#!/bin/bash git_dir="pki/${CERT_SUBDIR}" branch="100883" log_file="/var/log/letsencrypt/letsencrypt.log" #git_url="git.sdsys.ru/sdsys/pki.git" [[ -z ${GIT_URL} ]] && exit 0 function mail_send { echo "${message}"|mail -s "Attention! Certificate status!" \ -S smtp=${SMTP_SERVER} \ -S smtp-use-starttls \ -S smtp-auth=login \ -S ssl-verify=ignore \ -S smtp-auth-user=${JENKINS_MAIL_USER} \ -S smtp-auth-password=$(cat /run/secrets/jenkins-mail-pass) \ -S nss-config-dir=/etc/pki/nssdb \ -S from=${JENKINS_MAIL_USER} \ -a ${log_file} \ ${RECIPIENT_MAIL_BOX} } function git_config { cd /${git_dir} git config --global user.email "${JENKINS_MAIL_USER}" git config --global user.name "Jenkins" } function clear_log { echo -n > ${log_file} } if [ -z "$*" ]; then message="letsencrypt. No domain specified!!!"; mail_send; exit 1;fi clear_log if [ -d /${git_dir} ] then git_config && git checkout ${branch} && git pull https://${GIT_USER}:$(cat /run/secrets/provision-pass)@${GIT_URL} if [ $? -ne 0 ];then message="letsencrypt. Can't pull https://${GIT_URL}"; mail_send; exit 1;fi else cd / && git clone https://${GIT_USER}:$(cat /run/secrets/provision-pass)@${GIT_URL} && cd /${git_dir} && git checkout ${branch} if [ $? -ne 0 ];then message="letsencrypt. Can't clone https://${GIT_URL}"; mail_send; exit 1;fi fi domain=$(echo "$*" | sed 's/ / -d /g') certbot certonly --dry-run --webroot -w /var/www/html --config-dir /${git_dir}/letsencrypt -m admin@sdsys.ru -d ${domain} if [ $? -ne 0 ];then message="letsencrypt. Can't execute "dry-run" for $(echo $*). Generate cert and key will be skipped!!!"; mail_send; exit 1;fi clear_log certbot certonly --webroot -w /var/www/html --config-dir /${git_dir}/letsencrypt -m admin@sdsys.ru -d ${domain} if [ $? -ne 0 ];then message="letsencrypt. Can't generate cert and key for $(echo $*). See log !!!"; mail_send; exit 1;fi echo "Generate new key and cert for $(echo $*)" > /tmp/commit.txt git_config && git add -A && git commit -F /tmp/commit.txt git push https://${GIT_USER}:$(cat /run/secrets/provision-pass)@${GIT_URL} ${branch} if [ $? -ne 0 ];then message="letsencrypt. Can't push diff to https://${GIT_URL} !!!"; mail_send; exit 1;fi message="letsencrypt. Certs for domain $(echo $*) is generated!!!" mail_send