Re-provision storefront nginx when domain host is renamed.

Also create origin HTTPS with a self-signed cert on provision so Cloudflare Full does not fall through to another site's default SSL vhost.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
Alireza Hassani
2026-08-26 17:31:56 +03:30
co-authored by Cursor
parent cbe7aced6d
commit 5850c90d84
2 changed files with 49 additions and 15 deletions
+37 -7
View File
@@ -115,13 +115,21 @@ NODE
echo "using port $PORT for $SLUG"
if [[ ! -f "$NGINX_AVAILABLE" ]]; then
cat >"$NGINX_AVAILABLE" <<NGINX
server {
listen 80;
listen [::]:80;
server_name ${HOST} www.${HOST};
# Origin TLS so Cloudflare Full / direct HTTPS hit this vhost (not another site's default_server).
# Certbot / Cloudflare Origin CA can replace these files later.
SSL_DIR="/etc/nginx/ssl/$HOST"
mkdir -p "$SSL_DIR"
if [[ ! -f "$SSL_DIR/fullchain.pem" || ! -f "$SSL_DIR/privkey.pem" ]]; then
openssl req -x509 -nodes -newkey rsa:2048 -days 825 \
-keyout "$SSL_DIR/privkey.pem" \
-out "$SSL_DIR/fullchain.pem" \
-subj "/CN=$HOST" \
-addext "subjectAltName=DNS:$HOST,DNS:www.$HOST" \
>/dev/null 2>&1
echo "origin self-signed cert created: $SSL_DIR"
fi
PROXY_COMMON=$(cat <<PROXY
location = /sitemap.xml {
proxy_pass https://api.meshkee.com/api/v1/tenants/${HOST}/sitemap.xml;
proxy_set_header Host api.meshkee.com;
@@ -195,12 +203,34 @@ server {
proxy_set_header X-Forwarded-Proto \$scheme;
proxy_cache_bypass \$http_upgrade;
}
PROXY
)
if [[ ! -f "$NGINX_AVAILABLE" ]]; then
cat >"$NGINX_AVAILABLE" <<NGINX
server {
listen 80;
listen [::]:80;
server_name ${HOST} www.${HOST};
${PROXY_COMMON}
}
server {
listen 443 ssl;
listen [::]:443 ssl;
server_name ${HOST} www.${HOST};
ssl_certificate ${SSL_DIR}/fullchain.pem;
ssl_certificate_key ${SSL_DIR}/privkey.pem;
${PROXY_COMMON}
}
NGINX
ln -sfn "$NGINX_AVAILABLE" "$NGINX_ENABLED"
nginx -t
systemctl reload nginx
echo "nginx site created for $HOST → :$PORT"
echo "nginx site created for $HOST → :$PORT (http+https)"
else
echo "nginx site already exists: $NGINX_AVAILABLE"
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
+12 -8
View File
@@ -619,15 +619,19 @@ export class BusinessAdminService {
let deploySlug = domain.deploySlug;
let provisionError: string | null = null;
let nextGitRepoUrl = domain.gitRepoUrl;
const hostChanged = domain.host !== host;
const effectiveGitRepoUrl = gitRepoUrl || domain.gitRepoUrl?.trim() || null;
// Only provision when wiring a new/changed repo or when deploy slug is missing.
// Re-saving the same git URL must not block the API on clone/nginx/certbot again.
// Only provision when wiring a new/changed repo, deploy slug is missing, or
// the apex host changed (nginx vhost is keyed by host — rename must bind the new name).
// Re-saving the same git URL + same host must not block the API on clone again.
const alreadyWired =
!!gitRepoUrl &&
!!effectiveGitRepoUrl &&
!!domain.deploySlug?.trim() &&
domain.gitRepoUrl?.trim() === gitRepoUrl;
(!gitRepoUrl || domain.gitRepoUrl?.trim() === gitRepoUrl) &&
!hostChanged;
if (gitRepoUrl && !alreadyWired) {
if (effectiveGitRepoUrl && !alreadyWired) {
const slug = domain.deploySlug?.trim() || deploySlugFromHost(host);
if (!slug) {
throw new BadRequestException('Could not derive deploy slug from host');
@@ -645,10 +649,10 @@ export class BusinessAdminService {
await this.websiteDeployAgent.provision({
slug,
host,
gitRepoUrl: normalizeGitRepoUrlForClone(gitRepoUrl),
gitRepoUrl: normalizeGitRepoUrlForClone(effectiveGitRepoUrl),
});
deploySlug = slug;
nextGitRepoUrl = gitRepoUrl;
nextGitRepoUrl = effectiveGitRepoUrl;
} catch (err) {
if (err && typeof err === 'object' && 'message' in err && typeof err.message === 'string') {
provisionError = err.message;
@@ -658,7 +662,7 @@ export class BusinessAdminService {
}
} else if (alreadyWired) {
deploySlug = domain.deploySlug;
nextGitRepoUrl = gitRepoUrl;
nextGitRepoUrl = effectiveGitRepoUrl;
}
const updated = await this.prisma.domain.update({