Re-provision storefront nginx when domain host is renamed.
Also create origin HTTPS with a self-signed cert on provision so Cloudflare Full does not fall through to another site's default SSL vhost. Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
co-authored by
Cursor
parent
cbe7aced6d
commit
5850c90d84
@@ -115,13 +115,21 @@ NODE
|
||||
|
||||
echo "using port $PORT for $SLUG"
|
||||
|
||||
if [[ ! -f "$NGINX_AVAILABLE" ]]; then
|
||||
cat >"$NGINX_AVAILABLE" <<NGINX
|
||||
server {
|
||||
listen 80;
|
||||
listen [::]:80;
|
||||
server_name ${HOST} www.${HOST};
|
||||
# Origin TLS so Cloudflare Full / direct HTTPS hit this vhost (not another site's default_server).
|
||||
# Certbot / Cloudflare Origin CA can replace these files later.
|
||||
SSL_DIR="/etc/nginx/ssl/$HOST"
|
||||
mkdir -p "$SSL_DIR"
|
||||
if [[ ! -f "$SSL_DIR/fullchain.pem" || ! -f "$SSL_DIR/privkey.pem" ]]; then
|
||||
openssl req -x509 -nodes -newkey rsa:2048 -days 825 \
|
||||
-keyout "$SSL_DIR/privkey.pem" \
|
||||
-out "$SSL_DIR/fullchain.pem" \
|
||||
-subj "/CN=$HOST" \
|
||||
-addext "subjectAltName=DNS:$HOST,DNS:www.$HOST" \
|
||||
>/dev/null 2>&1
|
||||
echo "origin self-signed cert created: $SSL_DIR"
|
||||
fi
|
||||
|
||||
PROXY_COMMON=$(cat <<PROXY
|
||||
location = /sitemap.xml {
|
||||
proxy_pass https://api.meshkee.com/api/v1/tenants/${HOST}/sitemap.xml;
|
||||
proxy_set_header Host api.meshkee.com;
|
||||
@@ -195,12 +203,34 @@ server {
|
||||
proxy_set_header X-Forwarded-Proto \$scheme;
|
||||
proxy_cache_bypass \$http_upgrade;
|
||||
}
|
||||
PROXY
|
||||
)
|
||||
|
||||
if [[ ! -f "$NGINX_AVAILABLE" ]]; then
|
||||
cat >"$NGINX_AVAILABLE" <<NGINX
|
||||
server {
|
||||
listen 80;
|
||||
listen [::]:80;
|
||||
server_name ${HOST} www.${HOST};
|
||||
|
||||
${PROXY_COMMON}
|
||||
}
|
||||
|
||||
server {
|
||||
listen 443 ssl;
|
||||
listen [::]:443 ssl;
|
||||
server_name ${HOST} www.${HOST};
|
||||
|
||||
ssl_certificate ${SSL_DIR}/fullchain.pem;
|
||||
ssl_certificate_key ${SSL_DIR}/privkey.pem;
|
||||
|
||||
${PROXY_COMMON}
|
||||
}
|
||||
NGINX
|
||||
ln -sfn "$NGINX_AVAILABLE" "$NGINX_ENABLED"
|
||||
nginx -t
|
||||
systemctl reload nginx
|
||||
echo "nginx site created for $HOST → :$PORT"
|
||||
echo "nginx site created for $HOST → :$PORT (http+https)"
|
||||
else
|
||||
echo "nginx site already exists: $NGINX_AVAILABLE"
|
||||
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
||||
|
||||
@@ -619,15 +619,19 @@ export class BusinessAdminService {
|
||||
let deploySlug = domain.deploySlug;
|
||||
let provisionError: string | null = null;
|
||||
let nextGitRepoUrl = domain.gitRepoUrl;
|
||||
const hostChanged = domain.host !== host;
|
||||
const effectiveGitRepoUrl = gitRepoUrl || domain.gitRepoUrl?.trim() || null;
|
||||
|
||||
// Only provision when wiring a new/changed repo or when deploy slug is missing.
|
||||
// Re-saving the same git URL must not block the API on clone/nginx/certbot again.
|
||||
// Only provision when wiring a new/changed repo, deploy slug is missing, or
|
||||
// the apex host changed (nginx vhost is keyed by host — rename must bind the new name).
|
||||
// Re-saving the same git URL + same host must not block the API on clone again.
|
||||
const alreadyWired =
|
||||
!!gitRepoUrl &&
|
||||
!!effectiveGitRepoUrl &&
|
||||
!!domain.deploySlug?.trim() &&
|
||||
domain.gitRepoUrl?.trim() === gitRepoUrl;
|
||||
(!gitRepoUrl || domain.gitRepoUrl?.trim() === gitRepoUrl) &&
|
||||
!hostChanged;
|
||||
|
||||
if (gitRepoUrl && !alreadyWired) {
|
||||
if (effectiveGitRepoUrl && !alreadyWired) {
|
||||
const slug = domain.deploySlug?.trim() || deploySlugFromHost(host);
|
||||
if (!slug) {
|
||||
throw new BadRequestException('Could not derive deploy slug from host');
|
||||
@@ -645,10 +649,10 @@ export class BusinessAdminService {
|
||||
await this.websiteDeployAgent.provision({
|
||||
slug,
|
||||
host,
|
||||
gitRepoUrl: normalizeGitRepoUrlForClone(gitRepoUrl),
|
||||
gitRepoUrl: normalizeGitRepoUrlForClone(effectiveGitRepoUrl),
|
||||
});
|
||||
deploySlug = slug;
|
||||
nextGitRepoUrl = gitRepoUrl;
|
||||
nextGitRepoUrl = effectiveGitRepoUrl;
|
||||
} catch (err) {
|
||||
if (err && typeof err === 'object' && 'message' in err && typeof err.message === 'string') {
|
||||
provisionError = err.message;
|
||||
@@ -658,7 +662,7 @@ export class BusinessAdminService {
|
||||
}
|
||||
} else if (alreadyWired) {
|
||||
deploySlug = domain.deploySlug;
|
||||
nextGitRepoUrl = gitRepoUrl;
|
||||
nextGitRepoUrl = effectiveGitRepoUrl;
|
||||
}
|
||||
|
||||
const updated = await this.prisma.domain.update({
|
||||
|
||||
Reference in New Issue
Block a user