fix: xray (runs as nobody) couldn't read root-only letsencrypt certs for WS+TLS — copy to /etc/xray/certs with correct perms, keep it fresh via renewal hook

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
Savsis? 2026-09-11 08:23:21 +05:00
parent a8deb1fa8b
commit 36fa7d55b0
2 changed files with 28 additions and 6 deletions

View file

@ -156,9 +156,22 @@ retry certbot certonly --webroot -w "$WEBROOT" --non-interactive --agree-tos \
retry certbot certonly --webroot -w "$WEBROOT" --non-interactive --agree-tos \ retry certbot certonly --webroot -w "$WEBROOT" --non-interactive --agree-tos \
--register-unsafely-without-email -d "$DE1_ADDRESS" --register-unsafely-without-email -d "$DE1_ADDRESS"
echo "готовлю серт для xray (он не root, letsencrypt/live ему не почитать)..."
mkdir -p /etc/xray/certs
cp "/etc/letsencrypt/live/$DE1_ADDRESS/fullchain.pem" /etc/xray/certs/de1.crt
cp "/etc/letsencrypt/live/$DE1_ADDRESS/privkey.pem" /etc/xray/certs/de1.key
chmod 644 /etc/xray/certs/de1.crt /etc/xray/certs/de1.key
chown nobody:nogroup /etc/xray/certs/de1.crt /etc/xray/certs/de1.key
mkdir -p /etc/letsencrypt/renewal-hooks/deploy mkdir -p /etc/letsencrypt/renewal-hooks/deploy
cat > /etc/letsencrypt/renewal-hooks/deploy/mbs-reload.sh << 'HOOKEOF' cat > /etc/letsencrypt/renewal-hooks/deploy/mbs-reload.sh << HOOKEOF
#!/bin/bash #!/bin/bash
if [ -d "/etc/letsencrypt/live/$DE1_ADDRESS" ]; then
cp "/etc/letsencrypt/live/$DE1_ADDRESS/fullchain.pem" /etc/xray/certs/de1.crt
cp "/etc/letsencrypt/live/$DE1_ADDRESS/privkey.pem" /etc/xray/certs/de1.key
chmod 644 /etc/xray/certs/de1.crt /etc/xray/certs/de1.key
chown nobody:nogroup /etc/xray/certs/de1.crt /etc/xray/certs/de1.key
fi
systemctl reload nginx || true systemctl reload nginx || true
systemctl restart xray || true systemctl restart xray || true
HOOKEOF HOOKEOF
@ -343,8 +356,8 @@ cat > /usr/local/etc/xray/config.json << XRAYEOF
"wsSettings": { "path": "/mbs-ws" }, "wsSettings": { "path": "/mbs-ws" },
"tlsSettings": { "tlsSettings": {
"certificates": [{ "certificates": [{
"certificateFile": "/etc/letsencrypt/live/$DE1_ADDRESS/fullchain.pem", "certificateFile": "/etc/xray/certs/de1.crt",
"keyFile": "/etc/letsencrypt/live/$DE1_ADDRESS/privkey.pem" "keyFile": "/etc/xray/certs/de1.key"
}] }]
} }
} }

View file

@ -17,9 +17,18 @@ CERTBOT_SNIPPET = """echo "issuing a real TLS cert for {address} (needed for WS+
command -v certbot >/dev/null 2>&1 || apt-get install -y certbot command -v certbot >/dev/null 2>&1 || apt-get install -y certbot
ss -ltnp | grep -q ':80 ' && {{ echo "something is already on port 80, stop it first"; exit 1; }} ss -ltnp | grep -q ':80 ' && {{ echo "something is already on port 80, stop it first"; exit 1; }}
certbot certonly --standalone --non-interactive --agree-tos --register-unsafely-without-email -d {address} certbot certonly --standalone --non-interactive --agree-tos --register-unsafely-without-email -d {address}
mkdir -p /etc/xray/certs
cp /etc/letsencrypt/live/{address}/fullchain.pem /etc/xray/certs/node.crt
cp /etc/letsencrypt/live/{address}/privkey.pem /etc/xray/certs/node.key
chmod 644 /etc/xray/certs/node.crt /etc/xray/certs/node.key
chown nobody:nogroup /etc/xray/certs/node.crt /etc/xray/certs/node.key
mkdir -p /etc/letsencrypt/renewal-hooks/deploy mkdir -p /etc/letsencrypt/renewal-hooks/deploy
cat > /etc/letsencrypt/renewal-hooks/deploy/mbs-restart-xray.sh << 'HOOK' cat > /etc/letsencrypt/renewal-hooks/deploy/mbs-restart-xray.sh << HOOK
#!/bin/bash #!/bin/bash
cp /etc/letsencrypt/live/{address}/fullchain.pem /etc/xray/certs/node.crt
cp /etc/letsencrypt/live/{address}/privkey.pem /etc/xray/certs/node.key
chmod 644 /etc/xray/certs/node.crt /etc/xray/certs/node.key
chown nobody:nogroup /etc/xray/certs/node.crt /etc/xray/certs/node.key
systemctl restart xray || true systemctl restart xray || true
HOOK HOOK
chmod +x /etc/letsencrypt/renewal-hooks/deploy/mbs-restart-xray.sh chmod +x /etc/letsencrypt/renewal-hooks/deploy/mbs-restart-xray.sh
@ -185,8 +194,8 @@ def _build_config_json(transports, private_key, address):
elif t["security"] == "tls": elif t["security"] == "tls":
ib["streamSettings"] = {"network": "ws", "security": "tls", "wsSettings": {"path": t["path"]}, ib["streamSettings"] = {"network": "ws", "security": "tls", "wsSettings": {"path": t["path"]},
"tlsSettings": {"certificates": [{ "tlsSettings": {"certificates": [{
"certificateFile": f"/etc/letsencrypt/live/{address}/fullchain.pem", "certificateFile": "/etc/xray/certs/node.crt",
"keyFile": f"/etc/letsencrypt/live/{address}/privkey.pem", "keyFile": "/etc/xray/certs/node.key",
}]}} }]}}
inbounds.append(ib) inbounds.append(ib)