|
1 | 1 | #!/bin/bash |
2 | 2 |
|
3 | | -# Hydrate default.conf.template PROXY_HOST and PROXY_PORT PROXY_DOMAIN with environment variables |
4 | | -envsubst '$PROXY_HOST,$PROXY_PORT,$PROXY_DOMAIN' < /app/default.conf.template > /etc/nginx/conf.d/default.conf |
| 3 | +# Stop on error |
| 4 | +set -e |
5 | 5 |
|
| 6 | +# ------------------- |
| 7 | +# DEBUG information |
| 8 | +# ------------------- |
6 | 9 | if [ "$DEBUG" = "true" ]; then |
7 | 10 | echo "DEBUG MODE ENABLED" |
8 | | - |
9 | | - echo "Nginx configuration:" |
10 | | - cat /etc/nginx/conf.d/default.conf |
11 | | - echo -e "\n===========================" |
12 | | - |
13 | | - echo "Existing certificates:" |
14 | | - certbot certificates |
15 | | - echo -e "\n===========================" |
16 | | - |
17 | | - echo "Environment variables:" |
18 | | - echo " PROXY_HOST: $PROXY_HOST" |
19 | | - echo " PROXY_PORT: $PROXY_PORT" |
20 | | - echo " PROXY_DOMAIN: $PROXY_DOMAIN" |
21 | | - echo " SSL_ENABLED: $SSL_ENABLED" |
| 11 | + echo "MAPPINGS: $MAPPINGS" |
| 12 | + echo "SSL_ENABLED: $SSL_ENABLED" |
| 13 | + echo "Let's encrypt email: ${LETSENCRYPT_EMAIL:-contact@domain.com}" |
22 | 14 | echo "===========================" |
23 | 15 | fi |
24 | 16 |
|
25 | | -if [ "$SSL_ENABLED" = "true" ]; then |
26 | | - # check if certbot certificates already exist for $PROXY_DOMAIN |
27 | | - if certbot certificates | grep -q $PROXY_DOMAIN; then |
28 | | - echo "Certificate already exists for $PROXY_DOMAIN" |
29 | | - certbot --cert-name $PROXY_DOMAIN install |
| 17 | +# ------------------- |
| 18 | +# Split the MAPPINGS |
| 19 | +# ------------------- |
| 20 | +IFS=',' read -ra MAPPING_LIST <<< "$MAPPINGS" |
| 21 | + |
| 22 | +# Clear out any old default config(s) (optional) |
| 23 | +rm -f /etc/nginx/conf.d/*.conf |
| 24 | + |
| 25 | +# For each mapping: domain=host:port |
| 26 | +for MAPPING in "${MAPPING_LIST[@]}"; do |
| 27 | + |
| 28 | + # Extract the domain, host, port |
| 29 | + DOMAIN="$(echo "$MAPPING" | cut -d= -f1)" |
| 30 | + HOSTPORT="$(echo "$MAPPING" | cut -d= -f2)" |
| 31 | + |
| 32 | + PROXY_HOST="$(echo "$HOSTPORT" | cut -d: -f1)" |
| 33 | + PROXY_PORT="$(echo "$HOSTPORT" | cut -d: -f2)" |
| 34 | + |
| 35 | + # Export these so envsubst can substitute them |
| 36 | + export PROXY_DOMAIN="$DOMAIN" |
| 37 | + export PROXY_HOST="$PROXY_HOST" |
| 38 | + export PROXY_PORT="$PROXY_PORT" |
| 39 | + |
| 40 | + # ------------------------- |
| 41 | + # Render Nginx config |
| 42 | + # ------------------------- |
| 43 | + if [ "$DEBUG" = "true" ]; then |
| 44 | + echo "Generating config for:" |
| 45 | + echo " Domain: $PROXY_DOMAIN" |
| 46 | + echo " Host: $PROXY_HOST" |
| 47 | + echo " Port: $PROXY_PORT" |
| 48 | + fi |
| 49 | + |
| 50 | + # Determine which template to use |
| 51 | + CUSTOM_TEMPLATE="/app/${PROXY_HOST}.${PROXY_PORT}.conf" |
| 52 | + DEFAULT_TEMPLATE="/app/default.conf.template" |
| 53 | + |
| 54 | + if [ -f "$CUSTOM_TEMPLATE" ]; then |
| 55 | + TEMPLATE="$CUSTOM_TEMPLATE" |
| 56 | + echo "Using custom template: $TEMPLATE" |
30 | 57 | else |
31 | | - echo "Certificate does not exist for $PROXY_DOMAIN, creating..." |
32 | | - certbot --nginx --email "[email protected]" --agree-tos --no-eff-email -d $PROXY_DOMAIN |
| 58 | + TEMPLATE="$DEFAULT_TEMPLATE" |
| 59 | + echo "Using default template: $TEMPLATE" |
33 | 60 | fi |
34 | | -fi |
35 | 61 |
|
| 62 | + # Use envsubst to produce a .conf per domain |
| 63 | + envsubst '$PROXY_DOMAIN,$PROXY_HOST,$PROXY_PORT' \ |
| 64 | + < "$TEMPLATE" \ |
| 65 | + > "/etc/nginx/conf.d/${PROXY_DOMAIN}.conf" |
| 66 | + |
| 67 | + # ------------------------- |
| 68 | + # Issue or Install SSL Cert |
| 69 | + # ------------------------- |
| 70 | + if [ "$SSL_ENABLED" = "true" ]; then |
| 71 | + |
| 72 | + # Check whether a cert exists for this domain |
| 73 | + if certbot certificates | grep -q "$PROXY_DOMAIN"; then |
| 74 | + echo "Certificate already exists for $PROXY_DOMAIN" |
| 75 | + certbot --cert-name "$PROXY_DOMAIN" install |
| 76 | + else |
| 77 | + echo "Creating certificate for $PROXY_DOMAIN..." |
| 78 | + certbot --nginx \ |
| 79 | + --email "${LETSENCRYPT_EMAIL:-contact@domain.com}" \ |
| 80 | + --agree-tos \ |
| 81 | + --no-eff-email \ |
| 82 | + -d "$PROXY_DOMAIN" |
| 83 | + fi |
| 84 | + fi |
| 85 | + |
| 86 | + if [ "$DEBUG" = "true" ]; then |
| 87 | + echo "-------------------------------------------" |
| 88 | + fi |
| 89 | +done |
| 90 | + |
| 91 | +# ------------------------- |
| 92 | +# Debug / Verification |
| 93 | +# ------------------------- |
36 | 94 | if [ "$DEBUG" = "true" ]; then |
37 | | - echo "Updated Nginx configuration:" |
38 | | - cat /etc/nginx/conf.d/default.conf |
39 | | - echo -e "\n===========================" |
| 95 | + echo "Final Nginx Config(s):" |
| 96 | + cat /etc/nginx/conf.d/*.conf |
| 97 | + echo "-------------------------------------------" |
40 | 98 |
|
41 | | - echo "Certbot log:" |
42 | | - cat /var/log/letsencrypt/letsencrypt.log |
43 | | - echo -e "\n===========================" |
| 99 | + echo "Existing certificates:" |
| 100 | + certbot certificates || true |
| 101 | + echo "-------------------------------------------" |
44 | 102 | fi |
45 | 103 |
|
46 | | -# Stop nginx if it's already running |
47 | | -nginx -s stop |
| 104 | +# Stop nginx if it's already running (ignore error if not running) |
| 105 | +nginx -s stop || true |
48 | 106 |
|
49 | | -# Start nginx |
50 | | -nginx -g "daemon off;" |
| 107 | +# Start nginx in foreground |
| 108 | +exec nginx -g "daemon off;" |
0 commit comments