From 36fa7d55b06c7d6f095a1f38e5a4fd3956040624 Mon Sep 17 00:00:00 2001 From: savsis Date: Fri, 11 Sep 2026 08:23:21 +0500 Subject: [PATCH] =?UTF-8?q?fix:=20xray=20(runs=20as=20nobody)=20couldn't?= =?UTF-8?q?=20read=20root-only=20letsencrypt=20certs=20for=20WS+TLS=20?= =?UTF-8?q?=E2=80=94=20copy=20to=20/etc/xray/certs=20with=20correct=20perm?= =?UTF-8?q?s,=20keep=20it=20fresh=20via=20renewal=20hook?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Co-Authored-By: Claude Sonnet 5 --- install.sh | 19 ++++++++++++++++--- nodeprov.py | 15 ++++++++++++--- 2 files changed, 28 insertions(+), 6 deletions(-) diff --git a/install.sh b/install.sh index 0ca70d0..0d3ff79 100644 --- a/install.sh +++ b/install.sh @@ -156,9 +156,22 @@ retry certbot certonly --webroot -w "$WEBROOT" --non-interactive --agree-tos \ retry certbot certonly --webroot -w "$WEBROOT" --non-interactive --agree-tos \ --register-unsafely-without-email -d "$DE1_ADDRESS" +echo "готовлю серт для xray (он не root, letsencrypt/live ему не почитать)..." +mkdir -p /etc/xray/certs +cp "/etc/letsencrypt/live/$DE1_ADDRESS/fullchain.pem" /etc/xray/certs/de1.crt +cp "/etc/letsencrypt/live/$DE1_ADDRESS/privkey.pem" /etc/xray/certs/de1.key +chmod 644 /etc/xray/certs/de1.crt /etc/xray/certs/de1.key +chown nobody:nogroup /etc/xray/certs/de1.crt /etc/xray/certs/de1.key + mkdir -p /etc/letsencrypt/renewal-hooks/deploy -cat > /etc/letsencrypt/renewal-hooks/deploy/mbs-reload.sh << 'HOOKEOF' +cat > /etc/letsencrypt/renewal-hooks/deploy/mbs-reload.sh << HOOKEOF #!/bin/bash +if [ -d "/etc/letsencrypt/live/$DE1_ADDRESS" ]; then + cp "/etc/letsencrypt/live/$DE1_ADDRESS/fullchain.pem" /etc/xray/certs/de1.crt + cp "/etc/letsencrypt/live/$DE1_ADDRESS/privkey.pem" /etc/xray/certs/de1.key + chmod 644 /etc/xray/certs/de1.crt /etc/xray/certs/de1.key + chown nobody:nogroup /etc/xray/certs/de1.crt /etc/xray/certs/de1.key +fi systemctl reload nginx || true systemctl restart xray || true HOOKEOF @@ -343,8 +356,8 @@ cat > /usr/local/etc/xray/config.json << XRAYEOF "wsSettings": { "path": "/mbs-ws" }, "tlsSettings": { "certificates": [{ - "certificateFile": "/etc/letsencrypt/live/$DE1_ADDRESS/fullchain.pem", - "keyFile": "/etc/letsencrypt/live/$DE1_ADDRESS/privkey.pem" + "certificateFile": "/etc/xray/certs/de1.crt", + "keyFile": "/etc/xray/certs/de1.key" }] } } diff --git a/nodeprov.py b/nodeprov.py index fdf8e50..32f547b 100644 --- a/nodeprov.py +++ b/nodeprov.py @@ -17,9 +17,18 @@ CERTBOT_SNIPPET = """echo "issuing a real TLS cert for {address} (needed for WS+ command -v certbot >/dev/null 2>&1 || apt-get install -y certbot ss -ltnp | grep -q ':80 ' && {{ echo "something is already on port 80, stop it first"; exit 1; }} certbot certonly --standalone --non-interactive --agree-tos --register-unsafely-without-email -d {address} +mkdir -p /etc/xray/certs +cp /etc/letsencrypt/live/{address}/fullchain.pem /etc/xray/certs/node.crt +cp /etc/letsencrypt/live/{address}/privkey.pem /etc/xray/certs/node.key +chmod 644 /etc/xray/certs/node.crt /etc/xray/certs/node.key +chown nobody:nogroup /etc/xray/certs/node.crt /etc/xray/certs/node.key mkdir -p /etc/letsencrypt/renewal-hooks/deploy -cat > /etc/letsencrypt/renewal-hooks/deploy/mbs-restart-xray.sh << 'HOOK' +cat > /etc/letsencrypt/renewal-hooks/deploy/mbs-restart-xray.sh << HOOK #!/bin/bash +cp /etc/letsencrypt/live/{address}/fullchain.pem /etc/xray/certs/node.crt +cp /etc/letsencrypt/live/{address}/privkey.pem /etc/xray/certs/node.key +chmod 644 /etc/xray/certs/node.crt /etc/xray/certs/node.key +chown nobody:nogroup /etc/xray/certs/node.crt /etc/xray/certs/node.key systemctl restart xray || true HOOK chmod +x /etc/letsencrypt/renewal-hooks/deploy/mbs-restart-xray.sh @@ -185,8 +194,8 @@ def _build_config_json(transports, private_key, address): elif t["security"] == "tls": ib["streamSettings"] = {"network": "ws", "security": "tls", "wsSettings": {"path": t["path"]}, "tlsSettings": {"certificates": [{ - "certificateFile": f"/etc/letsencrypt/live/{address}/fullchain.pem", - "keyFile": f"/etc/letsencrypt/live/{address}/privkey.pem", + "certificateFile": "/etc/xray/certs/node.crt", + "keyFile": "/etc/xray/certs/node.key", }]}} inbounds.append(ib)