|
1 | 1 | #!/bin/bash
|
2 | 2 |
|
3 |
| -# Hydrate default.conf.template PROXY_HOST and PROXY_PORT PROXY_DOMAIN with environment variables |
4 |
| -envsubst '$PROXY_HOST,$PROXY_PORT,$PROXY_DOMAIN' < /app/default.conf.template > /etc/nginx/conf.d/default.conf |
| 3 | +# Stop on error |
| 4 | +set -e |
5 | 5 |
|
| 6 | +# ------------------- |
| 7 | +# DEBUG information |
| 8 | +# ------------------- |
6 | 9 | if [ "$DEBUG" = "true" ]; then
|
7 | 10 | echo "DEBUG MODE ENABLED"
|
8 |
| - |
9 |
| - echo "Nginx configuration:" |
10 |
| - cat /etc/nginx/conf.d/default.conf |
11 |
| - echo -e "\n===========================" |
12 |
| - |
13 |
| - echo "Existing certificates:" |
14 |
| - certbot certificates |
15 |
| - echo -e "\n===========================" |
16 |
| - |
17 |
| - echo "Environment variables:" |
18 |
| - echo " PROXY_HOST: $PROXY_HOST" |
19 |
| - echo " PROXY_PORT: $PROXY_PORT" |
20 |
| - echo " PROXY_DOMAIN: $PROXY_DOMAIN" |
21 |
| - echo " SSL_ENABLED: $SSL_ENABLED" |
| 11 | + echo "MAPPINGS: $MAPPINGS" |
| 12 | + echo "SSL_ENABLED: $SSL_ENABLED" |
| 13 | + echo "Let's encrypt email: ${LETSENCRYPT_EMAIL:-contact@domain.com}" |
22 | 14 | echo "==========================="
|
23 | 15 | fi
|
24 | 16 |
|
25 |
| -if [ "$SSL_ENABLED" = "true" ]; then |
26 |
| - # check if certbot certificates already exist for $PROXY_DOMAIN |
27 |
| - if certbot certificates | grep -q $PROXY_DOMAIN; then |
28 |
| - echo "Certificate already exists for $PROXY_DOMAIN" |
29 |
| - certbot --cert-name $PROXY_DOMAIN install |
| 17 | +# ------------------- |
| 18 | +# Split the MAPPINGS |
| 19 | +# ------------------- |
| 20 | +IFS=',' read -ra MAPPING_LIST <<< "$MAPPINGS" |
| 21 | + |
| 22 | +# Clear out any old default config(s) (optional) |
| 23 | +rm -f /etc/nginx/conf.d/*.conf |
| 24 | + |
| 25 | +# For each mapping: domain=host:port |
| 26 | +for MAPPING in "${MAPPING_LIST[@]}"; do |
| 27 | + |
| 28 | + # Extract the domain, host, port |
| 29 | + DOMAIN="$(echo "$MAPPING" | cut -d= -f1)" |
| 30 | + HOSTPORT="$(echo "$MAPPING" | cut -d= -f2)" |
| 31 | + |
| 32 | + PROXY_HOST="$(echo "$HOSTPORT" | cut -d: -f1)" |
| 33 | + PROXY_PORT="$(echo "$HOSTPORT" | cut -d: -f2)" |
| 34 | + |
| 35 | + # Export these so envsubst can substitute them |
| 36 | + export PROXY_DOMAIN="$DOMAIN" |
| 37 | + export PROXY_HOST="$PROXY_HOST" |
| 38 | + export PROXY_PORT="$PROXY_PORT" |
| 39 | + |
| 40 | + # ------------------------- |
| 41 | + # Render Nginx config |
| 42 | + # ------------------------- |
| 43 | + if [ "$DEBUG" = "true" ]; then |
| 44 | + echo "Generating config for:" |
| 45 | + echo " Domain: $PROXY_DOMAIN" |
| 46 | + echo " Host: $PROXY_HOST" |
| 47 | + echo " Port: $PROXY_PORT" |
| 48 | + fi |
| 49 | + |
| 50 | + # Determine which template to use |
| 51 | + CUSTOM_TEMPLATE="/app/${PROXY_HOST}.${PROXY_PORT}.conf" |
| 52 | + DEFAULT_TEMPLATE="/app/default.conf.template" |
| 53 | + |
| 54 | + if [ -f "$CUSTOM_TEMPLATE" ]; then |
| 55 | + TEMPLATE="$CUSTOM_TEMPLATE" |
| 56 | + echo "Using custom template: $TEMPLATE" |
30 | 57 | else
|
31 |
| - echo "Certificate does not exist for $PROXY_DOMAIN, creating..." |
32 |
| - certbot --nginx --email "[email protected]" --agree-tos --no-eff-email -d $PROXY_DOMAIN |
| 58 | + TEMPLATE="$DEFAULT_TEMPLATE" |
| 59 | + echo "Using default template: $TEMPLATE" |
33 | 60 | fi
|
34 |
| -fi |
35 | 61 |
|
| 62 | + # Use envsubst to produce a .conf per domain |
| 63 | + envsubst '$PROXY_DOMAIN,$PROXY_HOST,$PROXY_PORT' \ |
| 64 | + < "$TEMPLATE" \ |
| 65 | + > "/etc/nginx/conf.d/${PROXY_DOMAIN}.conf" |
| 66 | + |
| 67 | + # ------------------------- |
| 68 | + # Issue or Install SSL Cert |
| 69 | + # ------------------------- |
| 70 | + if [ "$SSL_ENABLED" = "true" ]; then |
| 71 | + |
| 72 | + # Check whether a cert exists for this domain |
| 73 | + if certbot certificates | grep -q "$PROXY_DOMAIN"; then |
| 74 | + echo "Certificate already exists for $PROXY_DOMAIN" |
| 75 | + certbot --cert-name "$PROXY_DOMAIN" install |
| 76 | + else |
| 77 | + echo "Creating certificate for $PROXY_DOMAIN..." |
| 78 | + certbot --nginx \ |
| 79 | + --email "${LETSENCRYPT_EMAIL:-contact@domain.com}" \ |
| 80 | + --agree-tos \ |
| 81 | + --no-eff-email \ |
| 82 | + -d "$PROXY_DOMAIN" |
| 83 | + fi |
| 84 | + fi |
| 85 | + |
| 86 | + if [ "$DEBUG" = "true" ]; then |
| 87 | + echo "-------------------------------------------" |
| 88 | + fi |
| 89 | +done |
| 90 | + |
| 91 | +# ------------------------- |
| 92 | +# Debug / Verification |
| 93 | +# ------------------------- |
36 | 94 | if [ "$DEBUG" = "true" ]; then
|
37 |
| - echo "Updated Nginx configuration:" |
38 |
| - cat /etc/nginx/conf.d/default.conf |
39 |
| - echo -e "\n===========================" |
| 95 | + echo "Final Nginx Config(s):" |
| 96 | + cat /etc/nginx/conf.d/*.conf |
| 97 | + echo "-------------------------------------------" |
40 | 98 |
|
41 |
| - echo "Certbot log:" |
42 |
| - cat /var/log/letsencrypt/letsencrypt.log |
43 |
| - echo -e "\n===========================" |
| 99 | + echo "Existing certificates:" |
| 100 | + certbot certificates || true |
| 101 | + echo "-------------------------------------------" |
44 | 102 | fi
|
45 | 103 |
|
46 |
| -# Stop nginx if it's already running |
47 |
| -nginx -s stop |
| 104 | +# Stop nginx if it's already running (ignore error if not running) |
| 105 | +nginx -s stop || true |
48 | 106 |
|
49 |
| -# Start nginx |
50 |
| -nginx -g "daemon off;" |
| 107 | +# Start nginx in foreground |
| 108 | +exec nginx -g "daemon off;" |
0 commit comments