Re-provision storefront nginx when domain host is renamed.
Also create origin HTTPS with a self-signed cert on provision so Cloudflare Full does not fall through to another site's default SSL vhost. Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
co-authored by
Cursor
parent
cbe7aced6d
commit
5850c90d84
@@ -115,13 +115,21 @@ NODE
|
||||
|
||||
echo "using port $PORT for $SLUG"
|
||||
|
||||
if [[ ! -f "$NGINX_AVAILABLE" ]]; then
|
||||
cat >"$NGINX_AVAILABLE" <<NGINX
|
||||
server {
|
||||
listen 80;
|
||||
listen [::]:80;
|
||||
server_name ${HOST} www.${HOST};
|
||||
# Origin TLS so Cloudflare Full / direct HTTPS hit this vhost (not another site's default_server).
|
||||
# Certbot / Cloudflare Origin CA can replace these files later.
|
||||
SSL_DIR="/etc/nginx/ssl/$HOST"
|
||||
mkdir -p "$SSL_DIR"
|
||||
if [[ ! -f "$SSL_DIR/fullchain.pem" || ! -f "$SSL_DIR/privkey.pem" ]]; then
|
||||
openssl req -x509 -nodes -newkey rsa:2048 -days 825 \
|
||||
-keyout "$SSL_DIR/privkey.pem" \
|
||||
-out "$SSL_DIR/fullchain.pem" \
|
||||
-subj "/CN=$HOST" \
|
||||
-addext "subjectAltName=DNS:$HOST,DNS:www.$HOST" \
|
||||
>/dev/null 2>&1
|
||||
echo "origin self-signed cert created: $SSL_DIR"
|
||||
fi
|
||||
|
||||
PROXY_COMMON=$(cat <<PROXY
|
||||
location = /sitemap.xml {
|
||||
proxy_pass https://api.meshkee.com/api/v1/tenants/${HOST}/sitemap.xml;
|
||||
proxy_set_header Host api.meshkee.com;
|
||||
@@ -195,12 +203,34 @@ server {
|
||||
proxy_set_header X-Forwarded-Proto \$scheme;
|
||||
proxy_cache_bypass \$http_upgrade;
|
||||
}
|
||||
PROXY
|
||||
)
|
||||
|
||||
if [[ ! -f "$NGINX_AVAILABLE" ]]; then
|
||||
cat >"$NGINX_AVAILABLE" <<NGINX
|
||||
server {
|
||||
listen 80;
|
||||
listen [::]:80;
|
||||
server_name ${HOST} www.${HOST};
|
||||
|
||||
${PROXY_COMMON}
|
||||
}
|
||||
|
||||
server {
|
||||
listen 443 ssl;
|
||||
listen [::]:443 ssl;
|
||||
server_name ${HOST} www.${HOST};
|
||||
|
||||
ssl_certificate ${SSL_DIR}/fullchain.pem;
|
||||
ssl_certificate_key ${SSL_DIR}/privkey.pem;
|
||||
|
||||
${PROXY_COMMON}
|
||||
}
|
||||
NGINX
|
||||
ln -sfn "$NGINX_AVAILABLE" "$NGINX_ENABLED"
|
||||
nginx -t
|
||||
systemctl reload nginx
|
||||
echo "nginx site created for $HOST → :$PORT"
|
||||
echo "nginx site created for $HOST → :$PORT (http+https)"
|
||||
else
|
||||
echo "nginx site already exists: $NGINX_AVAILABLE"
|
||||
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
||||
|
||||
Reference in New Issue
Block a user