/null @@ -1,133 +0,0 @@ -#!/bin/bash - -# SSL Certificate Renewal Script for admin.mnemo-cards.online -# This script obtains Let's Encrypt SSL certificate for admin panel -# Usage: ./renew_admin_ssl.sh - -set -e - -DOMAIN="admin.mnemo-cards.online" -EMAIL="admin@mnemo-cards.online" - -echo "🔐 Starting SSL certificate renewal for $DOMAIN..." - -# Colors for output -RED='\033[0;31m' -GREEN='\033[0;32m' -YELLOW='\033[1;33m' -BLUE='\033[0;34m' -NC='\033[0m' # No Color - -print_status() { - echo -e "${GREEN}[INFO]${NC} $1" -} - -print_warning() { - echo -e "${YELLOW}[WARNING]${NC} $1" -} - -print_error() { - echo -e "${RED}[ERROR]${NC} $1" -} - -print_success() { - echo -e "${GREEN}[SUCCESS]${NC} $1" -} - -# Check if certbot is installed -if ! command -v certbot &> /dev/null; then - print_status "Installing certbot..." - apt update - apt install -y certbot -fi - -# Check current nginx status -NGINX_RUNNING=false -if systemctl is-active --quiet nginx; then - NGINX_RUNNING=true - print_status "nginx is currently running" -else - print_status "nginx is currently stopped" -fi - -# Stop nginx for standalone mode -if [ "$NGINX_RUNNING" = true ]; then - print_status "Stopping nginx for certificate renewal..." - systemctl stop nginx - sleep 2 -fi - -# Obtain certificate -print_status "Obtaining SSL certificate for $DOMAIN..." -if certbot certonly --standalone \ - -d "$DOMAIN" \ - --email "$EMAIL" \ - --agree-tos \ - --non-interactive; then - - print_success "SSL certificate obtained successfully!" - - # Verify certificate files exist - if [ -f "/etc/letsencrypt/live/$DOMAIN/fullchain.pem" ] && [ -f "/etc/letsencrypt/live/$DOMAIN/privkey.pem" ]; then - print_success "Certificate files verified" - - # Set proper permissions - chmod 600 "/etc/letsencrypt/live/$DOMAIN/privkey.pem" - chmod 644 "/etc/letsencrypt/live/$DOMAIN/fullchain.pem" - - print_success "Certificate permissions set" - else - print_error "Certificate files not found after renewal!" - exit 1 - fi -else - print_error "Failed to obtain SSL certificate!" - exit 1 -fi - -# Start nginx back -if [ "$NGINX_RUNNING" = true ]; then - print_status "Starting nginx..." - systemctl start nginx - sleep 2 - - if systemctl is-active --quiet nginx; then - print_success "nginx started successfully" - else - print_error "Failed to start nginx!" - exit 1 - fi -fi - -# Test certificate validity -print_status "Testing certificate validity..." -if openssl x509 -in "/etc/letsencrypt/live/$DOMAIN/cert.pem" -text -noout | grep -q "Subject:.*$DOMAIN"; then - print_success "Certificate is valid for $DOMAIN" -else - print_error "Certificate validation failed!" - exit 1 -fi - -# Test HTTPS connection -print_status "Testing HTTPS connection..." -if curl -I --max-time 10 "https://$DOMAIN/" 2>/dev/null | grep -q "200\|301\|302"; then - print_success "HTTPS connection to $DOMAIN is working" -else - print_warning "HTTPS connection test failed - this may be normal if nginx config needs reloading" -fi - -# Setup auto-renewal cron job -print_status "Setting up automatic renewal..." -CRON_JOB="0 12 * * * /usr/bin/certbot renew --quiet --post-hook \"systemctl reload nginx\" --cert-name $DOMAIN" - -# Check if cron job already exists -if ! crontab -l 2>/dev/null | grep -q "certbot.*$DOMAIN"; then - (crontab -l 2>/dev/null; echo "$CRON_JOB") | crontab - - print_success "Auto-renewal cron job added" -else - print_info "Auto-renewal cron job already exists" -fi - -print_success "SSL certificate renewal completed successfully! 🎉" -print_info "Certificate will auto-renew before expiration" -print_info "Admin panel is now available at: https://$DOMAIN"