generate.sh 2.4 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162
  1. #!/bin/bash
  2. git_dir="pki"
  3. branch="100883"
  4. log_file="/var/log/letsencrypt/letsencrypt.log"
  5. #git_url="git.sdsys.ru/sdsys/pki.git"
  6. [[ -z ${GIT_URL} ]] && exit 0
  7. function mail_send {
  8. echo "${message}"|mail -s "Attention! Certificate status!" \
  9. -S smtp=${SMTP_SERVER} \
  10. -S smtp-use-starttls \
  11. -S smtp-auth=login \
  12. -S ssl-verify=ignore \
  13. -S smtp-auth-user=${JENKINS_MAIL_USER} \
  14. -S smtp-auth-password=$(cat /run/secrets/jenkins-mail-pass) \
  15. -S nss-config-dir=/etc/pki/nssdb \
  16. -S from=${JENKINS_MAIL_USER} \
  17. -a ${log_file} \
  18. ${RECIPIENT_MAIL_BOX}
  19. }
  20. function git_config {
  21. cd /${git_dir}
  22. git config --global user.email "${JENKINS_MAIL_USER}"
  23. git config --global user.name "Jenkins"
  24. }
  25. function clear_log {
  26. echo -n > ${log_file}
  27. }
  28. if [ -z "$*" ]; then message="letsencrypt. No domain specified!!!"; mail_send; exit 1;fi
  29. clear_log
  30. if [ -d /${git_dir} ]
  31. then
  32. git_config && git checkout ${branch} && git pull https://${GIT_USER}:$(cat /run/secrets/provision-pass)@${GIT_URL}
  33. if [ $? -ne 0 ];then message="letsencrypt. Can't pull https://${GIT_URL}"; mail_send; exit 1;fi
  34. else
  35. cd / && git clone https://${GIT_USER}:$(cat /run/secrets/provision-pass)@${GIT_URL} && cd /${git_dir} && git checkout ${branch}
  36. if [ $? -ne 0 ];then message="letsencrypt. Can't clone https://${GIT_URL}"; mail_send; exit 1;fi
  37. fi
  38. domain=$(echo "$*" | sed 's/ / -d /g')
  39. certbot certonly --dry-run --webroot -w /var/www/html --config-dir /${git_dir}/letsencrypt -m admin@sdsys.ru -d ${domain}
  40. if [ $? -ne 0 ];then message="letsencrypt. Can't execute "dry-run" for $(echo $*). Generate cert and key will be skipped!!!"; mail_send; exit 1;fi
  41. clear_log
  42. certbot certonly --webroot -w /var/www/html --config-dir /${git_dir}/letsencrypt -m admin@sdsys.ru -d ${domain}
  43. if [ $? -ne 0 ];then message="letsencrypt. Can't generate cert and key for $(echo $*). See log !!!"; mail_send; exit 1;fi
  44. echo "Generate new key and cert for $(echo $*)" > /tmp/commit.txt
  45. git_config && git add -A && git commit -F /tmp/commit.txt
  46. git push https://${GIT_USER}:$(cat /run/secrets/provision-pass)@${GIT_URL} ${branch}
  47. if [ $? -ne 0 ];then message="letsencrypt. Can't push diff to https://${GIT_URL} !!!"; mail_send; exit 1;fi
  48. message="letsencrypt. Certs for domain $(echo $*) is generated!!!"
  49. mail_send