fix: xray (runs as nobody) couldn't read root-only letsencrypt certs for WS+TLS — copy to /etc/xray/certs with correct perms, keep it fresh via renewal hook
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
parent
a8deb1fa8b
commit
36fa7d55b0
2 changed files with 28 additions and 6 deletions
19
install.sh
19
install.sh
|
|
@ -156,9 +156,22 @@ retry certbot certonly --webroot -w "$WEBROOT" --non-interactive --agree-tos \
|
||||||
retry certbot certonly --webroot -w "$WEBROOT" --non-interactive --agree-tos \
|
retry certbot certonly --webroot -w "$WEBROOT" --non-interactive --agree-tos \
|
||||||
--register-unsafely-without-email -d "$DE1_ADDRESS"
|
--register-unsafely-without-email -d "$DE1_ADDRESS"
|
||||||
|
|
||||||
|
echo "готовлю серт для xray (он не root, letsencrypt/live ему не почитать)..."
|
||||||
|
mkdir -p /etc/xray/certs
|
||||||
|
cp "/etc/letsencrypt/live/$DE1_ADDRESS/fullchain.pem" /etc/xray/certs/de1.crt
|
||||||
|
cp "/etc/letsencrypt/live/$DE1_ADDRESS/privkey.pem" /etc/xray/certs/de1.key
|
||||||
|
chmod 644 /etc/xray/certs/de1.crt /etc/xray/certs/de1.key
|
||||||
|
chown nobody:nogroup /etc/xray/certs/de1.crt /etc/xray/certs/de1.key
|
||||||
|
|
||||||
mkdir -p /etc/letsencrypt/renewal-hooks/deploy
|
mkdir -p /etc/letsencrypt/renewal-hooks/deploy
|
||||||
cat > /etc/letsencrypt/renewal-hooks/deploy/mbs-reload.sh << 'HOOKEOF'
|
cat > /etc/letsencrypt/renewal-hooks/deploy/mbs-reload.sh << HOOKEOF
|
||||||
#!/bin/bash
|
#!/bin/bash
|
||||||
|
if [ -d "/etc/letsencrypt/live/$DE1_ADDRESS" ]; then
|
||||||
|
cp "/etc/letsencrypt/live/$DE1_ADDRESS/fullchain.pem" /etc/xray/certs/de1.crt
|
||||||
|
cp "/etc/letsencrypt/live/$DE1_ADDRESS/privkey.pem" /etc/xray/certs/de1.key
|
||||||
|
chmod 644 /etc/xray/certs/de1.crt /etc/xray/certs/de1.key
|
||||||
|
chown nobody:nogroup /etc/xray/certs/de1.crt /etc/xray/certs/de1.key
|
||||||
|
fi
|
||||||
systemctl reload nginx || true
|
systemctl reload nginx || true
|
||||||
systemctl restart xray || true
|
systemctl restart xray || true
|
||||||
HOOKEOF
|
HOOKEOF
|
||||||
|
|
@ -343,8 +356,8 @@ cat > /usr/local/etc/xray/config.json << XRAYEOF
|
||||||
"wsSettings": { "path": "/mbs-ws" },
|
"wsSettings": { "path": "/mbs-ws" },
|
||||||
"tlsSettings": {
|
"tlsSettings": {
|
||||||
"certificates": [{
|
"certificates": [{
|
||||||
"certificateFile": "/etc/letsencrypt/live/$DE1_ADDRESS/fullchain.pem",
|
"certificateFile": "/etc/xray/certs/de1.crt",
|
||||||
"keyFile": "/etc/letsencrypt/live/$DE1_ADDRESS/privkey.pem"
|
"keyFile": "/etc/xray/certs/de1.key"
|
||||||
}]
|
}]
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
|
||||||
15
nodeprov.py
15
nodeprov.py
|
|
@ -17,9 +17,18 @@ CERTBOT_SNIPPET = """echo "issuing a real TLS cert for {address} (needed for WS+
|
||||||
command -v certbot >/dev/null 2>&1 || apt-get install -y certbot
|
command -v certbot >/dev/null 2>&1 || apt-get install -y certbot
|
||||||
ss -ltnp | grep -q ':80 ' && {{ echo "something is already on port 80, stop it first"; exit 1; }}
|
ss -ltnp | grep -q ':80 ' && {{ echo "something is already on port 80, stop it first"; exit 1; }}
|
||||||
certbot certonly --standalone --non-interactive --agree-tos --register-unsafely-without-email -d {address}
|
certbot certonly --standalone --non-interactive --agree-tos --register-unsafely-without-email -d {address}
|
||||||
|
mkdir -p /etc/xray/certs
|
||||||
|
cp /etc/letsencrypt/live/{address}/fullchain.pem /etc/xray/certs/node.crt
|
||||||
|
cp /etc/letsencrypt/live/{address}/privkey.pem /etc/xray/certs/node.key
|
||||||
|
chmod 644 /etc/xray/certs/node.crt /etc/xray/certs/node.key
|
||||||
|
chown nobody:nogroup /etc/xray/certs/node.crt /etc/xray/certs/node.key
|
||||||
mkdir -p /etc/letsencrypt/renewal-hooks/deploy
|
mkdir -p /etc/letsencrypt/renewal-hooks/deploy
|
||||||
cat > /etc/letsencrypt/renewal-hooks/deploy/mbs-restart-xray.sh << 'HOOK'
|
cat > /etc/letsencrypt/renewal-hooks/deploy/mbs-restart-xray.sh << HOOK
|
||||||
#!/bin/bash
|
#!/bin/bash
|
||||||
|
cp /etc/letsencrypt/live/{address}/fullchain.pem /etc/xray/certs/node.crt
|
||||||
|
cp /etc/letsencrypt/live/{address}/privkey.pem /etc/xray/certs/node.key
|
||||||
|
chmod 644 /etc/xray/certs/node.crt /etc/xray/certs/node.key
|
||||||
|
chown nobody:nogroup /etc/xray/certs/node.crt /etc/xray/certs/node.key
|
||||||
systemctl restart xray || true
|
systemctl restart xray || true
|
||||||
HOOK
|
HOOK
|
||||||
chmod +x /etc/letsencrypt/renewal-hooks/deploy/mbs-restart-xray.sh
|
chmod +x /etc/letsencrypt/renewal-hooks/deploy/mbs-restart-xray.sh
|
||||||
|
|
@ -185,8 +194,8 @@ def _build_config_json(transports, private_key, address):
|
||||||
elif t["security"] == "tls":
|
elif t["security"] == "tls":
|
||||||
ib["streamSettings"] = {"network": "ws", "security": "tls", "wsSettings": {"path": t["path"]},
|
ib["streamSettings"] = {"network": "ws", "security": "tls", "wsSettings": {"path": t["path"]},
|
||||||
"tlsSettings": {"certificates": [{
|
"tlsSettings": {"certificates": [{
|
||||||
"certificateFile": f"/etc/letsencrypt/live/{address}/fullchain.pem",
|
"certificateFile": "/etc/xray/certs/node.crt",
|
||||||
"keyFile": f"/etc/letsencrypt/live/{address}/privkey.pem",
|
"keyFile": "/etc/xray/certs/node.key",
|
||||||
}]}}
|
}]}}
|
||||||
inbounds.append(ib)
|
inbounds.append(ib)
|
||||||
|
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue