Re-provision storefront nginx when domain host is renamed.

Also create origin HTTPS with a self-signed cert on provision so Cloudflare Full does not fall through to another site's default SSL vhost.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
Alireza Hassani
2026-08-26 17:31:56 +03:30
co-authored by Cursor
parent cbe7aced6d
commit 5850c90d84
2 changed files with 49 additions and 15 deletions
+37 -7
View File
@@ -115,13 +115,21 @@ NODE
echo "using port $PORT for $SLUG"
if [[ ! -f "$NGINX_AVAILABLE" ]]; then
cat >"$NGINX_AVAILABLE" <<NGINX
server {
listen 80;
listen [::]:80;
server_name ${HOST} www.${HOST};
# Origin TLS so Cloudflare Full / direct HTTPS hit this vhost (not another site's default_server).
# Certbot / Cloudflare Origin CA can replace these files later.
SSL_DIR="/etc/nginx/ssl/$HOST"
mkdir -p "$SSL_DIR"
if [[ ! -f "$SSL_DIR/fullchain.pem" || ! -f "$SSL_DIR/privkey.pem" ]]; then
openssl req -x509 -nodes -newkey rsa:2048 -days 825 \
-keyout "$SSL_DIR/privkey.pem" \
-out "$SSL_DIR/fullchain.pem" \
-subj "/CN=$HOST" \
-addext "subjectAltName=DNS:$HOST,DNS:www.$HOST" \
>/dev/null 2>&1
echo "origin self-signed cert created: $SSL_DIR"
fi
PROXY_COMMON=$(cat <<PROXY
location = /sitemap.xml {
proxy_pass https://api.meshkee.com/api/v1/tenants/${HOST}/sitemap.xml;
proxy_set_header Host api.meshkee.com;
@@ -195,12 +203,34 @@ server {
proxy_set_header X-Forwarded-Proto \$scheme;
proxy_cache_bypass \$http_upgrade;
}
PROXY
)
if [[ ! -f "$NGINX_AVAILABLE" ]]; then
cat >"$NGINX_AVAILABLE" <<NGINX
server {
listen 80;
listen [::]:80;
server_name ${HOST} www.${HOST};
${PROXY_COMMON}
}
server {
listen 443 ssl;
listen [::]:443 ssl;
server_name ${HOST} www.${HOST};
ssl_certificate ${SSL_DIR}/fullchain.pem;
ssl_certificate_key ${SSL_DIR}/privkey.pem;
${PROXY_COMMON}
}
NGINX
ln -sfn "$NGINX_AVAILABLE" "$NGINX_ENABLED"
nginx -t
systemctl reload nginx
echo "nginx site created for $HOST → :$PORT"
echo "nginx site created for $HOST → :$PORT (http+https)"
else
echo "nginx site already exists: $NGINX_AVAILABLE"
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"