jina verze
This commit is contained in:
@@ -1,4 +1,4 @@
|
||||
# KUBE 7.1.553
|
||||
# KUBE 7.0.539
|
||||
|
||||
Bash script for deploying/backups and restore SODEW infrastructures.
|
||||
|
||||
|
||||
@@ -22,50 +22,6 @@ spec:
|
||||
resources: { requests: { storage: 500Gi } }
|
||||
storageClassName: ""
|
||||
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: PersistentVolume
|
||||
metadata: { name: "{{ .Values.openlitespeed }}-private-pv" }
|
||||
spec:
|
||||
capacity: { storage: 5Gi }
|
||||
volumeMode: Filesystem
|
||||
accessModes: [ ReadWriteMany ]
|
||||
persistentVolumeReclaimPolicy: Retain
|
||||
hostPath: { path: "{{ .Values.olsPrivatePath }}", type: DirectoryOrCreate }
|
||||
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: PersistentVolumeClaim
|
||||
metadata: { name: "{{ .Values.openlitespeed }}-private-pvc", namespace: "{{ .Values.namespace }}" }
|
||||
spec:
|
||||
volumeName: "{{ .Values.openlitespeed }}-private-pv"
|
||||
volumeMode: Filesystem
|
||||
accessModes: [ ReadWriteMany ]
|
||||
resources: { requests: { storage: 5Gi } }
|
||||
storageClassName: ""
|
||||
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: PersistentVolume
|
||||
metadata: { name: "{{ .Values.openlitespeed }}-public-pv" }
|
||||
spec:
|
||||
capacity: { storage: 10Gi }
|
||||
volumeMode: Filesystem
|
||||
accessModes: [ ReadWriteMany ]
|
||||
persistentVolumeReclaimPolicy: Retain
|
||||
hostPath: { path: "{{ .Values.olsPublicPath }}", type: DirectoryOrCreate }
|
||||
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: PersistentVolumeClaim
|
||||
metadata: { name: "{{ .Values.openlitespeed }}-public-pvc", namespace: "{{ .Values.namespace }}" }
|
||||
spec:
|
||||
volumeName: "{{ .Values.openlitespeed }}-public-pv"
|
||||
volumeMode: Filesystem
|
||||
accessModes: [ ReadWriteMany ]
|
||||
resources: { requests: { storage: 10Gi } }
|
||||
storageClassName: ""
|
||||
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: PersistentVolume
|
||||
@@ -75,7 +31,7 @@ spec:
|
||||
volumeMode: Filesystem
|
||||
accessModes: [ ReadWriteMany ]
|
||||
persistentVolumeReclaimPolicy: Retain
|
||||
hostPath: { path: "{{ .Values.olsConfigPath }}", type: DirectoryOrCreate }
|
||||
hostPath: { path: "{{ .Values.openlitespeedConfigPath }}", type: DirectoryOrCreate }
|
||||
|
||||
---
|
||||
apiVersion: v1
|
||||
@@ -97,7 +53,7 @@ spec:
|
||||
volumeMode: Filesystem
|
||||
accessModes: [ ReadWriteMany ]
|
||||
persistentVolumeReclaimPolicy: Retain
|
||||
hostPath: { path: "{{ .Values.olsAdminPath }}", type: DirectoryOrCreate }
|
||||
hostPath: { path: "{{ .Values.openlitespeedAdminPath }}", type: DirectoryOrCreate }
|
||||
|
||||
---
|
||||
apiVersion: v1
|
||||
@@ -119,7 +75,7 @@ spec:
|
||||
volumeMode: Filesystem
|
||||
accessModes: [ ReadWriteMany ]
|
||||
persistentVolumeReclaimPolicy: Retain
|
||||
hostPath: { path: "{{ .Values.olsPhpIniPath }}", type: DirectoryOrCreate }
|
||||
hostPath: { path: "{{ .Values.openlitespeedPhpIniPath }}", type: DirectoryOrCreate }
|
||||
|
||||
---
|
||||
apiVersion: v1
|
||||
@@ -142,7 +98,7 @@ spec:
|
||||
accessModes: [ ReadWriteMany ]
|
||||
persistentVolumeReclaimPolicy: Retain
|
||||
storageClassName: ""
|
||||
hostPath: { path: "{{ .Values.olsLogsPath }}", type: DirectoryOrCreate }
|
||||
hostPath: { path: "{{ .Values.openlitespeedLogsPath }}", type: DirectoryOrCreate }
|
||||
|
||||
---
|
||||
apiVersion: v1
|
||||
@@ -155,6 +111,50 @@ spec:
|
||||
resources: { requests: { storage: 10Gi } }
|
||||
storageClassName: ""
|
||||
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: PersistentVolume
|
||||
metadata: { name: "{{ .Values.openlitespeed }}-vhost-data-pv" }
|
||||
spec:
|
||||
capacity: { storage: 5Gi }
|
||||
volumeMode: Filesystem
|
||||
accessModes: [ ReadWriteMany ]
|
||||
persistentVolumeReclaimPolicy: Retain
|
||||
hostPath: { path: "{{ .Values.openlitespeedVhostDataPath }}", type: DirectoryOrCreate }
|
||||
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: PersistentVolumeClaim
|
||||
metadata: { name: "{{ .Values.openlitespeed }}-vhost-data-pvc", namespace: "{{ .Values.namespace }}" }
|
||||
spec:
|
||||
volumeName: "{{ .Values.openlitespeed }}-vhost-data-pv"
|
||||
volumeMode: Filesystem
|
||||
accessModes: [ ReadWriteMany ]
|
||||
resources: { requests: { storage: 5Gi } }
|
||||
storageClassName: ""
|
||||
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: PersistentVolume
|
||||
metadata: { name: "{{ .Values.openlitespeed }}-vhost-shared-pv" }
|
||||
spec:
|
||||
capacity: { storage: 1Gi }
|
||||
volumeMode: Filesystem
|
||||
accessModes: [ ReadWriteMany ]
|
||||
persistentVolumeReclaimPolicy: Retain
|
||||
hostPath: { path: "{{ .Values.openlitespeedVhostSharedPath }}", type: DirectoryOrCreate }
|
||||
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: PersistentVolumeClaim
|
||||
metadata: { name: "{{ .Values.openlitespeed }}-vhost-shared-pvc", namespace: "{{ .Values.namespace }}" }
|
||||
spec:
|
||||
volumeName: "{{ .Values.openlitespeed }}-vhost-shared-pv"
|
||||
volumeMode: Filesystem
|
||||
accessModes: [ ReadWriteMany ]
|
||||
resources: { requests: { storage: 1Gi } }
|
||||
storageClassName: ""
|
||||
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
@@ -194,22 +194,18 @@ spec:
|
||||
readinessProbe: { tcpSocket: { port: 80 }, initialDelaySeconds: 5, periodSeconds: 5, failureThreshold: 3 }
|
||||
livenessProbe: { tcpSocket: { port: 80 }, initialDelaySeconds: 10, periodSeconds: 10, failureThreshold: 5 }
|
||||
volumeMounts:
|
||||
- { name: "{{ .Values.openlitespeed }}-vhosts-volume", mountPath: {{ .Values.olsPodVhostsPath }} }
|
||||
- { name: "{{ .Values.openlitespeed }}-private-volume", mountPath: {{ .Values.olsPodPrivatePath }}, readOnly: true }
|
||||
- { name: "{{ .Values.openlitespeed }}-public-volume", mountPath: {{ .Values.olsPodPublicPath }}, readOnly: true }
|
||||
- { name: "{{ .Values.openlitespeed }}-config-volume", mountPath: /usr/local/lsws/conf }
|
||||
- { name: "{{ .Values.openlitespeed }}-admin-volume", mountPath: /usr/local/lsws/admin/conf }
|
||||
- { name: "{{ .Values.openlitespeed }}-phpini-volume", mountPath: /etc/ols-php-ini }
|
||||
- { name: "{{ .Values.openlitespeed }}-logs-volume", mountPath: /usr/local/lsws/logs }
|
||||
- { name: "{{ .Values.openlitespeed }}-cache-volume", mountPath: /usr/local/lsws/cachedata }
|
||||
- { name: "{{ .Values.openlitespeed }}-tmp-volume", mountPath: /tmp/lshttpd }
|
||||
- { name: "{{ .Values.openlitespeed }}-vhosts-volume", mountPath: /var/www/vhosts }
|
||||
- { name: "{{ .Values.openlitespeed }}-config-volume", mountPath: /usr/local/lsws/conf }
|
||||
- { name: "{{ .Values.openlitespeed }}-admin-volume", mountPath: /usr/local/lsws/admin/conf }
|
||||
- { name: "{{ .Values.openlitespeed }}-phpini-volume", mountPath: /etc/ols-php-ini }
|
||||
- { name: "{{ .Values.openlitespeed }}-logs-volume", mountPath: /usr/local/lsws/logs }
|
||||
- { name: "{{ .Values.openlitespeed }}-cache-volume", mountPath: /usr/local/lsws/cachedata }
|
||||
- { name: "{{ .Values.openlitespeed }}-tmp-volume", mountPath: /tmp/lshttpd }
|
||||
- { name: "{{ .Values.openlitespeed }}-vhost-data-volume", mountPath: /var/www/data, readOnly: true }
|
||||
- { name: "{{ .Values.openlitespeed }}-vhost-shared-volume", mountPath: /var/www/shared, readOnly: true }
|
||||
volumes:
|
||||
- name: "{{ .Values.openlitespeed }}-vhosts-volume"
|
||||
persistentVolumeClaim: { claimName: "{{ .Values.openlitespeed }}-vhosts-pvc" }
|
||||
- name: "{{ .Values.openlitespeed }}-private-volume"
|
||||
persistentVolumeClaim: { claimName: "{{ .Values.openlitespeed }}-private-pvc" }
|
||||
- name: "{{ .Values.openlitespeed }}-public-volume"
|
||||
persistentVolumeClaim: { claimName: "{{ .Values.openlitespeed }}-public-pvc" }
|
||||
- name: "{{ .Values.openlitespeed }}-config-volume"
|
||||
persistentVolumeClaim: { claimName: "{{ .Values.openlitespeed }}-config-pvc" }
|
||||
- name: "{{ .Values.openlitespeed }}-admin-volume"
|
||||
@@ -222,6 +218,10 @@ spec:
|
||||
emptyDir: { sizeLimit: 100Gi }
|
||||
- name: "{{ .Values.openlitespeed }}-tmp-volume"
|
||||
emptyDir: { sizeLimit: 100Gi }
|
||||
- name: "{{ .Values.openlitespeed }}-vhost-data-volume"
|
||||
persistentVolumeClaim: { claimName: "{{ .Values.openlitespeed }}-vhost-data-pvc" }
|
||||
- name: "{{ .Values.openlitespeed }}-vhost-shared-volume"
|
||||
persistentVolumeClaim: { claimName: "{{ .Values.openlitespeed }}-vhost-shared-pvc" }
|
||||
|
||||
---
|
||||
apiVersion: v1
|
||||
@@ -264,7 +264,7 @@ apiVersion: traefik.io/v1alpha1
|
||||
kind: MiddlewareTCP
|
||||
metadata: { name: "{{ .Values.openlitespeed }}-admin-allowlist", namespace: "{{ .Values.namespace }}" }
|
||||
spec:
|
||||
ipAllowList: { sourceRange: [ {{ .Values.olsAdminWhiteList }} ] }
|
||||
ipAllowList: { sourceRange: [ {{ .Values.openlitespeedAdminWhiteList }} ] }
|
||||
|
||||
---
|
||||
apiVersion: traefik.io/v1alpha1
|
||||
|
||||
@@ -1,13 +0,0 @@
|
||||
RewriteEngine On
|
||||
|
||||
RewriteCond %{DOCUMENT_ROOT}/.php81 -f
|
||||
RewriteRule ^ - [H=application/x-httpd-lsphp81]
|
||||
|
||||
RewriteCond %{DOCUMENT_ROOT}/.php82 -f
|
||||
RewriteRule ^ - [H=application/x-httpd-lsphp82]
|
||||
|
||||
RewriteCond %{DOCUMENT_ROOT}/.php83 -f
|
||||
RewriteRule ^ - [H=application/x-httpd-lsphp83]
|
||||
|
||||
RewriteCond %{DOCUMENT_ROOT}/.php84 -f
|
||||
RewriteRule ^ - [H=application/x-httpd-lsphp84]
|
||||
@@ -1,37 +0,0 @@
|
||||
allowSymbolLink 1
|
||||
enableScript 1
|
||||
restrained 1
|
||||
setUIDMode 2
|
||||
vhRoot /var/www/vhosts/$VH_NAME
|
||||
|
||||
virtualHostConfig {
|
||||
docRoot $VH_ROOT/www/
|
||||
vhDomain $VH_NAME
|
||||
vhAliases *.$VH_NAME
|
||||
|
||||
index {
|
||||
useServer 0
|
||||
indexFiles index.php
|
||||
}
|
||||
|
||||
phpIniOverride {
|
||||
php_admin_value upload_tmp_dir $VH_ROOT/tmp
|
||||
php_admin_value session.save_path $VH_ROOT/session
|
||||
php_admin_value open_basedir "$VH_ROOT/www:$VH_ROOT/tmp:$VH_ROOT/session:/var/www/private/$VH_NAME:/var/www/public"
|
||||
php_admin_value auto_prepend_file /var/www/private/$VH_NAME/bootstrap.php
|
||||
}
|
||||
|
||||
rewrite {
|
||||
enable 1
|
||||
autoLoadHtaccess 1
|
||||
rules <<<END_rules
|
||||
#rewriteFile /usr/local/lsws/conf/rules/php.rules
|
||||
rewriteFile /usr/local/lsws/conf/rules/https.rules
|
||||
rewriteFile /usr/local/lsws/conf/rules/front-controller.rules
|
||||
END_rules
|
||||
}
|
||||
|
||||
accessControl {
|
||||
allow 127.0.0.1, ::1, 10.42.0.0/16, 10.43.0.0/16
|
||||
}
|
||||
}
|
||||
-5
@@ -27,12 +27,7 @@ rewrite {
|
||||
enable 1
|
||||
autoLoadHtaccess 1
|
||||
rules <<<END_rules
|
||||
rewriteFile /usr/local/lsws/conf/rules/php.rules
|
||||
rewriteFile /usr/local/lsws/conf/rules/https.rules
|
||||
rewriteFile /usr/local/lsws/conf/rules/front-controller.rules
|
||||
END_rules
|
||||
}
|
||||
|
||||
accessControl {
|
||||
allow 127.0.0.1, ::1, 10.42.0.0/16, 10.43.0.0/16
|
||||
}
|
||||
@@ -1,38 +0,0 @@
|
||||
docRoot $VH_ROOT/www/
|
||||
vhDomain $VH_NAME
|
||||
vhAliases *.$VH_NAME
|
||||
|
||||
index {
|
||||
useServer 0
|
||||
indexFiles index.php
|
||||
}
|
||||
|
||||
phpIniOverride {
|
||||
# --- paths ---
|
||||
php_admin_value upload_tmp_dir $VH_ROOT/tmp
|
||||
php_admin_value session.save_path $VH_ROOT/session
|
||||
php_admin_value open_basedir "$VH_ROOT/www:$VH_ROOT/tmp:$VH_ROOT/session:/var/www/private/$VH_NAME:/var/www/public"
|
||||
php_admin_value auto_prepend_file /var/www/private/$VH_NAME/bootstrap.php
|
||||
|
||||
# --- hard limits ---
|
||||
php_admin_value memory_limit {{memory_limit}}
|
||||
php_admin_value max_execution_time {{max_execution_time}}
|
||||
php_admin_value max_input_time 30
|
||||
php_admin_value max_input_vars 1000
|
||||
php_admin_value post_max_size {{post_max_size}}
|
||||
php_admin_value upload_max_filesize {{upload_max_filesize}}
|
||||
}
|
||||
|
||||
rewrite {
|
||||
enable 1
|
||||
autoLoadHtaccess 1
|
||||
rules <<<END_rules
|
||||
rewriteFile /usr/local/lsws/conf/rules/php.rules
|
||||
rewriteFile /usr/local/lsws/conf/rules/https.rules
|
||||
rewriteFile /usr/local/lsws/conf/rules/front-controller.rules
|
||||
END_rules
|
||||
}
|
||||
|
||||
accessControl {
|
||||
allow 127.0.0.1, ::1, 10.42.0.0/16, 10.43.0.0/16
|
||||
}
|
||||
@@ -7,9 +7,9 @@ hostIp="127.0.0.1"
|
||||
hostUuid=$(fileValueGetOrCreate "$appDataPath/$hostName.uuid" $(uuidgen))
|
||||
hostSalt=$(filePasswordGetOrCreate "$appDataPath/$hostName.salt")
|
||||
basePath="/_data"
|
||||
vhostsPath="$basePath/vhosts"
|
||||
domainsList="$appAssetsPath/domains.list"
|
||||
sftpAccessGroup="sftp-access"
|
||||
dnsResolver="@1.1.1.1"
|
||||
pigzThreads="4"
|
||||
rocketChatUrl=""
|
||||
|
||||
@@ -45,29 +45,21 @@ mariadbSlavePath="$basePath/$mariadbKube/slave"
|
||||
mariadbRootPass=$(filePasswordGetOrCreate "$appDataPath/$hostName.$mariadbKube")
|
||||
|
||||
# OpenLiteSpeed
|
||||
olsKube="openlitespeed"
|
||||
olsYaml="$appDataPath/yaml/$olsKube.yaml"
|
||||
olsPath="$basePath/$olsKube"
|
||||
olsVhostsPath="$basePath/vhosts"
|
||||
olsPrivatePath="$olsPath/vhosts-private"
|
||||
olsPublicPath="$olsPath/vhosts-public"
|
||||
olsLogsPath="$olsPath/logs"
|
||||
olsAdminPath="$olsPath/admin"
|
||||
olsPhpIniPath="$olsPath/php-ini"
|
||||
olsConfigPath="$olsPath/config"
|
||||
olsConfigFile="$olsConfigPath/httpd_config.conf"
|
||||
olsVhostsConfigPath="$olsConfigPath/vhosts"
|
||||
olsPodVhostsPath="/var/www/vhosts"
|
||||
olsPodPrivatePath="/var/www/private"
|
||||
olsPodPublicPath="/var/www/public"
|
||||
olsAdminWhiteList=("0.0.0.0/0")
|
||||
olsAdminPass=$(filePasswordGetOrCreate "$appDataPath/$hostName.$olsKube")
|
||||
olsVhostMode="standalone"
|
||||
olsVhostFile="virtual.host.conf"
|
||||
olsVhostTemplate="v.template"
|
||||
olsQuotaBlockLimit=10485760
|
||||
olsQuotaInodeLimit=100000
|
||||
olsPhpList=(81 82 83 84 85)
|
||||
openlitespeedKube="openlitespeed"
|
||||
openlitespeedYaml="$appDataPath/yaml/$openlitespeedKube.yaml"
|
||||
openlitespeedPath="$basePath/$openlitespeedKube"
|
||||
openlitespeedAdminPath="$openlitespeedPath/admin"
|
||||
openlitespeedPhpIniPath="$openlitespeedPath/php-ini"
|
||||
openlitespeedConfigPath="$openlitespeedPath/config"
|
||||
openlitespeedLogsPath="$openlitespeedPath/logs"
|
||||
openlitespeedVhostDataPath="$openlitespeedPath/vhost-data"
|
||||
openlitespeedVhostSharedPath="$openlitespeedPath/vhost-shared"
|
||||
openlitespeedVhostsPath="$openlitespeedConfigPath/vhosts"
|
||||
openlitespeedConfigFile="$openlitespeedConfigPath/httpd_config.conf"
|
||||
openlitespeedAdminWhiteList=("0.0.0.0/0")
|
||||
openlitespeedAdminPass=$(filePasswordGetOrCreate "$appDataPath/$hostName.$openlitespeedKube")
|
||||
openlitespeedQuotaBlockLimit=10485760
|
||||
openlitespeedQuotaInodeLimit=100000
|
||||
|
||||
# Postfix
|
||||
postfixKube="postfix"
|
||||
@@ -85,6 +77,7 @@ postfixDomainsFile="virtual_domains.maps"
|
||||
postfixAliasesFile="virtual_aliases.maps"
|
||||
postfixSendersFile="senders.maps"
|
||||
postfixIp="$hostIp"
|
||||
postfixResolver="@8.8.8.8"
|
||||
|
||||
# Worker
|
||||
workerKube="worker"
|
||||
@@ -128,10 +121,9 @@ backupArchiveInterval=30
|
||||
|
||||
# Storage
|
||||
# Default path to remote storage root for rSync / FTP / SSH
|
||||
storageType="rsync"
|
||||
storagePath="/$hostName"
|
||||
storageDailyKeep=10
|
||||
storageArchiveKeep=3
|
||||
storageType="rsync"
|
||||
storageDays=99
|
||||
|
||||
# Storage rSync
|
||||
rsyncUri="username@wedos.net/path"
|
||||
@@ -160,5 +152,4 @@ cronJobs=(
|
||||
"20,40 * * * * /bin/bash $appPath/$appFile --script diag-report-ai-short"
|
||||
"5 * * * * /bin/bash $appPath/$appFile --script diag-report-ai-full"
|
||||
"0 * * * * /bin/bash $appPath/$appFile --script backup"
|
||||
"* * * * * /bin/bash $appPath/$appFile --script unigma"
|
||||
)
|
||||
|
||||
@@ -9,7 +9,7 @@
|
||||
- `namespace` - Default kubernetes namespace
|
||||
- `hostname` - Hostname server
|
||||
- `basePath` - Base path for all resources
|
||||
- `olsVhostsPath` - Directory for vhosts
|
||||
- `vhostsPath` - Directory for vhosts
|
||||
- `domainsList` - File with domains list
|
||||
***
|
||||
|
||||
@@ -35,13 +35,13 @@
|
||||
- `mariadbRootPass` - MariaDB root password
|
||||
***
|
||||
|
||||
- `olsKube` - Openlitespeed identifier in k3s
|
||||
- `olsYaml` - Path to file template YAML for OpenLiteSpeed
|
||||
- `olsPath` - Directory for OpenLiteSpeed configuration
|
||||
- `olsAdminPath` - Directory for OpenLiteSpeed Admin configuration
|
||||
- `olsConfigFile` - OpenLiteSpeed configuration file
|
||||
- `olsVhostsConfigPath` - Directory for vhosts configuration files
|
||||
- `olsAdminPass` - OpenLiteSpeed admin panel password
|
||||
- `openlitespeedKube` - Openlitespeed identifier in k3s
|
||||
- `openlitespeedYaml` - Path to file template YAML for OpenLiteSpeed
|
||||
- `openlitespeedPath` - Directory for OpenLiteSpeed configuration
|
||||
- `openlitespeedAdminPath` - Directory for OpenLiteSpeed Admin configuration
|
||||
- `openlitespeedConfigFile` - OpenLiteSpeed configuration file
|
||||
- `openlitespeedVhostsPath` - Directory for vhosts configuration files
|
||||
- `openlitespeedAdminPass` - OpenLiteSpeed admin panel password
|
||||
***
|
||||
|
||||
- `postfixKube` - Postfix identifier in k3s
|
||||
|
||||
@@ -128,7 +128,7 @@ sudo kube.sh --remove example.com
|
||||
When specifying a domain, the following checks are performed:
|
||||
* Presence of the domain in the `OpenLiteSpeed` configuration
|
||||
* Presence of the domain in the list of stopped sites (OpenLiteSpeed)
|
||||
* Presence of the domain directory in the virtual hosts directory (`olsVhostsPath`)
|
||||
* Presence of the domain directory in the virtual hosts directory (`vhostsPath`)
|
||||
* Presence of the `WordPress` configuration file (`wp-config.php`)
|
||||
* Checking the database name entry in the WordPress configuration and verifying its existence
|
||||
* Checking the database user entry in the WordPress configuration and verifying its existence
|
||||
@@ -139,7 +139,7 @@ When specifying a domain, the following checks are performed:
|
||||
|
||||
If the domain is not specified, the following checks are performed for all domains:
|
||||
* Presence of the domain in the list of stopped sites (`OpenLiteSpeed`)
|
||||
* Presence of the domain directory in the virtual hosts directory (`olsVhostsPath`)
|
||||
* Presence of the domain directory in the virtual hosts directory (`vhostsPath`)
|
||||
* Presence of the `WordPress` configuration file (`wp-config.php`)
|
||||
* Checking the database name entry in the `WordPress` configuration and verifying its existence
|
||||
* Checking the database user entry in the `WordPress` configuration and verifying its existence
|
||||
@@ -182,10 +182,10 @@ Examples of responses:
|
||||
|
||||
Where:
|
||||
- `CFG` - existence of the configuration file `$dataPath/config/<domain>.config`
|
||||
- `DIR` - existence of the directory `$olsVhostsPath/<domain>`
|
||||
- `DIR` - existence of the directory `$vhostsPath/<domain>`
|
||||
- `OLS` - existence of an entry in the `OpenLiteSpeed` configuration
|
||||
- `MD` - existence of the database (based on the entry in the configuration file)
|
||||
- `MU` - existence of the database user (based on the entry in the configuration file)
|
||||
- `RU` - existence of the Redis user (based on the entry in the configuration file)
|
||||
- `WP` - existence of the WP configuration file `$olsVhostsPath/<domain>/www/wp-config.php`
|
||||
- `WP` - existence of the WP configuration file `$vhostsPath/<domain>/www/wp-config.php`
|
||||
)
|
||||
|
||||
@@ -2,7 +2,7 @@
|
||||
|
||||
export PATH="/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin"
|
||||
|
||||
readonly appVersion="7.1.553"
|
||||
readonly appVersion="7.0.539"
|
||||
readonly appName="KUBE"
|
||||
readonly appPath="$(cd -- "$(dirname -- "${BASH_SOURCE[0]}")" && pwd -P)"
|
||||
readonly appFile="$(basename -- "$0")"
|
||||
@@ -16,8 +16,7 @@ function appDev() {
|
||||
printRow
|
||||
printFill 30 "◤◢" "$fontYellow" "◤$fontReset"
|
||||
|
||||
|
||||
|
||||
cmdOpenlitespeedRestart
|
||||
|
||||
printFill 30 "◤◢" "$fontYellow" "◤$fontReset"
|
||||
}
|
||||
|
||||
@@ -51,7 +51,7 @@ function appFailure() {
|
||||
|
||||
if [[ "${1:-}" =~ ^[0-9]+$ ]]; then
|
||||
code="$1"
|
||||
shift || true
|
||||
shift
|
||||
fi
|
||||
|
||||
printf '%b\n' "\033[0;91mCrash: $*\033[0m"
|
||||
@@ -70,18 +70,18 @@ function appLoadFile() {
|
||||
function appCheckConfig() {
|
||||
local value
|
||||
|
||||
local -a values=('hostName' 'hostIp' 'hostUuid' 'hostSalt' 'k3sNamespace' 'redisKube' 'mariadbKube' 'olsKube' 'postfixKube' 'workerKube' 'redisFileUsersAcl' 'postfixIp' 'postfixHost' 'postfixPostmaster' 'postfixDkimSelector' 'workerApiUrl' 'workerName' 'backupType' 'backupFirstDir')
|
||||
local -a values=('hostName' 'hostIp' 'hostUuid' 'hostSalt' 'k3sNamespace' 'redisKube' 'mariadbKube' 'openlitespeedKube' 'postfixKube' 'workerKube' 'redisFileUsersAcl' 'postfixIp' 'postfixHost' 'postfixPostmaster' 'postfixDkimSelector' 'workerApiUrl' 'workerName' 'backupType' 'backupFirstDir')
|
||||
for value in "${values[@]}"; do
|
||||
[[ -n "${!value-}" ]] || appFailure 4 "$value: not specified"
|
||||
done
|
||||
|
||||
values=('appAssetsPath' 'appDataPath' 'basePath' 'olsVhostsPath' 'domainsList' 'k3sCmd' 'redisPath' 'mariadbMasterPath' 'mariadbSlavePath' 'olsPath' 'olsAdminPath' 'olsPhpIniPath' 'olsLogsPath' 'olsConfigFile' 'olsPrivatePath' 'olsPublicPath' 'olsVhostsConfigPath' 'postfixPath' 'postfixDkimPath' 'workerPath' 'workerAgentPath' 'workerTasksPath' 'workerFilesPath' 'logPath' 'logFile' 'backupDailyPath' 'backupArchivePath' 'storagePath' 'rsyncPath' 'ftpPath' 'sshPath')
|
||||
values=('appAssetsPath' 'appDataPath' 'basePath' 'vhostsPath' 'domainsList' 'k3sCmd' 'redisPath' 'mariadbMasterPath' 'mariadbSlavePath' 'openlitespeedPath' 'openlitespeedAdminPath' 'openlitespeedPhpIniPath' 'openlitespeedLogsPath' 'openlitespeedConfigFile' 'openlitespeedVhostDataPath' 'openlitespeedVhostSharedPath' 'openlitespeedVhostsPath' 'postfixPath' 'postfixDkimPath' 'workerPath' 'workerAgentPath' 'workerTasksPath' 'workerFilesPath' 'logPath' 'logFile' 'backupDailyPath' 'backupArchivePath' 'storagePath' 'rsyncPath' 'ftpPath' 'sshPath')
|
||||
for value in "${values[@]}"; do
|
||||
[[ "${!value-}" == /* ]] || appFailure 4 "$value: a variable must begin with /"
|
||||
[[ "${!value-}" != */ ]] || appFailure 4 "$value: a variable cannot end in /"
|
||||
done
|
||||
|
||||
values=('backupParallelJobs' 'k3sReadyRetries' 'k3sReadySleep' 'workerApiGettingPause' 'workerApiSendingPause' 'backupDailyKeep' 'backupArchiveInterval' 'storageDailyKeep' 'storageArchiveKeep' 'olsQuotaBlockLimit' 'olsQuotaInodeLimit')
|
||||
values=('backupParallelJobs' 'k3sReadyRetries' 'k3sReadySleep' 'workerApiGettingPause' 'workerApiSendingPause' 'backupDailyKeep' 'backupArchiveInterval' 'storageDailyKeep' 'storageArchiveKeep' 'openlitespeedQuotaBlockLimit' 'openlitespeedQuotaInodeLimit')
|
||||
for value in "${values[@]}"; do
|
||||
[[ "${!value-}" =~ ^[0-9]+$ ]] && (( ${!value} >= 1 )) || appFailure 4 "$value: incorrect number value"
|
||||
done
|
||||
|
||||
@@ -10,7 +10,7 @@ function cmdBackupSitesArchive() {
|
||||
local type="${2:-$backupType}"
|
||||
|
||||
local error vhostList total
|
||||
run vhostList error openlitespeedConfigVhostList || { printDanger "Failed get list of vhosts: $error"; return 1; }
|
||||
run vhostList error openlitespeedVhostList || { printDanger "Failed get list of virtual hosts: $error"; return 1; }
|
||||
total=$(grep -c . <<< "$vhostList")
|
||||
|
||||
printSection "Config"
|
||||
@@ -68,13 +68,13 @@ function cmdBackupSitesRsync() {
|
||||
printDotText "Path" "$path"
|
||||
|
||||
local error vhostList
|
||||
run vhostList error openlitespeedConfigVhostList || { printDanger "Failed get list of vhosts: $error"; return 1; }
|
||||
run vhostList error openlitespeedVhostList || { printDanger "Failed get list of virtual hosts: $error"; return 1; }
|
||||
|
||||
printText "Files..."
|
||||
if [[ "$path" == *"$backupFirstDir" ]]; then
|
||||
runError error rsync -a --mkpath -- "$olsVhostsPath/" "$path" || printDanger "$error"
|
||||
runError error rsync -a --mkpath -- "$vhostsPath/" "$path" || printDanger "$error"
|
||||
else
|
||||
runError error rsync -a --link-dest="$backupDailyPath/$backupFirstDir" -- "$olsVhostsPath/" "$path" || printDanger "$error"
|
||||
runError error rsync -a --link-dest="$backupDailyPath/$backupFirstDir" -- "$vhostsPath/" "$path" || printDanger "$error"
|
||||
fi
|
||||
|
||||
printText "Databases..."
|
||||
@@ -84,7 +84,7 @@ function cmdBackupSitesRsync() {
|
||||
|
||||
printText "Configs..."
|
||||
while read -r domain; do
|
||||
runError error cp -p -- "$olsVhostsConfigPath/$domain.conf" "$path/$domain.conf" || printDanger "$error"
|
||||
runError error cp -p -- "$openlitespeedVhostsPath/$domain.conf" "$path/$domain.conf" || printDanger "$error"
|
||||
done < <(awk 'NF' <<< "$vhostList")
|
||||
}
|
||||
|
||||
@@ -302,7 +302,6 @@ function cmdBackupDispatch() {
|
||||
# [$3] (type): backup type.
|
||||
function cmdBackupRun() {
|
||||
local target="$1"
|
||||
[[ -n "$target" ]] || { printRow; printDanger "Target not specified"; return 1; }
|
||||
|
||||
local path="$2"
|
||||
path=$(backupPathGenerate "$path")
|
||||
@@ -328,56 +327,3 @@ function cmdBackupRun() {
|
||||
fi
|
||||
fi
|
||||
}
|
||||
|
||||
function cmdBackupList() {
|
||||
printRow
|
||||
|
||||
local dirList archiveList dailyList backupList backupCount error
|
||||
run dirList error fileList "$backupArchivePath" d || { printDanger "$error"; return 1; }
|
||||
archiveList=$(printf '%s\n' "$dirList" | grep -E -- "$backupArchiveDirPattern" | sort || true)
|
||||
|
||||
run dirList error fileList "$backupDailyPath" d || { printDanger "$error"; return 1; }
|
||||
dailyList=$(printf '%s\n' "$dirList" | grep -E -- "$backupDailyDirPattern" | sort || true)
|
||||
|
||||
backupList=$(printf '%s\n' "$archiveList" "$dailyList" | awk 'NF' | sort)
|
||||
backupCount=$(grep -c . <<< "$backupList" || true)
|
||||
local i=0 num dir label
|
||||
while read -r dir; do
|
||||
((++i))
|
||||
num=$(printf "%0${#backupCount}d" "$i")
|
||||
label="$num: $fontBlue$dir$fontReset"
|
||||
|
||||
if listContains "$dir" "$archiveList"; then
|
||||
printDotText "$label" "${fontGreen}archive$fontReset"
|
||||
elif listContains "$dir" "$dailyList"; then
|
||||
printDotText "$label" "${fontGreen}daily$fontReset"
|
||||
else
|
||||
printDotText "$label" "$labelUnknown"
|
||||
fi
|
||||
done < <(awk 'NF' <<< "$backupList")
|
||||
}
|
||||
|
||||
function cmdBackupSize() {
|
||||
local dirList file size total=0 archiveList dailyList
|
||||
|
||||
printSection "Archive: $backupArchivePath"
|
||||
run dirList error fileList "$backupArchivePath" d || { printDanger "$error"; return 1; }
|
||||
archiveList=$(printf '%s\n' "$dirList" | grep -E -- "$backupArchiveDirPattern" | sort || true)
|
||||
while IFS= read -r file; do
|
||||
size=$(pathSize "$backupArchivePath/$file" "gb")
|
||||
printDotText "$file" "$size Gb"
|
||||
(( total += size ))
|
||||
done <<< "$archiveList"
|
||||
|
||||
printSection "Daily: $backupDailyPath"
|
||||
run dirList error fileList "$backupDailyPath" d || { printDanger "$error"; return 1; }
|
||||
dailyList=$(printf '%s\n' "$dirList" | grep -E -- "$backupDailyDirPattern" | sort || true)
|
||||
while IFS= read -r file; do
|
||||
size=$(pathSize "$backupDailyPath/$file" "gb")
|
||||
printDotText "$file" "$size Gb"
|
||||
(( total += size ))
|
||||
done <<< "$dailyList"
|
||||
|
||||
printRow
|
||||
printDotText "total" "$total Gb"
|
||||
}
|
||||
|
||||
@@ -3,14 +3,14 @@ function cmdHelpPrint() {
|
||||
}
|
||||
|
||||
function cmdHelpK3S() {
|
||||
local title="-k|--k3s <action>"
|
||||
local title="-k|--k3s <action> [option]"
|
||||
local desc="
|
||||
create - create all resources in k3s
|
||||
remove - remove all resources in k3s
|
||||
info - detail about a k3s
|
||||
status - status about a k3s
|
||||
top - top pod
|
||||
res [<resource>] - get resource info (all|pod|event|pv|pvc|deploy|ds|rs|sts|svc|ing|ip|secret|cm|job|cj|ep|no|ns|cs|netpol)"
|
||||
res [resource] - get resource info (all|pod|event|pv|pvc|deploy|ds|rs|sts|svc|ing|ip|secret|cm|job|cj|ep|no|ns|cs|netpol)"
|
||||
|
||||
cmdHelpPrint "$title" "$desc"
|
||||
}
|
||||
@@ -26,8 +26,8 @@ function cmdHelpMariaDB() {
|
||||
replica - replica rebuild
|
||||
database - database list
|
||||
user - user list
|
||||
dump [all|<database>] [<file>] - dump specified database or all databases from Master
|
||||
dump_slave [<file>] - full dump from Slave"
|
||||
dump [all|<database>] [file] - dump specified database or all databases from Master
|
||||
dump_slave [file] - full dump from Slave"
|
||||
|
||||
cmdHelpPrint "$title" "$desc"
|
||||
}
|
||||
@@ -50,21 +50,22 @@ function cmdHelpRedis() {
|
||||
function cmdHelpOpenLiteSpeed() {
|
||||
local title="-o|--ols <action>"
|
||||
local desc="
|
||||
install - install OpenLiteSpeed in k3s
|
||||
update - update OpenLiteSpeed in k3s
|
||||
uninstall - uninstall OpenLiteSpeed from k3s
|
||||
info - detail about a OpenLiteSpeed
|
||||
list <option> - vhost list (all|up|down)
|
||||
up - unpause vhost
|
||||
down - pause vhost
|
||||
alias - set aliases for domain
|
||||
restart - restart OLS (graceful restart)
|
||||
php_kill all|<domain> - kill lsphp for domain or all domains
|
||||
white_list - WebAdmin white list update
|
||||
allow_list - WebAdmin allow list update
|
||||
install - install OpenLiteSpeed in k3s
|
||||
update - update OpenLiteSpeed in k3s
|
||||
uninstall - uninstall OpenLiteSpeed from k3s
|
||||
info - detail about a OpenLiteSpeed
|
||||
list <option> - vhost list (all|up|down)
|
||||
up - unpause vhost
|
||||
down - pause vhost
|
||||
alias - set aliases for domain
|
||||
restart - restart OLS (graceful restart)
|
||||
restart_php - restart PHP
|
||||
kill_php - kill PHP (hard restart)
|
||||
white_list - WebAdmin white list update
|
||||
allow_list - WebAdmin allow list update
|
||||
alias_list all|<domain> - get aliases for domain or all domains
|
||||
rebuild all|<domain> - rebuild owner and permission files
|
||||
config - check config $olsConfigFile"
|
||||
config - check config $openlitespeedConfigFile"
|
||||
|
||||
cmdHelpPrint "$title" "$desc"
|
||||
}
|
||||
@@ -72,13 +73,14 @@ function cmdHelpOpenLiteSpeed() {
|
||||
function cmdHelpPostfix() {
|
||||
local title="-p|--postfix <action>"
|
||||
local desc="
|
||||
install - install Postfix in k3s
|
||||
update - update Postfix in k3s
|
||||
uninstall - uninstall Postfix from k3s
|
||||
info - detail about a Postfix
|
||||
status - status about a Postfix
|
||||
user - user list (SASL)
|
||||
dkim [<domain>] - autocreate and display DKIM key for DNS record or all domains !!!"
|
||||
install - install Postfix in k3s
|
||||
update - update Postfix in k3s
|
||||
uninstall - uninstall Postfix from k3s
|
||||
info - detail about a Postfix
|
||||
list <option> - list (domain|alias|senders|sasl) !!!!
|
||||
domain <domain> - add domain
|
||||
alias <domain> <email> - set alias for domain
|
||||
dkim [domain] - autocreate and display DKIM key for DNS record or all domains !!!"
|
||||
|
||||
cmdHelpPrint "$title" "$desc"
|
||||
}
|
||||
@@ -89,10 +91,10 @@ function cmdHelpWorker() {
|
||||
install - install Worker in k3s
|
||||
update - update Worker in k3s
|
||||
uninstall - uninstall Worker from k3s
|
||||
task <file> [domain] - Execute task !!!!!
|
||||
list - task list
|
||||
down - stop receiving new tasks from the API (pause)
|
||||
up - start receiving new tasks from the API (unpause)
|
||||
task <file> [<domain>] - Execute task !!!!!"
|
||||
up - start receiving new tasks from the API (unpause)"
|
||||
|
||||
cmdHelpPrint "$title" "$desc"
|
||||
}
|
||||
@@ -111,8 +113,8 @@ function cmdHelpMetric() {
|
||||
function cmdHelpSite() {
|
||||
local title="-s|--site <action>"
|
||||
local desc="
|
||||
add <domain> [<pathF>] [<pathD>] - add site (pathF: source files | pathD: source database)
|
||||
add_wp|wp <domain> [<pathF>] [<pathD>] - add site on Wordpress
|
||||
add <domain> [pathF] [pathD] - add site (pathF: source files | pathD: source database)
|
||||
add_wp|wp <domain> [pathF] [pathD] - add site on Wordpress
|
||||
remove <domain> [-f|--force] - site full remove (-f|--force - forced mode)
|
||||
copy <domain> <domainNew> - create copy of site
|
||||
rename <domain> <domainNew> - rename of site
|
||||
@@ -122,7 +124,7 @@ function cmdHelpSite() {
|
||||
rebuild_wp <domain> - rewrite config connection to internal services in bootstrap.php
|
||||
reset_pass all|<domain> - reset ALL passwords for domain or all domains
|
||||
reset_auth all|<domain> - reset ALL authentication settings for domain or all domains
|
||||
dump <domain> [<file>] - dump database of site"
|
||||
dump <domain> [file] - dump database of site"
|
||||
|
||||
cmdHelpPrint "$title" "$desc"
|
||||
}
|
||||
@@ -133,8 +135,7 @@ function cmdHelpWP() {
|
||||
user <domain> - user list
|
||||
pass <domain> <user> <pass> - user password set
|
||||
salt all|<domain> - shuffle salts
|
||||
check all|<domain> - check core and plugins
|
||||
exec all|<domain> <command> - command exec"
|
||||
exec <domain> <command> - command exec"
|
||||
|
||||
cmdHelpPrint "$title" "$desc"
|
||||
}
|
||||
@@ -162,27 +163,24 @@ function cmdHelpCron() {
|
||||
}
|
||||
|
||||
function cmdHelpBackup() {
|
||||
local title="--backup <action>"
|
||||
local title="-b|--backup <target> [path] [type]"
|
||||
local path=$(backupPathGenerate)
|
||||
local desc="
|
||||
run all|<domain> [<path>] [<type>] - backup
|
||||
path: path to save backup, default: autogenerate
|
||||
type: type backup (zip|tar|archive|rsync), default: $backupType
|
||||
list - list backups on local
|
||||
size - list of backup sizes"
|
||||
|
||||
target - all|<domain>
|
||||
path - path to save backup, default value: $path (autogenerate)
|
||||
type - type backup (zip|tar|archive|rsync), default value: $backupType"
|
||||
cmdHelpPrint "$title" "$desc"
|
||||
}
|
||||
|
||||
function cmdHelpRestore() {
|
||||
local title="--restore <domain> $fontRed[NO TESTED!]$fornReset"
|
||||
local title="--restore <domain> [option] [NO TESTED!]"
|
||||
local desc="
|
||||
run <domain> [<option>] - manual site restore
|
||||
<empty> - manual site restore
|
||||
list - display a list of available markers for restore
|
||||
last - automatic site restore from the last backup
|
||||
full - automatic site restore from the last FULL backup
|
||||
auto - automatic site restore from the last FULL backup or the last backup
|
||||
N - automatic site restore from the last backup #N (N: 1+)"
|
||||
<domain> - manual site restore
|
||||
<domain> list - display a list of available markers for restore
|
||||
<domain> last - automatic site restore from the last backup
|
||||
<domain> full - automatic site restore from the last FULL backup
|
||||
<domain> auto - automatic site restore from the last FULL backup or the last backup
|
||||
<domain> N - automatic site restore from the last backup #N (N: 1+)"
|
||||
|
||||
cmdHelpPrint "$title" "$desc"
|
||||
}
|
||||
@@ -192,7 +190,6 @@ function cmdHelpStorage() {
|
||||
local desc="
|
||||
list - list backups on external storage
|
||||
compare - comparison table
|
||||
size - list of backup sizes
|
||||
sync <type> - synchronization with external storage (archive|daily)
|
||||
remove - remove backups on external storage"
|
||||
|
||||
@@ -216,7 +213,7 @@ function cmdHelpScript() {
|
||||
}
|
||||
|
||||
function cmdHelpTest() {
|
||||
local title="--test <action> $fontRed[NO TESTED!]$fornReset"
|
||||
local title="--test <action> [NO TESTED!]"
|
||||
local desc="
|
||||
mariadb - test MariaDB replica
|
||||
redis - test Redis cluster
|
||||
@@ -229,9 +226,9 @@ function cmdHelpTest() {
|
||||
function cmdHelpMalware() {
|
||||
local title="--malware <action>"
|
||||
local desc="
|
||||
plugin - check plugins (files) in all vhosts
|
||||
user - check users Wordpress in all vhosts
|
||||
file all|<domain> - check files"
|
||||
muplugin - check MU plugins (files) in all vhosts
|
||||
user - check users Wordpress in all vhosts
|
||||
file all|<domain> - check files"
|
||||
|
||||
cmdHelpPrint "$title" "$desc"
|
||||
}
|
||||
@@ -301,7 +298,7 @@ function cmdHelp() {
|
||||
printDotFix 20 "$fontBlue --log" "Log of pods"
|
||||
printDotFix 20 "$fontBlue --describe" "Describe of pods"
|
||||
printDotFix 20 "$fontBlue --delete" "Delete pods"
|
||||
printDotFix 20 "$fontBlue --backup" "Create backup of sites"
|
||||
printDotFix 20 "$fontBlue -b|--backup" "Create backup of sites"
|
||||
printDotFix 20 "$fontBlue --restore" "Restore sites from backups"
|
||||
printDotFix 20 "$fontBlue --storage" "Copy backups to storage"
|
||||
printDotFix 20 "$fontBlue --script" "Execute scripts"
|
||||
|
||||
@@ -45,8 +45,6 @@ function cmdK3sPodSelect() {
|
||||
# Interactively opens a shell or CLI inside a selected pod.
|
||||
# [$1] (cli): pass "cli" to open the native CLI (mariadb/redis-cli) instead of a shell.
|
||||
function cmdShell() {
|
||||
printTitle " Shell $@"
|
||||
|
||||
local cli="$1"
|
||||
local pod
|
||||
cmdK3sPodSelect pod || return 1
|
||||
@@ -99,8 +97,6 @@ function cmdShell() {
|
||||
# Interactively selects a pod and streams its logs.
|
||||
# [$@] (...): extra arguments passed to kubectl logs (e.g. -f, --tail=100).
|
||||
function cmdLog() {
|
||||
printTitle " Log $@"
|
||||
|
||||
local pod
|
||||
cmdK3sPodSelect pod || return 1
|
||||
|
||||
@@ -119,8 +115,6 @@ function cmdDescribe() {
|
||||
local target="${1:-pod}"
|
||||
shift || true
|
||||
|
||||
printTitle " Describe $@"
|
||||
|
||||
case "$target" in
|
||||
pod)
|
||||
local pod
|
||||
@@ -144,8 +138,6 @@ function cmdDescribe() {
|
||||
|
||||
# Interactively selects and deletes a pod.
|
||||
function cmdDelete() {
|
||||
printTitle " Delete $@ $fontRed[DANGER]$fontReset"
|
||||
|
||||
local pod
|
||||
cmdK3sPodSelect pod || return 1
|
||||
|
||||
@@ -186,7 +178,6 @@ netpol|NetworkPolicies"
|
||||
local i=0 line code info num
|
||||
total=$(grep -c . <<< "$resList")
|
||||
while IFS= read -r line; do
|
||||
[[ -n "$line" ]] || continue
|
||||
((i++))
|
||||
num=$(printf "%${#total}d" "$i")
|
||||
code="${line%%|*}"
|
||||
|
||||
@@ -98,50 +98,19 @@ wgpwpp-cache.php
|
||||
installatron_hide_status_test.php
|
||||
"
|
||||
|
||||
run vhostsList error fileList "$olsVhostsPath" d || { printDanger "$error"; return 1; }
|
||||
run vhostsList error fileList "$vhostsPath" d || { printDanger "$error"; return 1; }
|
||||
while read -r dir; do
|
||||
local found=0 pluginList
|
||||
|
||||
# unknown
|
||||
run itemList error fileList "$olsVhostsPath/$dir/www/wp-content/mu-plugins/" f || continue
|
||||
local found=0
|
||||
run itemList error fileList "$vhostsPath/$dir/www/wp-content/mu-plugins/" f || continue
|
||||
while read -r item; do
|
||||
if grep -qF '($i){static $a=null' "$olsVhostsPath/$dir/www/wp-content/mu-plugins/$item"; then
|
||||
if grep -qF '($i){static $a=null' "$vhostsPath/$dir/www/wp-content/mu-plugins/$item"; then
|
||||
(( found++ )) || printSection "$dir"
|
||||
printDotText "$item" "${fontRed}malware$fontReset"
|
||||
elif ! listContains "$item" "$allowedFiles"; then
|
||||
(( found++ )) || printSection "$dir"
|
||||
printDotText "/wp-content/mu-plugins/$item" "$labelUnknown"
|
||||
printDotText "$item" "${fontYellow}warning$fontReset"
|
||||
fi
|
||||
done < <(awk 'NF' <<< "$itemList")
|
||||
|
||||
# wp2shell
|
||||
pluginList=$(find "$olsVhostsPath/$dir/www/wp-content/plugins" -maxdepth 1 -type d -name 'wp2shell*' 2>/dev/null)
|
||||
if [ -n "$pluginList" ]; then
|
||||
while IFS= read -r item; do
|
||||
(( found++ )) || printSection "$dir"
|
||||
printDotText "${item#"$olsVhostsPath/$dir/www"}" "${fontRed}malware$fontReset"
|
||||
done <<< "$pluginList"
|
||||
fi
|
||||
|
||||
# wp-static-cache
|
||||
pluginList=$(find "$olsVhostsPath/$dir/www/wp-content/plugins" -maxdepth 1 -type d -name 'wp-static-cache*' 2>/dev/null)
|
||||
if [ -n "$pluginList" ]; then
|
||||
while IFS= read -r item; do
|
||||
(( found++ )) || printSection "$dir"
|
||||
printDotText "${item#"$olsVhostsPath/$dir/www"}" "${fontRed}malware$fontReset"
|
||||
done <<< "$pluginList"
|
||||
fi
|
||||
|
||||
# other
|
||||
for subdir in wp-content/mu-plugins wp-content/plugins; do
|
||||
pluginList=$(find "$olsVhostsPath/$dir/www/$subdir" -maxdepth 1 -regextype posix-extended -regex '^.*[^0-9a-f][0-9a-f]{6,8}(\.php)?$' 2>/dev/null)
|
||||
if [ -n "$pluginList" ]; then
|
||||
while IFS= read -r item; do
|
||||
(( found++ )) || printSection "$dir"
|
||||
printDotText "${item#"$olsVhostsPath/$dir/www"}" "${fontYellow}warning$fontReset"
|
||||
done <<< "$pluginList"
|
||||
fi
|
||||
done
|
||||
done < <(awk 'NF' <<< "$vhostsList")
|
||||
}
|
||||
|
||||
@@ -153,7 +122,7 @@ function cmdMalwareFilesCheck() {
|
||||
|
||||
if [[ -z "$target" ]]; then
|
||||
printDanger "Target not specified";
|
||||
elif ! run vhostList error openlitespeedConfigVhostList; then
|
||||
elif ! run vhostList error openlitespeedVhostList; then
|
||||
printDanger "Cannot get vhost list: $error";
|
||||
elif [[ "$target" == "all" ]]; then
|
||||
local domain
|
||||
|
||||
@@ -2,7 +2,7 @@ openlitespeedLabel="[OpenLiteSpeed]"
|
||||
|
||||
# Renders the OpenLiteSpeed Kubernetes YAML manifest via Helm.
|
||||
function cmdOpenlitespeedYamlRender() {
|
||||
local templateFile="templates/$olsKube.yaml"
|
||||
local templateFile="templates/$openlitespeedKube.yaml"
|
||||
|
||||
printSection "Render YAML file | Helm"
|
||||
printDotText "Template" "$appAssetsPath/k3s/$templateFile"
|
||||
@@ -26,13 +26,13 @@ function cmdOpenlitespeedYamlRender() {
|
||||
}
|
||||
|
||||
local adminWhiteList=() adminWhiteStr
|
||||
for i in "${!olsAdminWhiteList[@]}"; do
|
||||
adminWhiteList[$i]="\"${olsAdminWhiteList[$i]}\""
|
||||
for i in "${!openlitespeedAdminWhiteList[@]}"; do
|
||||
adminWhiteList[$i]="\"${openlitespeedAdminWhiteList[$i]}\""
|
||||
done
|
||||
adminWhiteStr=$(IFS=','; printf '%s\n' "${adminWhiteList[*]}")
|
||||
|
||||
local varsFile
|
||||
varsFile=$(mktemp "/tmp/$olsKube.vars.XXXXXX.yaml") || {
|
||||
varsFile=$(mktemp "/tmp/$openlitespeedKube.vars.XXXXXX.yaml") || {
|
||||
printDotText "render" "$labelFail"
|
||||
printDanger "Create temp variables file"
|
||||
return 1
|
||||
@@ -42,24 +42,21 @@ function cmdOpenlitespeedYamlRender() {
|
||||
cat > "$varsFile" <<EOF
|
||||
openlitespeedHelm: true
|
||||
namespace: $k3sNamespace
|
||||
openlitespeed: $olsKube
|
||||
olsPodVhostsPath: $olsPodVhostsPath
|
||||
olsPodPrivatePath: $olsPodPrivatePath
|
||||
olsPodPublicPath: $olsPodPublicPath
|
||||
olsVhostsPath: $olsVhostsPath
|
||||
olsPrivatePath: $olsPrivatePath
|
||||
olsPublicPath: $olsPublicPath
|
||||
olsConfigPath: $olsConfigPath
|
||||
olsPhpIniPath: $olsPhpIniPath
|
||||
olsLogsPath: $olsLogsPath
|
||||
olsAdminPath: $olsAdminPath
|
||||
olsAdminWhiteList: $adminWhiteStr
|
||||
openlitespeed: $openlitespeedKube
|
||||
openlitespeedConfigPath: $openlitespeedConfigPath
|
||||
openlitespeedPhpIniPath: $openlitespeedPhpIniPath
|
||||
openlitespeedLogsPath: $openlitespeedLogsPath
|
||||
openlitespeedVhostDataPath: $openlitespeedVhostDataPath
|
||||
openlitespeedVhostSharedPath: $openlitespeedVhostSharedPath
|
||||
openlitespeedAdminPath: $openlitespeedAdminPath
|
||||
openlitespeedAdminWhiteList: $adminWhiteStr
|
||||
vhostsPath: $vhostsPath
|
||||
EOF
|
||||
|
||||
printDotText "Result" "$olsYaml"
|
||||
mkdir -p -- "$(dirname -- "$olsYaml")" || return 1
|
||||
fileBackup "$olsYaml"
|
||||
helm template stack "$appAssetsPath/k3s" -f "$varsFile" -f "$profileCpuFile" -f "$profileMemoryFile" --show-only "$templateFile" > "$olsYaml" || {
|
||||
printDotText "Result" "$openlitespeedYaml"
|
||||
mkdir -p -- "$(dirname -- "$openlitespeedYaml")" || return 1
|
||||
fileBackup "$openlitespeedYaml"
|
||||
helm template stack "$appAssetsPath/k3s" -f "$varsFile" -f "$profileCpuFile" -f "$profileMemoryFile" --show-only "$templateFile" > "$openlitespeedYaml" || {
|
||||
printDotText "render" "$labelFail"
|
||||
printDanger "Render failed"
|
||||
return 1
|
||||
@@ -70,35 +67,8 @@ EOF
|
||||
|
||||
# Initializes OpenLiteSpeed after Kubernetes deployment: patches Traefik, sets admin credentials, PHP config, rules, and restarts.
|
||||
function cmdOpenlitespeedInit() {
|
||||
printSection "Initialization..."
|
||||
printInfo "$openlitespeedLabel Initialization..."
|
||||
|
||||
local ug
|
||||
ug="$(stat -c "%u:%g" "$olsConfigFile")"
|
||||
|
||||
# Patch svc traefik
|
||||
runSilent "$k3sCmd" kubectl -n kube-system patch svc traefik -p '{"spec": {"externalTrafficPolicy": "Local"}}' || {
|
||||
printDotText "Patch svc traefik" "$labelFail"
|
||||
return 1
|
||||
}
|
||||
printDotText "Patch svc traefik" "$labelDone"
|
||||
|
||||
cmdOpenlitespeedWaitReady || return 1
|
||||
|
||||
# Updating Administrator Password
|
||||
runSilent cmdOpenlitespeedAdminPassUpdate "$olsAdminPass" || {
|
||||
printDotText "Updating admin password" "$labelFail"
|
||||
return 1
|
||||
}
|
||||
printDotText "Updating admin password" "$labelDone"
|
||||
|
||||
# Adding redirect rules
|
||||
mkdir -p "$olsConfigPath/rules"
|
||||
cp -n "$appAssetsPath"/openlitespeed/rules/* "$olsConfigPath/rules/"
|
||||
chown -R "$ug" "$olsConfigPath/rules"
|
||||
chmod 750 -R "$olsConfigPath/rules"
|
||||
printDotText "Adding redirect rules" "$labelDone"
|
||||
|
||||
# Adding PHP configs
|
||||
local profileFile="$appAssetsPath/openlitespeed/profiles/memory-$kubeMemoryProfile.config"
|
||||
local children max_memory_limit memory_limit max_execution_time post_max_size upload_max_filesize
|
||||
children=$(configGet "$profileFile" "children")
|
||||
@@ -108,7 +78,15 @@ function cmdOpenlitespeedInit() {
|
||||
post_max_size=$(configGet "$profileFile" "post_max_size")
|
||||
upload_max_filesize=$(configGet "$profileFile" "upload_max_filesize")
|
||||
|
||||
local phpIniFile="$olsPhpIniPath/00-ols-master.ini"
|
||||
"$k3sCmd" kubectl -n kube-system patch svc traefik -p '{"spec": {"externalTrafficPolicy": "Local"}}'
|
||||
cmdOpenlitespeedWaitReady || return 1
|
||||
cmdOpenlitespeedAdminPassUpdate "$openlitespeedAdminPass" || return 1
|
||||
|
||||
local ug output error
|
||||
run ug error stat -c "%u:%g" "$openlitespeedConfigFile" || printDanger "$openlitespeedLabel Stat: $error"
|
||||
|
||||
printInfo "$openlitespeedLabel Adding PHP configs..."
|
||||
local phpIniFile="$openlitespeedPhpIniPath/00-ols-master.ini"
|
||||
fileBackup "$phpIniFile"
|
||||
cp -f -- "$appAssetsPath/openlitespeed/php/00-ols-master.ini" "$phpIniFile"
|
||||
sed -i \
|
||||
@@ -119,43 +97,58 @@ function cmdOpenlitespeedInit() {
|
||||
-e "s|{{post_max_size}}|$post_max_size|g" \
|
||||
-e "s|{{upload_max_filesize}}|$upload_max_filesize|g" \
|
||||
-- "$phpIniFile"
|
||||
find "$olsPhpIniPath" -type f -exec chmod 644 {} +
|
||||
printDotText "Adding PHP configs" "$labelDone"
|
||||
find "$openlitespeedPhpIniPath" -type f -exec chmod 644 {} +
|
||||
|
||||
# Path OLS Admin config
|
||||
runSilent openlitespeedAdminAllowList || {
|
||||
printDotText "Path OLS Admin config" "$labelFail"
|
||||
return 1
|
||||
}
|
||||
printDotText "Path OLS Admin config" "$labelDone"
|
||||
printInfo "$openlitespeedLabel Adding redirect rules..."
|
||||
mkdir -p "$openlitespeedConfigPath/rules"
|
||||
cp -n "$appAssetsPath"/openlitespeed/rules/* "$openlitespeedConfigPath/rules/"
|
||||
chown -R "$ug" "$openlitespeedConfigPath/rules"
|
||||
chmod 750 -R "$openlitespeedConfigPath/rules"
|
||||
|
||||
# Path OLS config
|
||||
openlitespeedConfigRebuild || {
|
||||
printDotText "Path OLS config" "$labelFail"
|
||||
return 1
|
||||
}
|
||||
printDotText "Path OLS config" "$labelDone"
|
||||
printInfo "$openlitespeedLabel Path OLS config..."
|
||||
fileBackup "$openlitespeedConfigFile"
|
||||
openlitespeedConfigEditSet '' useIpInProxyHeader 2 || return 1
|
||||
openlitespeedConfigEditSet 'fileAccessControl' checkSymbolLink 1 || return 1
|
||||
openlitespeedConfigEditSet 'accessControl' allow '10.42.0.0/16T, 10.43.0.0/16T' || return 1
|
||||
openlitespeedConfigEditDel 'ext[Pp]rocessor\h+lsphp' env 'PHPRC=*' || return 1
|
||||
openlitespeedConfigEditSet 'ext[Pp]rocessor\h+lsphp' backlog 100 || return 1
|
||||
openlitespeedConfigEditSet 'ext[Pp]rocessor\h+lsphp' procSoftLimit 700 || return 1
|
||||
openlitespeedConfigEditSet 'ext[Pp]rocessor\h+lsphp' procHardLimit 800 || return 1
|
||||
openlitespeedConfigEditSet 'ext[Pp]rocessor\h+lsphp' maxConns "$children" || return 1
|
||||
openlitespeedConfigEditSetMasked 'ext[Pp]rocessor\h+lsphp' env 'PHP_INI_SCAN_DIR=*' 'PHP_INI_SCAN_DIR=:/etc/ols-php-ini' || return 1
|
||||
openlitespeedConfigEditSetMasked 'ext[Pp]rocessor\h+lsphp' env 'PHP_LSAPI_CHILDREN=*' "PHP_LSAPI_CHILDREN=$children" || return 1
|
||||
openlitespeedConfigEditSetMasked 'ext[Pp]rocessor\h+lsphp' env 'LSAPI_AVOID_FORK=*' 'LSAPI_AVOID_FORK=0' || return 1
|
||||
openlitespeedConfigEditSetMasked 'ext[Pp]rocessor\h+lsphp' env 'LSAPI_MAX_IDLE=*' 'LSAPI_MAX_IDLE=120' || return 1
|
||||
openlitespeedConfigEditSetMasked 'ext[Pp]rocessor\h+lsphp' env 'LSAPI_MAX_IDLE_CHILDREN=*' 'LSAPI_MAX_IDLE_CHILDREN=1' || return 1
|
||||
openlitespeedConfigEditSetMasked 'ext[Pp]rocessor\h+lsphp' env 'LSAPI_PGRP_MAX_IDLE=*' 'LSAPI_PGRP_MAX_IDLE=300' || return 1
|
||||
openlitespeedConfigEditSetMasked 'ext[Pp]rocessor\h+lsphp' env 'LSAPI_MAX_PROCESS_TIME=*' 'LSAPI_MAX_PROCESS_TIME=300' || return 1
|
||||
openlitespeedConfigEditSetMasked 'ext[Pp]rocessor\h+lsphp' env 'LSAPI_SLOW_REQ_MSECS=*' 'LSAPI_SLOW_REQ_MSECS=5000' || return 1
|
||||
|
||||
printInfo "$openlitespeedLabel Path OLS Admin config..."
|
||||
openlitespeedAdminAllowList || return 1
|
||||
|
||||
cmdOpenlitespeedRestart
|
||||
cmdOpenlitespeedPhpKill all
|
||||
cmdOpenlitespeedPhpRestart
|
||||
|
||||
printSuccess "$openlitespeedLabel Initialization completed"
|
||||
}
|
||||
|
||||
# Updates OpenLiteSpeed Kubernetes resources (limits, replicas, etc.) without re-initialization.
|
||||
function cmdOpenlitespeedUpdate() {
|
||||
cmdOpenlitespeedYamlRender || return 1
|
||||
cmdK3sYamlApplyEx "$olsYaml" || return 1
|
||||
cmdK3sYamlApplyEx "$openlitespeedYaml" || return 1
|
||||
}
|
||||
|
||||
# Installs OpenLiteSpeed into Kubernetes and runs initialization.
|
||||
function cmdOpenlitespeedInstall() {
|
||||
cmdOpenlitespeedYamlRender || return 1
|
||||
cmdK3sYamlApplyEx "$olsYaml" || return 1
|
||||
cmdK3sYamlApplyEx "$openlitespeedYaml" || return 1
|
||||
cmdOpenlitespeedInit
|
||||
}
|
||||
|
||||
# Uninstalls OpenLiteSpeed Kubernetes resources.
|
||||
function cmdOpenlitespeedUninstall() {
|
||||
"$k3sCmd" kubectl delete -f "$olsYaml"
|
||||
"$k3sCmd" kubectl delete -f "$openlitespeedYaml"
|
||||
}
|
||||
|
||||
# Waits until OpenLiteSpeed WebAdmin PHP is ready.
|
||||
@@ -184,91 +177,101 @@ function cmdOpenlitespeedAdminPassUpdate() {
|
||||
local encrypt output error
|
||||
|
||||
run encrypt error openlitespeedExec /usr/local/lsws/admin/fcgi-bin/admin_php -q /usr/local/lsws/admin/misc/htpasswd.php "$password" || {
|
||||
printDotText "Get encrypt" "$labelFail"
|
||||
printDanger "$error"
|
||||
printDanger "$openlitespeedLabel Create pass | $error"
|
||||
return 1
|
||||
}
|
||||
printDotText "Get encrypt" "$labelDone"
|
||||
|
||||
run output error openlitespeedExec bash -c "echo '$user:$encrypt' > /usr/local/lsws/admin/conf/htpasswd" || {
|
||||
printDotText "Save data" "$labelFail"
|
||||
printDanger "$error"
|
||||
printDanger "$openlitespeedLabel Encrypt pass | $error"
|
||||
return 1
|
||||
}
|
||||
printDotText "Save data" "$labelDone"
|
||||
|
||||
# if admin... save to <hostname>.openlitespeed
|
||||
printSuccess "$openlitespeedLabel Authorization parameters updated"
|
||||
}
|
||||
|
||||
# Restarts OpenLiteSpeed on all OLS pods.
|
||||
function cmdOpenlitespeedRestart() {
|
||||
local podList error
|
||||
run podList error k3sPodListStatus "$olsKube" || { printDanger "Get pods: $error"; return 1; }
|
||||
[[ -n "$podList" ]] || { printDanger "Pods not found"; return 1; }
|
||||
local output error podList
|
||||
|
||||
local pod phase output
|
||||
while IFS='|' read -r pod phase; do
|
||||
printSection "$pod"
|
||||
if ! run podList error k3sPodListStatus "$openlitespeedKube"; then
|
||||
printDanger "Get pods: $error"
|
||||
elif [[ -z "$podList" ]]; then
|
||||
printDanger "Pods not found"
|
||||
else
|
||||
while IFS='|' read -r pod phase; do
|
||||
printSection "$pod"
|
||||
|
||||
if [[ "$phase" != "Running" ]]; then
|
||||
printDotText "Phase" "$fontRed$phase$fontReset"
|
||||
else
|
||||
printDotText "Phase" "$fontGreen$phase$fontReset"
|
||||
|
||||
if ! run output error openlitespeedPodExec "$pod" /usr/local/lsws/bin/lswsctrl restart; then
|
||||
printDotText "Restart" "$labelUnknown"
|
||||
printDanger "$error"
|
||||
elif [[ "$output" =~ "[OK]" ]]; then
|
||||
printDotText "Restart" "$fontGreen$output$fontReset"
|
||||
if [[ "$phase" != "Running" ]]; then
|
||||
printDotText "Phase" "$fontRed$phase$fontReset"
|
||||
else
|
||||
printDotText "Restart" "$fontRed$output$fontReset"
|
||||
printDotText "Phase" "$fontGreen$phase$fontReset"
|
||||
|
||||
if ! run output error openlitespeedPodExec "$pod" /usr/local/lsws/bin/lswsctrl restart; then
|
||||
printDotText "Restart" "$labelUnknown"
|
||||
printDanger "$error"
|
||||
elif [[ "$output" =~ "[OK]" ]]; then
|
||||
printDotText "Restart" "$fontGreen$output$fontReset"
|
||||
else
|
||||
printDotText "Restart" "$fontRed$output$fontReset"
|
||||
fi
|
||||
|
||||
# k3sRun wait --for=condition=Ready "pod/$pod" --timeout=10s >/dev/null 2>&1 || true
|
||||
fi
|
||||
fi
|
||||
done < <(awk 'NF' <<< "$podList")
|
||||
done < <(awk 'NF' <<< "$podList")
|
||||
fi
|
||||
}
|
||||
|
||||
# Restarts PHP workers on all OLS pods.
|
||||
function cmdOpenlitespeedPhpKill() {
|
||||
local target="$1"
|
||||
[[ -n "$target" ]] || { printRow; printDanger "Target not specified"; return 1; }
|
||||
function cmdOpenlitespeedPhpRestart() {
|
||||
local output error podList
|
||||
|
||||
local podList error
|
||||
run podList error k3sPodListStatus "$olsKube" || { printRow; printDanger "Get pods: $error"; return 1; }
|
||||
[[ -n "$podList" ]] || { printRow; printDanger "Pods not found"; return 1; }
|
||||
if ! run podList error k3sPodListStatus "$openlitespeedKube"; then
|
||||
printDanger "Get pods: $error"
|
||||
elif [[ -z "$podList" ]]; then
|
||||
printDanger "Pods not found"
|
||||
else
|
||||
while IFS='|' read -r pod phase; do
|
||||
printSection "$pod"
|
||||
|
||||
local uid=""
|
||||
if [[ "$target" != "all" ]]; then
|
||||
local vhostList
|
||||
run vhostList error openlitespeedConfigVhostList || { printRow; printDanger "Cannot get vhost list: $error"; return 1; }
|
||||
listContains "$target" "$vhostList" || { printRow; printDanger "Unknown domain: $target"; return 1; }
|
||||
uid=$(domainToUid "$target")
|
||||
[[ -n "$uid" ]] || { printDanger "Cannot resolve UID for: $target"; return 1; }
|
||||
fi
|
||||
|
||||
local pod phase
|
||||
while IFS='|' read -r pod phase; do
|
||||
printSection "$pod"
|
||||
|
||||
if [[ "$phase" != "Running" ]]; then
|
||||
printDotText "Phase" "$fontRed$phase$fontReset"
|
||||
else
|
||||
printDotText "Phase" "$fontGreen$phase$fontReset"
|
||||
|
||||
if [[ -n "$uid" ]]; then
|
||||
runSilent openlitespeedPodExec "$pod" pkill -u "$uid" -x lsphp
|
||||
if [[ "$phase" != "Running" ]]; then
|
||||
printDotText "Phase" "$fontRed$phase$fontReset"
|
||||
else
|
||||
runSilent openlitespeedPodExec "$pod" pkill -x lsphp
|
||||
printDotText "Phase" "$fontGreen$phase$fontReset"
|
||||
run output error openlitespeedPodExec "$pod" killall -USR1 lsphp || true
|
||||
printDotText "PHP" "process restart"
|
||||
fi
|
||||
printDotText "kill$fontBlue lsphp$fontReset processes for $target" "$labelDone"
|
||||
fi
|
||||
done < <(awk 'NF' <<< "$podList")
|
||||
done < <(awk 'NF' <<< "$podList")
|
||||
fi
|
||||
}
|
||||
|
||||
# Restarts PHP (kill) workers on all OLS pods.
|
||||
function cmdOpenlitespeedPhpKill() {
|
||||
local output error podList
|
||||
|
||||
if ! run podList error k3sPodListStatus "$openlitespeedKube"; then
|
||||
printDanger "Get pods: $error"
|
||||
elif [[ -z "$podList" ]]; then
|
||||
printDanger "Pods not found"
|
||||
else
|
||||
while IFS='|' read -r pod phase; do
|
||||
printSection "$pod"
|
||||
|
||||
if [[ "$phase" != "Running" ]]; then
|
||||
printDotText "Phase" "$fontRed$phase$fontReset"
|
||||
else
|
||||
printDotText "Phase" "$fontGreen$phase$fontReset"
|
||||
run output error openlitespeedPodExec "$pod" pkill -9 -f lsphp || true
|
||||
printDotText "PHP" "process kill"
|
||||
fi
|
||||
done < <(awk 'NF' <<< "$podList")
|
||||
fi
|
||||
}
|
||||
|
||||
# Prints OpenLiteSpeed and PHP versions for each OLS pod.
|
||||
function cmdOpenlitespeedInfo() {
|
||||
local output error podList ver pid
|
||||
|
||||
if ! run podList error k3sPodListStatus "$olsKube"; then
|
||||
if ! run podList error k3sPodListStatus "$openlitespeedKube"; then
|
||||
printDanger "Get pods: $error"
|
||||
elif [[ -z "$podList" ]]; then
|
||||
printDanger "Pods not found"
|
||||
@@ -310,7 +313,7 @@ function cmdOpenlitespeedInfo() {
|
||||
|
||||
printSection "Hosts"
|
||||
local vhostList vhostDown
|
||||
if run output error openlitespeedConfigVhostList; then
|
||||
if run output error openlitespeedVhostList; then
|
||||
mapfile -t vhostList < <(awk 'NF' <<< "$output")
|
||||
printDotText "all" "${#vhostList[@]}"
|
||||
else
|
||||
@@ -318,7 +321,7 @@ function cmdOpenlitespeedInfo() {
|
||||
printDanger "$error"
|
||||
fi
|
||||
|
||||
if run output error openlitespeedConfigVhostList "down"; then
|
||||
if run output error openlitespeedVhostList "down"; then
|
||||
mapfile -t vhostDownList < <(awk 'NF' <<< "$output")
|
||||
printDotText "down" "${#vhostDownList[@]}"
|
||||
else
|
||||
@@ -326,17 +329,18 @@ function cmdOpenlitespeedInfo() {
|
||||
printDanger "$error"
|
||||
fi
|
||||
|
||||
local count="$(find "$olsVhostsPath" -mindepth 1 -maxdepth 1 -type d | wc -l)"
|
||||
printDotText "directories" "$fontGray$olsVhostsPath$fontReset $count"
|
||||
local count="$(find "$vhostsPath" -mindepth 1 -maxdepth 1 -type d | wc -l)"
|
||||
printDotText "directories" "$fontGray$vhostsPath$fontReset $count"
|
||||
}
|
||||
|
||||
# Marks a virtual host as suspended.
|
||||
# $1 (domain): site domain name.
|
||||
function cmdOpenlitespeedVhostDown() {
|
||||
function cmdOpenlitespeedVHostDown() {
|
||||
local error
|
||||
|
||||
printRow
|
||||
|
||||
local error
|
||||
if ! runError error openlitespeedVhostConfigDown "$@"; then
|
||||
if ! runError error openlitespeedVHostDown "$@"; then
|
||||
printDotText "VHost down" "$labelFail"
|
||||
printDanger "$error"
|
||||
else
|
||||
@@ -347,11 +351,12 @@ function cmdOpenlitespeedVhostDown() {
|
||||
|
||||
# Marks a virtual host as active.
|
||||
# $1 (domain): site domain name.
|
||||
function cmdOpenlitespeedVhostUp() {
|
||||
function cmdOpenlitespeedVHostUp() {
|
||||
local error
|
||||
|
||||
printRow
|
||||
|
||||
local error
|
||||
if ! runError error openlitespeedVhostConfigUp "$@"; then
|
||||
if ! runError error openlitespeedVHostUp "$@"; then
|
||||
printDotText "VHost up" "$labelFail"
|
||||
printDanger "$error"
|
||||
else
|
||||
@@ -363,10 +368,11 @@ function cmdOpenlitespeedVhostUp() {
|
||||
# Lists virtual hosts with optional status filtering.
|
||||
# [$1] (type): all (default) | up | down.
|
||||
function cmdOpenlitespeedSiteList() {
|
||||
local output error type="${1:-all}"
|
||||
|
||||
printRow
|
||||
|
||||
local output error type="${1:-all}"
|
||||
if ! run output error openlitespeedConfigVhostList "$type"; then
|
||||
if ! run output error openlitespeedVhostList "$type"; then
|
||||
printDanger "$error"
|
||||
else
|
||||
printText "$output"
|
||||
@@ -375,66 +381,67 @@ function cmdOpenlitespeedSiteList() {
|
||||
|
||||
# Updates the Traefik middleware allowlist for OpenLiteSpeed WebAdmin.
|
||||
function cmdOpenlitespeedAdminWhiteList() {
|
||||
local output error
|
||||
|
||||
printRow
|
||||
|
||||
local output error
|
||||
run output error openlitespeedAdminWhiteList || { printDotText "Update" "$labelFail"; printDanger "$error"; return 1; }
|
||||
|
||||
printDotText "White list" "$output"
|
||||
printDotText "Update" "$labelDone"
|
||||
}
|
||||
|
||||
# Updates OpenLiteSpeed WebAdmin access control from current Traefik pod IPs.
|
||||
function cmdOpenlitespeedAdminAllowList() {
|
||||
printRow
|
||||
|
||||
local output error
|
||||
run output error openlitespeedAdminAllowList || { printDotText "Update" "$labelFail"; printDanger "$error"; return 1; }
|
||||
|
||||
printDotText "Allow list: ${output:-$labelNull}"
|
||||
printDotText "Update" "$labelDone"
|
||||
cmdOpenlitespeedRestart
|
||||
if ! run output error openlitespeedAdminWhiteList; then
|
||||
printDotText "Update" "$labelFail"
|
||||
printDanger "$error"
|
||||
else
|
||||
printDotText "White list" "$output"
|
||||
printDotText "Update" "$labelDone"
|
||||
fi
|
||||
}
|
||||
|
||||
# Sets aliases for an OpenLiteSpeed virtual host.
|
||||
# $1 (domain): primary site domain name.
|
||||
# $@ (...): alias domain names.
|
||||
function cmdOpenlitespeedVhostAliasSet() {
|
||||
local domain
|
||||
domain=$(domainPrepare "$1")
|
||||
function cmdOpenlitespeedAliasSet() {
|
||||
local output error
|
||||
|
||||
printRow
|
||||
|
||||
domainCheck "$domain" || return 1
|
||||
|
||||
local vhostList aliasList output error
|
||||
if ! run vhostList error openlitespeedConfigVhostList; then
|
||||
appError "Error retrieving vhost list: $error"
|
||||
return 1
|
||||
elif ! listContains "$domain" "$vhostList"; then
|
||||
appError "Domain not exists in OpenLiteSpeed config: $domain"
|
||||
return 1
|
||||
fi
|
||||
|
||||
run output error openlitespeedVhostSet "$@" || {
|
||||
printDotText "Set" "$labelFail"
|
||||
if ! run output error openlitespeedAliasSet "$@"; then
|
||||
printDanger "$error"
|
||||
return 1
|
||||
}
|
||||
elif [[ -z "$output" ]]; then
|
||||
printText "$labelNull"
|
||||
cmdOpenlitespeedRestart
|
||||
else
|
||||
printText "$output"
|
||||
cmdOpenlitespeedRestart
|
||||
fi
|
||||
}
|
||||
|
||||
printDotText "Alias" "${output:-$labelNull}"
|
||||
printDotText "Set" "$labelDone"
|
||||
cmdOpenlitespeedRestart
|
||||
# Updates OpenLiteSpeed WebAdmin access control from current Traefik pod IPs.
|
||||
function cmdOpenlitespeedAdminAllowList() {
|
||||
local output error
|
||||
|
||||
printRow
|
||||
|
||||
if ! run output error openlitespeedAdminAllowList; then
|
||||
printDotText "Update" "$labelFail"
|
||||
printDanger "$error"
|
||||
elif [[ -z "$output" ]]; then
|
||||
printDotText "Allow list" "$labelNull"
|
||||
printDotText "Update" "$labelDone"
|
||||
cmdOpenlitespeedRestart
|
||||
else
|
||||
printDotText "Allow list" "$output"
|
||||
printDotText "Update" "$labelDone"
|
||||
cmdOpenlitespeedRestart
|
||||
fi
|
||||
}
|
||||
|
||||
# Lists aliases for a domain or all domains.
|
||||
# [$1] (target): domain name, or "all" to list all.
|
||||
function cmdOpenlitespeedAliasList() {
|
||||
local output error domain target="$1"
|
||||
|
||||
printRow
|
||||
|
||||
local output error domain target="$1"
|
||||
if [[ "$target" == all ]]; then
|
||||
if ! run output error openlitespeedConfigAliasList; then
|
||||
if ! run output error openlitespeedAliasList; then
|
||||
printDanger "$error"
|
||||
elif [[ -z "$output" ]]; then
|
||||
printText "$labelNull"
|
||||
@@ -443,7 +450,7 @@ function cmdOpenlitespeedAliasList() {
|
||||
fi
|
||||
else
|
||||
domain=$(domainPrepare "$target")
|
||||
if ! run output error openlitespeedConfigVhostAliasList "$domain"; then
|
||||
if ! run output error openlitespeedVhostAlias "$domain"; then
|
||||
printDanger "$error"
|
||||
elif [[ -z "$output" ]]; then
|
||||
printText "$labelNull"
|
||||
@@ -455,9 +462,10 @@ function cmdOpenlitespeedAliasList() {
|
||||
|
||||
# Tests the OpenLiteSpeed configuration inside the container.
|
||||
function cmdOpenlitespeedConfigCheck() {
|
||||
local output error
|
||||
|
||||
printRow
|
||||
|
||||
local output error
|
||||
run output error openlitespeedExec sh -lc "/usr/local/lsws/bin/openlitespeed -t 2>/dev/null || true"
|
||||
if grep -qi 'configuration failed!' <<< "$output"; then
|
||||
printDotText "Check config" "$labelFail"
|
||||
@@ -475,7 +483,7 @@ function cmdOpenlitespeedVhostRebuild() {
|
||||
|
||||
if [[ -z "$target" ]]; then
|
||||
printDanger "Target not specified";
|
||||
elif ! run vhostList error openlitespeedConfigVhostList; then
|
||||
elif ! run vhostList error openlitespeedVhostList; then
|
||||
printDanger "Cannot get vhost list: $error";
|
||||
elif [[ "$target" == "all" ]]; then
|
||||
local domain
|
||||
|
||||
@@ -113,10 +113,6 @@ EOF
|
||||
function cmdPostfixInit() {
|
||||
printSection "Initialization..."
|
||||
|
||||
touch "$postfixConfigPath/$postfixDomainsFile" || return 1
|
||||
touch "$postfixConfigPath/$postfixAliasesFile" || return 1
|
||||
touch "$postfixConfigPath/$postfixSendersFile" || return 1
|
||||
|
||||
postfixDkimAdd "$postfixHost" || {
|
||||
printDotText "Add DKIM for host" "$labelFail"
|
||||
return 1
|
||||
@@ -150,20 +146,6 @@ function cmdPostfixUninstall() {
|
||||
"$k3sCmd" kubectl delete -f "$postfixYaml"
|
||||
}
|
||||
|
||||
function cmdPostfixUser() {
|
||||
local output error
|
||||
|
||||
printRow
|
||||
|
||||
if ! run output error postfixUserList; then
|
||||
printDanger "$error"
|
||||
elif [[ -z "$output" ]]; then
|
||||
printText "$labelNull"
|
||||
else
|
||||
printText "$output"
|
||||
fi
|
||||
}
|
||||
|
||||
# Prints the Postfix mail version.
|
||||
function cmdPostfixInfo() {
|
||||
local output error podList ver pid
|
||||
@@ -208,69 +190,123 @@ function cmdPostfixInfo() {
|
||||
fi
|
||||
}
|
||||
|
||||
# Sets a virtual alias forward-to address for a domain and saves it to site config.
|
||||
# $1 (domain): site domain name.
|
||||
# $2 (mail): forward-to email address.
|
||||
function cmdPostfixVirtualAliasSetEx() {
|
||||
local domain="$1"
|
||||
[[ -n "$domain" ]] || { printDanger "$postfixLabel Domain not specified"; return 1; }
|
||||
local mail="$2"
|
||||
[[ -n "$mail" ]] || { printDanger "$postfixLabel Mail not specified"; return 1; }
|
||||
|
||||
local domainList output error
|
||||
if ! run domainList error postfixDomainList; then
|
||||
printDanger "$postfixLabel postfixDomainList: $error"
|
||||
return 1
|
||||
elif ! listContains "$domain" "$domainList"; then
|
||||
printDanger "$postfixLabel Domain not found in postfixDomainList"
|
||||
return 1
|
||||
elif ! run output error siteConfigSet "$domain" "postfixForwardTo" "$mail"; then
|
||||
printDanger "$postfixLabel siteConfigSet: $error"
|
||||
elif ! run output error postfixVirtualAliasSet "@$domain" "$mail"; then
|
||||
printDanger "$postfixLabel postfixVirtualAliasSet: $error"
|
||||
fi
|
||||
}
|
||||
|
||||
# Checks MTA host DNS records (A, SPF, PTR, DKIM) against configured values.
|
||||
function cmdPostfixMtaDnsCheck() {
|
||||
local label output error text
|
||||
|
||||
printSection "MTA DNS: $postfixHost"
|
||||
|
||||
# A record
|
||||
if ! run output error dig +short A "$postfixHost" "$dnsResolver"; then
|
||||
printDotText "A record" "$fontRed${output:-$error}$fontReset"
|
||||
label="$postfixLabel A record: $postfixHost"
|
||||
if ! run output error dig +short A "$postfixHost" "$postfixResolver"; then
|
||||
printDanger "$label"
|
||||
else
|
||||
text=$(printf '%s' "$output" | paste -sd, - | sed 's/,/ \/ /g')
|
||||
if grep -Fxq -- "$postfixIp" <<<"$output"; then
|
||||
printDotText "A record" "$fontGreen$text$fontReset"
|
||||
printSuccess "$label | $text"
|
||||
else
|
||||
printDotText "A record" "$fontYellow$text$fontReset"
|
||||
printWarning "$label | $text"
|
||||
fi
|
||||
fi
|
||||
|
||||
# SPF record
|
||||
if ! run output error dig +short TXT "$postfixHost" "$dnsResolver"; then
|
||||
printDotText "SPF record" "$fontRed${output:-$error}$fontReset"
|
||||
label="$postfixLabel SPF record: $postfixHost"
|
||||
if ! run output error dig +short TXT "$postfixHost" "$postfixResolver"; then
|
||||
printDanger "$label"
|
||||
elif grep -Eq '^"?v=spf1([[:space:]]|")' <<<"$output"; then
|
||||
printDotText "SPF record" "$fontGreen$output$fontReset"
|
||||
printSuccess "$label | $output"
|
||||
else
|
||||
printDotText "SPF record" "$fontRed$output$fontReset"
|
||||
printWarning "$label | $output"
|
||||
fi
|
||||
|
||||
# PTR record
|
||||
if ! run output error dig -x "$postfixIp" +short "$dnsResolver"; then
|
||||
printDotText "PTR record" "$fontRed${output:-$error}$fontReset"
|
||||
label="$postfixLabel PTR record: $postfixHost"
|
||||
if ! run output error dig -x "$postfixIp" +short "$postfixResolver"; then
|
||||
printDanger "$label"
|
||||
else
|
||||
text=$(printf '%s' "$output" | paste -sd, - | sed 's/,/ \/ /g')
|
||||
if grep -Fxq -- "$postfixHost." <<<"$output"; then
|
||||
printDotText "PTR record" "$fontGreen$text$fontReset"
|
||||
printSuccess "$label | $text"
|
||||
else
|
||||
printDotText "PTR record" "$fontYellow$text$fontReset"
|
||||
printWarning "$label | $text"
|
||||
fi
|
||||
fi
|
||||
|
||||
# DKIM record
|
||||
label="$postfixLabel DKIM record: $postfixHost"
|
||||
if ! run output error dig +short TXT "$postfixDkimSelector._domainkey.$postfixHost"; then
|
||||
printDotText "DKIM record" "$fontRed${output:-$error}$fontReset"
|
||||
printDanger "$label | $error"
|
||||
else
|
||||
local dkimDnsNorm dkimFileRaw dkimFileNorm
|
||||
dkimDnsNorm=$(
|
||||
printf '%s\n' "$output" |
|
||||
tr -d '\n' |
|
||||
sed -e 's/"//g' -e 's/[[:space:]]//g' |
|
||||
sed -n 's/.*p=\([^;]*\).*/\1/p'
|
||||
printf '%s\n' "$output" |
|
||||
tr -d '\n' |
|
||||
sed -e 's/"//g' -e 's/[[:space:]]//g' |
|
||||
sed -n 's/.*p=\([^;]*\).*/\1/p'
|
||||
)
|
||||
|
||||
dkimFileRaw=$(postfixDkimGet "$postfixHost")
|
||||
dkimFileNorm=$(
|
||||
printf '%s\n' "$dkimFileRaw" |
|
||||
tr -d '\n' |
|
||||
sed -e 's/[()"]//g' -e 's/[[:space:]]//g' |
|
||||
sed -n 's/.*p=\([^;]*\).*/\1/p'
|
||||
printf '%s\n' "$dkimFileRaw" |
|
||||
tr -d '\n' |
|
||||
sed -e 's/[()"]//g' -e 's/[[:space:]]//g' |
|
||||
sed -n 's/.*p=\([^;]*\).*/\1/p'
|
||||
)
|
||||
|
||||
if [[ "$dkimDnsNorm" == "$dkimFileNorm" ]]; then
|
||||
printText "$fontGreen$dkimDnsNorm$fontReset"
|
||||
printSuccess "$label | OK"
|
||||
else
|
||||
printText "DNS : $fontYellow$dkimDnsNorm$fontReset"
|
||||
printText "File: $fontYellow$dkimFileNorm$fontReset"
|
||||
printWarning "$label | DNS : $dkimDnsNorm"
|
||||
printWarning "$label | FILE: $dkimFileNorm"
|
||||
fi
|
||||
fi
|
||||
}
|
||||
|
||||
# Prints domain/alias/sender/SASL lists; accepts domain/alias/senders/sasl as filter.
|
||||
# [$1] (filter): domain|alias|senders|sasl; omit to print all.
|
||||
function cmdPostfixList() {
|
||||
case "$1" in
|
||||
'domain')
|
||||
postfixDomainList
|
||||
;;
|
||||
'alias')
|
||||
postfixAliasList
|
||||
;;
|
||||
'senders')
|
||||
postfixSendersList
|
||||
;;
|
||||
'sasl')
|
||||
postfixSaslUserList
|
||||
;;
|
||||
*)
|
||||
printInfo "$postfixLabel Domains"
|
||||
postfixDomainList
|
||||
|
||||
printInfo "$postfixLabel Aliases"
|
||||
postfixAliasList
|
||||
|
||||
printInfo "$postfixLabel Senders"
|
||||
postfixSendersList
|
||||
|
||||
printInfo "$postfixLabel SASL users"
|
||||
postfixSaslUserList
|
||||
;;
|
||||
esac
|
||||
}
|
||||
|
||||
@@ -101,7 +101,7 @@ function cmdRedisUninstall() {
|
||||
|
||||
# local output error podList ver pid
|
||||
|
||||
# if ! run podList error k3sPodListStatus "$olsKube"; then
|
||||
# if ! run podList error k3sPodListStatus "$openlitespeedKube"; then
|
||||
# printDanger "Get pods: $error"
|
||||
# elif [[ -z "$podList" ]]; then
|
||||
# printDanger "Pods not found"
|
||||
|
||||
@@ -17,7 +17,7 @@ function restoreSiteFiles() {
|
||||
domain=$(domainPrepare "$1")
|
||||
domainCheck "$domain" || return 1
|
||||
|
||||
local target="$olsVhostsPath/$domain"
|
||||
local target="$vhostsPath/$domain"
|
||||
|
||||
local source="$2"
|
||||
if [[ -z "$source" ]]; then
|
||||
@@ -257,7 +257,7 @@ function restoreSite() {
|
||||
# Config
|
||||
printInfo "$restoreLabel $domain | Config: $sourceConf"
|
||||
if [[ -n "$sourceConf" ]]; then
|
||||
if ! runError error cp -f -- "$sourceConf" "$olsVhostsConfigPath/$domain.conf"; then
|
||||
if ! runError error cp -f -- "$sourceConf" "$openlitespeedVhostsPath/$domain.conf"; then
|
||||
printDanger "$restoreLabel $domain | Config: $error"
|
||||
return 1
|
||||
fi
|
||||
|
||||
@@ -202,23 +202,27 @@ function cmdOpenlitespeed() {
|
||||
;;
|
||||
up)
|
||||
printTitle " $openlitespeedLabel Up $@"
|
||||
cmdOpenlitespeedVhostUp "$@"
|
||||
cmdOpenlitespeedVHostUp "$@"
|
||||
;;
|
||||
down)
|
||||
printTitle " $openlitespeedLabel Down $@"
|
||||
cmdOpenlitespeedVhostDown "$@"
|
||||
cmdOpenlitespeedVHostDown "$@"
|
||||
;;
|
||||
alias)
|
||||
printTitle " $openlitespeedLabel Alias $1"
|
||||
cmdOpenlitespeedVhostAliasSet "$@"
|
||||
cmdOpenlitespeedAliasSet "$@"
|
||||
;;
|
||||
restart)
|
||||
printTitle " $openlitespeedLabel Restart"
|
||||
cmdOpenlitespeedRestart
|
||||
;;
|
||||
php_kill)
|
||||
printTitle " $openlitespeedLabel Kill PHP $@"
|
||||
cmdOpenlitespeedPhpKill "$@"
|
||||
restart_php)
|
||||
printTitle " $openlitespeedLabel Restart PHP"
|
||||
cmdOpenlitespeedPhpRestart
|
||||
;;
|
||||
kill_php)
|
||||
printTitle " $openlitespeedLabel Kill PHP"
|
||||
cmdOpenlitespeedPhpKill
|
||||
;;
|
||||
white_list)
|
||||
printTitle " $openlitespeedLabel White list update"
|
||||
@@ -276,13 +280,22 @@ function cmdPostfix() {
|
||||
printTitle " $postfixLabel Info"
|
||||
cmdPostfixInfo
|
||||
;;
|
||||
status)
|
||||
printTitle " $postfixLabel Status"
|
||||
cmdPostfixMtaDnsCheck
|
||||
list)
|
||||
if [[ -z "$1" ]]; then
|
||||
printInfo " $postfixLabel List all"
|
||||
else
|
||||
printInfo " $postfixLabel List $action"
|
||||
fi
|
||||
cmdPostfixList "$@"
|
||||
;;
|
||||
user)
|
||||
printTitle " $postfixLabel User list"
|
||||
cmdPostfixUser
|
||||
domain)
|
||||
printInfo " $postfixLabel Domain add"
|
||||
postfixDomainAdd "$@"
|
||||
postfixPostmapRebuild
|
||||
;;
|
||||
alias)
|
||||
printInfo " $postfixLabel Set alias for domain"
|
||||
cmdPostfixVirtualAliasSetEx "$@"
|
||||
;;
|
||||
dkim)
|
||||
printInfo " $postfixLabel DKIM record for DNS (autocreate)"
|
||||
@@ -544,51 +557,21 @@ function cmdCron() {
|
||||
}
|
||||
|
||||
function cmdBackup() {
|
||||
local action="${1:-}"
|
||||
shift || true
|
||||
|
||||
case "$action" in
|
||||
run)
|
||||
printTitle " $systemLabel Backup of target"
|
||||
cmdBackupRun "$@"
|
||||
;;
|
||||
list)
|
||||
printTitle " $systemLabel List of backups on local storage"
|
||||
cmdBackupList
|
||||
;;
|
||||
size)
|
||||
printTitle " $systemLabel List of Backup Sizes"
|
||||
cmdBackupSize
|
||||
;;
|
||||
# remove)
|
||||
# printTitle " $backupLabel Remove of backups on local storage"
|
||||
# cmdStorageBackupRemove
|
||||
# ;;
|
||||
*)
|
||||
printTitle " $systemLabel Backup"
|
||||
printRow
|
||||
printWarning "Unsupported or empty command: $action"
|
||||
cmdHelpBackup
|
||||
;;
|
||||
esac
|
||||
if [[ -n "$1" ]]; then
|
||||
cmdBackupRun "$@"
|
||||
else
|
||||
printDanger "$backupLabel Empty command"
|
||||
cmdHelpBackup
|
||||
fi
|
||||
}
|
||||
|
||||
function cmdRestore() {
|
||||
local action="${1:-}"
|
||||
shift || true
|
||||
|
||||
case "$action" in
|
||||
run)
|
||||
printTitle " $restoreLabel Backup of target"
|
||||
restoreRun "$@"
|
||||
;;
|
||||
*)
|
||||
printTitle " $restoreLabel"
|
||||
printRow
|
||||
printWarning "Unsupported or empty command: $action"
|
||||
cmdHelpRestore
|
||||
;;
|
||||
esac
|
||||
if [[ -n "$1" ]]; then
|
||||
restoreRun "$@"
|
||||
else
|
||||
printDanger "$restoreLabel Empty command"
|
||||
cmdHelpRestore
|
||||
fi
|
||||
}
|
||||
|
||||
function cmdStorage() {
|
||||
@@ -604,10 +587,6 @@ function cmdStorage() {
|
||||
printTitle " $systemLabel Comparison table"
|
||||
cmdStorageBackupCompare
|
||||
;;
|
||||
size)
|
||||
printTitle " $systemLabel List of Backup Sizes on external storage"
|
||||
cmdStorageBackupSize
|
||||
;;
|
||||
sync)
|
||||
printTitle " $systemLabel Synchronization with external storage"
|
||||
cmdStorageBackupSync "$@"
|
||||
@@ -625,12 +604,6 @@ function cmdStorage() {
|
||||
esac
|
||||
}
|
||||
|
||||
# Dispatches a named script sub-command and redirects output to a timestamped log file.
|
||||
# $1 (option): script name (backup, mariadb-dump, worker-observer, metric-kube, metric-sites, diag-report-ai-short, diag-report-ai-full).
|
||||
function cmdScript() {
|
||||
cmdScriptRun "$@"
|
||||
}
|
||||
|
||||
function cmdInstall() {
|
||||
printTitle " $ks3Label Full install"
|
||||
if cmdRouterConfirm "Are you sure you want to$fontRed INSTALL$fontReset $fontBlue FULL infrastrutute$fontReset?"; then
|
||||
@@ -677,8 +650,8 @@ function cmdMalware() {
|
||||
printTitle " Malware user list"
|
||||
cmdMalwareUserList
|
||||
;;
|
||||
plugin)
|
||||
printTitle " Malware plugin list"
|
||||
muplugin)
|
||||
printTitle " Malware MU plugin list"
|
||||
cmdMalwareMuPluginList
|
||||
;;
|
||||
file)
|
||||
@@ -701,30 +674,42 @@ function cmdRouter() {
|
||||
printHeader
|
||||
|
||||
case "$action" in
|
||||
-k|--k3s) cmdK3s "$@" ;;
|
||||
-m|--mariadb) cmdMariadb "$@" ;;
|
||||
-r|--redis) cmdRedis "$@" ;;
|
||||
-o|--ols) cmdOpenlitespeed "$@" ;;
|
||||
-p|--postfix) cmdPostfix "$@" ;;
|
||||
-w|--worker) cmdWorker "$@" ;;
|
||||
-s|--site) cmdSite "$@" ;;
|
||||
--metric) cmdMetric "$@" ;;
|
||||
--wp) cmdWordpress "$@" ;;
|
||||
--sftp) cmdSftp "$@" ;;
|
||||
--cron) cmdCron "$@" ;;
|
||||
--shell) cmdShell "$@" ;;
|
||||
--log) cmdLog "$@" ;;
|
||||
--describe) cmdDescribe "$@" ;;
|
||||
--delete) cmdDelete "$@" ;;
|
||||
--backup) cmdBackup "$@" ;;
|
||||
--restore) cmdRestore "$@" ;;
|
||||
--storage) cmdStorage "$@" ;;
|
||||
--script) cmdScript "$@" ;;
|
||||
--install) cmdInstall "$@" ;;
|
||||
--test) cmdTest "$@" ;;
|
||||
--malware) cmdMalware "$@" ;;
|
||||
--help) cmdHelp "$@" ;;
|
||||
dev) appDev "$@" ;;
|
||||
-k|--k3s) cmdK3s "$@" ;;
|
||||
-m|--mariadb) cmdMariadb "$@" ;;
|
||||
-r|--redis) cmdRedis "$@" ;;
|
||||
-o|--ols) cmdOpenlitespeed "$@" ;;
|
||||
-p|--postfix) cmdPostfix "$@" ;;
|
||||
-w|--worker) cmdWorker "$@" ;;
|
||||
-s|--site) cmdSite "$@" ;;
|
||||
--metric) cmdMetric "$@" ;;
|
||||
--wp) cmdWordpress "$@" ;;
|
||||
--sftp) cmdSftp "$@" ;;
|
||||
--cron) cmdCron "$@" ;;
|
||||
--shell)
|
||||
printTitle " Shell $@"
|
||||
cmdShell "$@"
|
||||
;;
|
||||
--log)
|
||||
printTitle " Log $@"
|
||||
cmdLog "$@"
|
||||
;;
|
||||
--describe)
|
||||
printTitle " Describe $@"
|
||||
cmdDescribe "$@"
|
||||
;;
|
||||
--delete)
|
||||
printTitle " Delete $@ $fontRed[DANGER]$fontReset"
|
||||
cmdDelete "$@"
|
||||
;;
|
||||
-b|--backup) cmdBackup "$@" ;;
|
||||
--restore) cmdRestore "$@" ;;
|
||||
--storage) cmdStorage "$@" ;;
|
||||
--script) cmdScript "$@" ;;
|
||||
--install) cmdInstall "$@" ;;
|
||||
--test) cmdTest "$@" ;;
|
||||
--malware) cmdMalware "$@" ;;
|
||||
--help) cmdHelp "$@" ;;
|
||||
dev) appDev "$@" ;;
|
||||
esac
|
||||
|
||||
local status=$?
|
||||
|
||||
@@ -53,14 +53,18 @@ function cmdScriptDiagReportAi() {
|
||||
printFinish
|
||||
}
|
||||
|
||||
function cmdScriptRun() {
|
||||
# Dispatches a named script sub-command and redirects output to a timestamped log file.
|
||||
# $1 (option): script name (backup, mariadb-dump, worker-observer, metric-kube, metric-sites, diag-report-ai-short, diag-report-ai-full).
|
||||
function cmdScript() {
|
||||
local option="$1"
|
||||
|
||||
printText "Output: $logPath/$option/${appDate}_$appTime.log"
|
||||
printText "$logPath/$option/${appDate}_$appTime.log"
|
||||
printRow
|
||||
|
||||
printFile="$logPath/$option/${appDate}_$appTime.log"
|
||||
local logFileOld="$logFile"
|
||||
|
||||
local logFileOld
|
||||
logFileOld="$logFile"
|
||||
logFile=""
|
||||
|
||||
case "$option" in
|
||||
@@ -85,9 +89,6 @@ function cmdScriptRun() {
|
||||
diag-report-ai-full)
|
||||
cmdScriptDiagReportAi "full"
|
||||
;;
|
||||
unigma)
|
||||
cmdUnigma
|
||||
;;
|
||||
*)
|
||||
printFile=""
|
||||
logFile="$logFileOld"
|
||||
|
||||
@@ -9,10 +9,10 @@ siteWordpressLabel="[Wordpress]"
|
||||
function cmdSiteAdd() {
|
||||
local domain sourceFiles
|
||||
domain=$(domainPrepare "$1")
|
||||
shift || true
|
||||
shift
|
||||
|
||||
sourceFiles="${1:-$appAssetsPath/vhost/default}"
|
||||
shift || true
|
||||
shift
|
||||
|
||||
printSection "Add site"
|
||||
printDotText "domain" "$domain"
|
||||
@@ -36,10 +36,10 @@ function cmdSiteAdd() {
|
||||
function cmdSiteRemove() {
|
||||
local domain mode
|
||||
domain=$(domainPrepare "$1")
|
||||
shift || true
|
||||
shift
|
||||
|
||||
mode="$1"
|
||||
shift || true
|
||||
shift
|
||||
|
||||
if [[ ! "$mode" == "-f" && ! "$mode" == "--force" ]]; then
|
||||
if ! cmdRouterConfirm "Are you sure you want to$fontRed DELETE$fontReset the site $fontBlue$domain$fontReset?"; then
|
||||
@@ -141,13 +141,13 @@ function cmdSiteRename() {
|
||||
function cmdSiteAddWordpress() {
|
||||
local domain sourceFiles
|
||||
domain=$(domainPrepare "$1")
|
||||
shift || true
|
||||
shift
|
||||
|
||||
sourceFiles="${1:-$appAssetsPath/vhost/wordpress}"
|
||||
if [[ ! -e "$sourceFiles" ]]; then
|
||||
sourceFiles="$appAssetsPath/vhost/wordpress.tar.gz"
|
||||
fi
|
||||
shift || true
|
||||
shift
|
||||
|
||||
printSection "Add site (Wordpress)"
|
||||
printDotText "domain" "$domain"
|
||||
@@ -185,7 +185,7 @@ function cmdSiteConfigRebuild() {
|
||||
printDotText "OLS vhost" "$labelDone"
|
||||
fi
|
||||
|
||||
if ! runError error openlitespeedConfigVhostSet "$domain"; then
|
||||
if ! runError error openlitespeedConfigRebuild "$domain"; then
|
||||
printDotText "OLS config" "$labelFail"
|
||||
printDanger "$error"
|
||||
else
|
||||
@@ -247,7 +247,7 @@ function cmdSitePasswordReset() {
|
||||
|
||||
if [[ -z "$target" ]]; then
|
||||
printDanger "Target not specified";
|
||||
elif ! run vhostList error openlitespeedConfigVhostList; then
|
||||
elif ! run vhostList error openlitespeedVhostList; then
|
||||
printDanger "Cannot get vhost list: $error";
|
||||
elif [[ "$target" == "all" ]]; then
|
||||
local domain
|
||||
@@ -280,7 +280,7 @@ function cmdSiteAuthReset() {
|
||||
|
||||
if [[ -z "$target" ]]; then
|
||||
printDanger "Target not specified";
|
||||
elif ! run vhostList error openlitespeedConfigVhostList; then
|
||||
elif ! run vhostList error openlitespeedVhostList; then
|
||||
printDanger "Cannot get vhost list: $error";
|
||||
elif [[ "$target" == "all" ]]; then
|
||||
local domain
|
||||
@@ -375,7 +375,7 @@ function cmdSiteInfo() {
|
||||
fi
|
||||
|
||||
local limits blockLimit inodeLimit
|
||||
if ! run limits error openlitespeedVhostQuotaGet "$ug"; then
|
||||
if ! run limits error openlitespeedVhostQuota "$ug"; then
|
||||
printDotText "quota block limit" "$labelUnknown"
|
||||
printDotText "quota inode limit" "$labelUnknown"
|
||||
else
|
||||
@@ -410,25 +410,25 @@ function cmdSiteInfo() {
|
||||
fi
|
||||
|
||||
printSection "OpenLiteSpeed"
|
||||
if [[ ! -f "$olsVhostsConfigPath/$domain.conf" ]]; then
|
||||
printDotText "file$fontReset" "$fontRed$olsVhostsConfigPath/$domain.conf$fontReset"
|
||||
if [[ ! -f "$openlitespeedVhostsPath/$domain.conf" ]]; then
|
||||
printDotText "file$fontReset" "$fontRed$openlitespeedVhostsPath/$domain.conf$fontReset"
|
||||
printDotText "file$fontReset" "${fontRed}not found$fontReset"
|
||||
else
|
||||
printDotText "file$fontReset" "$fontGreen$olsVhostsConfigPath/$domain.conf$fontReset"
|
||||
printDotText "file$fontReset" "$fontGreen$openlitespeedVhostsPath/$domain.conf$fontReset"
|
||||
fi
|
||||
|
||||
if [[ ! -d "$olsVhostsPath/$domain" ]]; then
|
||||
printDotText "path$fontReset" "$fontRed$olsVhostsPath/$domain$fontReset"
|
||||
if [[ ! -d "$vhostsPath/$domain" ]]; then
|
||||
printDotText "path$fontReset" "$fontRed$vhostsPath/$domain$fontReset"
|
||||
printDotText "path$fontReset" "${fontRed}not found$fontReset"
|
||||
else
|
||||
printDotText "path$fontReset" "$fontGreen$olsVhostsPath/$domain$fontReset"
|
||||
printDotText "path$fontReset" "$fontGreen$vhostsPath/$domain$fontReset"
|
||||
fi
|
||||
|
||||
if [[ ! -d "$olsPrivatePath/$domain" ]]; then
|
||||
printDotText "data$fontReset" "$fontRed$olsPrivatePath/$domain$fontReset"
|
||||
if [[ ! -d "$openlitespeedVhostDataPath/$domain" ]]; then
|
||||
printDotText "data$fontReset" "$fontRed$openlitespeedVhostDataPath/$domain$fontReset"
|
||||
printDotText "data$fontReset" "${fontRed}not found$fontReset"
|
||||
else
|
||||
printDotText "data$fontReset" "$fontGreen$olsPrivatePath/$domain$fontReset"
|
||||
printDotText "data$fontReset" "$fontGreen$openlitespeedVhostDataPath/$domain$fontReset"
|
||||
fi
|
||||
}
|
||||
|
||||
@@ -489,7 +489,7 @@ function cmdSiteStatus() {
|
||||
fi
|
||||
|
||||
local limits blockLimit inodeLimit
|
||||
if ! run limits error openlitespeedVhostQuotaGet "$ug"; then
|
||||
if ! run limits error openlitespeedVhostQuota "$ug"; then
|
||||
printDotText "quota block limit" "$labelFail"
|
||||
printDotText "quota inode limit" "$labelFail"
|
||||
else
|
||||
@@ -519,7 +519,7 @@ function cmdSiteStatus() {
|
||||
|
||||
printSection "Path | existence, owner, permissions, ACL:nobody"
|
||||
local path
|
||||
path="$olsVhostsPath/$domain"
|
||||
path="$vhostsPath/$domain"
|
||||
label="vhost $fontBlue/$fontReset"
|
||||
note="${fontGray}755:root:root$fontReset"
|
||||
if [[ ! -d "$path" ]]; then
|
||||
@@ -530,7 +530,7 @@ function cmdSiteStatus() {
|
||||
printDotText "$label" "$note $labelPass"
|
||||
fi
|
||||
|
||||
path="$olsVhostsPath/$domain/www"
|
||||
path="$vhostsPath/$domain/www"
|
||||
label="vhost $fontBlue/www$fontReset"
|
||||
note="${fontGray}2750:u:g acl:r-x$fontReset"
|
||||
if [[ ! -d "$path" ]]; then
|
||||
@@ -547,7 +547,7 @@ function cmdSiteStatus() {
|
||||
local dir
|
||||
dirs=(session tmp)
|
||||
for dir in "${dirs[@]}"; do
|
||||
path="$olsVhostsPath/$domain/$dir"
|
||||
path="$vhostsPath/$domain/$dir"
|
||||
label="vhost $fontBlue/$dir$fontReset"
|
||||
note="${fontGray}770:u:g acl:rwx$fontReset"
|
||||
if [[ ! -d "$path" ]]; then
|
||||
@@ -561,7 +561,7 @@ function cmdSiteStatus() {
|
||||
fi
|
||||
done
|
||||
|
||||
path="$olsPrivatePath/$domain"
|
||||
path="$openlitespeedVhostDataPath/$domain"
|
||||
label="vhost-data $fontBlue/$fontReset"
|
||||
note="${fontGray}750:u:g acl:r-x$fontReset"
|
||||
if [[ ! -d "$path" ]]; then
|
||||
@@ -574,7 +574,7 @@ function cmdSiteStatus() {
|
||||
printDotText "$label" "$note $labelPass"
|
||||
fi
|
||||
|
||||
path="$olsPrivatePath/$domain/bootstrap.php"
|
||||
path="$openlitespeedVhostDataPath/$domain/bootstrap.php"
|
||||
label="vhost-data $fontBlue/bootstrap.php$fontReset"
|
||||
note="${fontGray}600:u:g acl:r--$fontReset"
|
||||
if [[ ! -f "$path" ]]; then
|
||||
@@ -589,7 +589,7 @@ function cmdSiteStatus() {
|
||||
# fileSignatureAclDiff "$path" "user:nobody:r--"
|
||||
|
||||
printSection "OpenLiteSpeed"
|
||||
if ! run vhostList error openlitespeedConfigVhostList; then
|
||||
if ! run vhostList error openlitespeedVhostList; then
|
||||
printDotText "get vhost list" "$labelFail"
|
||||
else
|
||||
note="$fontGray$domain$fontReset"
|
||||
@@ -600,7 +600,7 @@ function cmdSiteStatus() {
|
||||
fi
|
||||
fi
|
||||
note="$fontGray$domain.conf$fontReset"
|
||||
if [[ ! -f "$olsVhostsConfigPath/$domain.conf" ]]; then
|
||||
if [[ ! -f "$openlitespeedVhostsPath/$domain.conf" ]]; then
|
||||
printDotText "config" "$note $labelFail"
|
||||
else
|
||||
printDotText "config" "$note $labelPass"
|
||||
@@ -715,120 +715,120 @@ function siteFilesCheck() {
|
||||
ug=$(domainToUser "$domain")
|
||||
dots=30
|
||||
|
||||
# fileSignatureDiff "$olsVhostsPath/$domain" "755:root:root"
|
||||
if ! run output error fileSignatureDiff "$olsVhostsPath/$domain" "755:root:root"; then
|
||||
# fileSignatureDiff "$vhostsPath/$domain" "755:root:root"
|
||||
if ! run output error fileSignatureDiff "$vhostsPath/$domain" "755:root:root"; then
|
||||
printDanger "${error:-$output}"
|
||||
elif [[ -n "$output" ]]; then
|
||||
local prefix=":$olsVhostsPath/$domain"
|
||||
local prefix=":$vhostsPath/$domain"
|
||||
printDot "$dots" "${fontCyan}vhost d 755:root:root$fontReset" "" "${output/$prefix/ /}"
|
||||
fi
|
||||
|
||||
# fileSignatureDiffList "$olsVhostsPath/$domain/www" "d" "2750|$ug:$ug"
|
||||
if ! run output error fileSignatureDiffList "$olsVhostsPath/$domain/www" "d" "2750|$ug:$ug"; then
|
||||
# fileSignatureDiffList "$vhostsPath/$domain/www" "d" "2750|$ug:$ug"
|
||||
if ! run output error fileSignatureDiffList "$vhostsPath/$domain/www" "d" "2750|$ug:$ug"; then
|
||||
printDanger "${error:-$output}"
|
||||
else
|
||||
lineCount=$(grep -c . <<< "$output" || true)
|
||||
if [[ "$lineCount" -gt 0 ]]; then
|
||||
local label="${fontCyan}www d 2750:u:g$fontReset"
|
||||
local prefix=":$olsVhostsPath/$domain/www/"
|
||||
local prefix=":$vhostsPath/$domain/www/"
|
||||
while read -r line; do
|
||||
printDot "$dots" "$label" "" "${line/$prefix/ /}"
|
||||
done < <(awk 'NF' <<< "$output")
|
||||
fi
|
||||
fi
|
||||
|
||||
# fileSignatureDiffList "$olsVhostsPath/$domain/www" "f" "(600|640):$ug:$ug"
|
||||
if ! run output error fileSignatureDiffList "$olsVhostsPath/$domain/www" "f" "(600|640):$ug:$ug"; then
|
||||
# fileSignatureDiffList "$vhostsPath/$domain/www" "f" "(600|640):$ug:$ug"
|
||||
if ! run output error fileSignatureDiffList "$vhostsPath/$domain/www" "f" "(600|640):$ug:$ug"; then
|
||||
printDanger "${error:-$output}"
|
||||
else
|
||||
lineCount=$(grep -c . <<< "$output" || true)
|
||||
if [[ "$lineCount" -gt 0 ]]; then
|
||||
local label="${fontCyan}www f (600|640):u:g$fontReset"
|
||||
local prefix=":$olsVhostsPath/$domain/www/"
|
||||
local prefix=":$vhostsPath/$domain/www/"
|
||||
while read -r line; do
|
||||
printDot "$dots" "$label" "" "${line/$prefix/ /}"
|
||||
done < <(awk 'NF' <<< "$output")
|
||||
fi
|
||||
fi
|
||||
|
||||
# fileSignatureDiffList "$olsVhostsPath/$domain/tmp" "d" "770:$ug:$ug"
|
||||
if ! run output error fileSignatureDiffList "$olsVhostsPath/$domain/tmp" "d" "770:$ug:$ug"; then
|
||||
# fileSignatureDiffList "$vhostsPath/$domain/tmp" "d" "770:$ug:$ug"
|
||||
if ! run output error fileSignatureDiffList "$vhostsPath/$domain/tmp" "d" "770:$ug:$ug"; then
|
||||
printDanger "${error:-$output}"
|
||||
else
|
||||
lineCount=$(grep -c . <<< "$output" || true)
|
||||
if [[ "$lineCount" -gt 0 ]]; then
|
||||
local label="${fontCyan}tmp d 770:u:g$fontReset"
|
||||
local prefix=":$olsVhostsPath/$domain/tmp/"
|
||||
local prefix=":$vhostsPath/$domain/tmp/"
|
||||
while read -r line; do
|
||||
printDot "$dots" "$label" "" "${line/$prefix/ /}"
|
||||
done < <(awk 'NF' <<< "$output")
|
||||
fi
|
||||
fi
|
||||
|
||||
# fileSignatureDiffList "$olsVhostsPath/$domain/tmp" "f" "660:$ug:$ug"
|
||||
if ! run output error fileSignatureDiffList "$olsVhostsPath/$domain/tmp" "f" "660:$ug:$ug"; then
|
||||
# fileSignatureDiffList "$vhostsPath/$domain/tmp" "f" "660:$ug:$ug"
|
||||
if ! run output error fileSignatureDiffList "$vhostsPath/$domain/tmp" "f" "660:$ug:$ug"; then
|
||||
printDanger "${error:-$output}"
|
||||
else
|
||||
lineCount=$(grep -c . <<< "$output" || true)
|
||||
if [[ "$lineCount" -gt 0 ]]; then
|
||||
local label="${fontCyan}tmp f 660:u:g$fontReset"
|
||||
local prefix=":$olsVhostsPath/$domain/tmp/"
|
||||
local prefix=":$vhostsPath/$domain/tmp/"
|
||||
while read -r line; do
|
||||
printDot "$dots" "$label" "" "${line/$prefix/ /}"
|
||||
done < <(awk 'NF' <<< "$output")
|
||||
fi
|
||||
fi
|
||||
|
||||
# fileSignatureDiffList "$olsVhostsPath/$domain/session" "d" "770:$ug:$ug"
|
||||
if ! run output error fileSignatureDiffList "$olsVhostsPath/$domain/session" "d" "770:$ug:$ug"; then
|
||||
# fileSignatureDiffList "$vhostsPath/$domain/session" "d" "770:$ug:$ug"
|
||||
if ! run output error fileSignatureDiffList "$vhostsPath/$domain/session" "d" "770:$ug:$ug"; then
|
||||
printDanger "${error:-$output}"
|
||||
else
|
||||
lineCount=$(grep -c . <<< "$output" || true)
|
||||
if [[ "$lineCount" -gt 0 ]]; then
|
||||
local label="${fontCyan}session d 770:u:g$fontReset"
|
||||
local prefix=":$olsVhostsPath/$domain/session/"
|
||||
local prefix=":$vhostsPath/$domain/session/"
|
||||
while read -r line; do
|
||||
printDot "$dots" "$label" "" "${line/$prefix/ /}"
|
||||
done < <(awk 'NF' <<< "$output")
|
||||
fi
|
||||
fi
|
||||
|
||||
# fileSignatureDiffList "$olsVhostsPath/$domain/session" "f" "(660|600):$ug:$ug"
|
||||
if ! run output error fileSignatureDiffList "$olsVhostsPath/$domain/session" "f" "(660|600):$ug:$ug"; then
|
||||
# fileSignatureDiffList "$vhostsPath/$domain/session" "f" "(660|600):$ug:$ug"
|
||||
if ! run output error fileSignatureDiffList "$vhostsPath/$domain/session" "f" "(660|600):$ug:$ug"; then
|
||||
printDanger "${error:-$output}"
|
||||
else
|
||||
lineCount=$(grep -c . <<< "$output" || true)
|
||||
if [[ "$lineCount" -gt 0 ]]; then
|
||||
local label="${fontCyan}session f (660|600):u:g$fontReset"
|
||||
local prefix=":$olsVhostsPath/$domain/session/"
|
||||
local prefix=":$vhostsPath/$domain/session/"
|
||||
while read -r line; do
|
||||
printDot "$dots" "$label" "" "${line/$prefix/ /}"
|
||||
done < <(awk 'NF' <<< "$output")
|
||||
fi
|
||||
fi
|
||||
|
||||
# fileSignatureDiffList "$olsPrivatePath/$domain" "d" "750:$ug:$ug"
|
||||
if ! run output error fileSignatureDiffList "$olsPrivatePath/$domain" "d" "750:$ug:$ug"; then
|
||||
# fileSignatureDiffList "$openlitespeedVhostDataPath/$domain" "d" "750:$ug:$ug"
|
||||
if ! run output error fileSignatureDiffList "$openlitespeedVhostDataPath/$domain" "d" "750:$ug:$ug"; then
|
||||
printDanger "${error:-$output}"
|
||||
else
|
||||
lineCount=$(grep -c . <<< "$output" || true)
|
||||
if [[ "$lineCount" -gt 0 ]]; then
|
||||
local label="${fontCyan}data d 750:u:g$fontReset"
|
||||
local prefix=":$olsPrivatePath/$domain/"
|
||||
local prefix=":$openlitespeedVhostDataPath/$domain/"
|
||||
while read -r line; do
|
||||
printDot "$dots" "$label" "" "${line/$prefix/ /}"
|
||||
done < <(awk 'NF' <<< "$output")
|
||||
fi
|
||||
fi
|
||||
|
||||
# fileSignatureDiffList "$olsPrivatePath/$domain" "f" "600:$ug:$ug"
|
||||
if ! run output error fileSignatureDiffList "$olsPrivatePath/$domain" "f" "600:$ug:$ug"; then
|
||||
# fileSignatureDiffList "$openlitespeedVhostDataPath/$domain" "f" "600:$ug:$ug"
|
||||
if ! run output error fileSignatureDiffList "$openlitespeedVhostDataPath/$domain" "f" "600:$ug:$ug"; then
|
||||
printDanger "${error:-$output}"
|
||||
else
|
||||
lineCount=$(grep -c . <<< "$output" || true)
|
||||
if [[ "$lineCount" -gt 0 ]]; then
|
||||
local label="${fontCyan}data f 600:u:g$fontReset"
|
||||
local prefix=":$olsPrivatePath/$domain/"
|
||||
local prefix=":$openlitespeedVhostDataPath/$domain/"
|
||||
while read -r line; do
|
||||
printDot "$dots" "$label" "" "${line/$prefix/ /}"
|
||||
done < <(awk 'NF' <<< "$output")
|
||||
|
||||
@@ -355,20 +355,3 @@ function cmdStorageBackupCompare() {
|
||||
printDotText "$fontBlue$dir$fontReset" "[ $localStatus : $remoteStatus ]"
|
||||
done < <(awk 'NF' <<< "$allDirs")
|
||||
}
|
||||
|
||||
function cmdStorageBackupSize() {
|
||||
local fileList file size total
|
||||
|
||||
printSection "FTP: $ftpPath"
|
||||
|
||||
total=0
|
||||
fileList=$(ftpFileList | sort -n)
|
||||
while IFS= read -r file; do
|
||||
size=$(ftpPathSize "/$file" "gb")
|
||||
printDotText "$file" "$size Gb"
|
||||
(( total += size ))
|
||||
done <<< "$fileList"
|
||||
|
||||
printRow
|
||||
printDotText "total" "$total Gb"
|
||||
}
|
||||
|
||||
@@ -136,9 +136,8 @@ function cmdCronList() {
|
||||
local i=0 line total
|
||||
total=$(grep -c . <<< "$list")
|
||||
while IFS= read -r line; do
|
||||
[[ -n "$line" ]] || continue
|
||||
((i++))
|
||||
num=$(printf "%${#total}d" "$i")
|
||||
num=$(printf "%0${#total}d" "$i")
|
||||
printDotFix 20 "$num: $line"
|
||||
done <<< "$list"
|
||||
}
|
||||
|
||||
@@ -1,59 +0,0 @@
|
||||
UNIGMA_PHP=""
|
||||
UNIGMA_MEM=""
|
||||
UNIGMA_EXEC=""
|
||||
|
||||
function cmdUnigma() {
|
||||
local podList vhostsList error raw pod phase
|
||||
|
||||
printSection "Unigma"
|
||||
|
||||
run podList error k3sPodListStatus "$olsKube" || { printDanger "Get pods: $error"; return 1; }
|
||||
[[ -n "$podList" ]] || { printDanger "Pods not found"; return 1; }
|
||||
|
||||
# run vhostList error fileList "$olsVhostsPath" d || { printDanger "$error"; return 1; }
|
||||
run vhostList error openlitespeedConfigVhostList || { printDanger "Failed get list of vhosts: $error"; return 1; }
|
||||
while read -r vhost; do
|
||||
run raw error unigmaGetTxt "$vhost" || {
|
||||
printDotText "$vhost" "${fontGray}failed get Unigma data$fontReset";
|
||||
continue
|
||||
}
|
||||
# raw='php=8.1;mem=112M;exec=60'
|
||||
|
||||
unigmaParse "$raw" || {
|
||||
printDotText "$vhost" "$labelFail";
|
||||
printDanger "$error"
|
||||
continue
|
||||
}
|
||||
|
||||
unigmaIniSet "$vhost" "$UNIGMA_MEM" "$UNIGMA_EXEC"
|
||||
case $? in
|
||||
1) printDotText "$vhost" "$labelFail"; printDanger "$error"; continue ;;
|
||||
2)
|
||||
uid=$(domainToUid "$vhost")
|
||||
[[ -n "$uid" ]] || {
|
||||
printDotText "$vhost" "$labelFail";
|
||||
printDanger "Cannot resolve UID for: $vhost";
|
||||
continue;
|
||||
}
|
||||
|
||||
local pod phase
|
||||
while IFS='|' read -r pod phase; do
|
||||
if [[ "$phase" != "Running" ]]; then
|
||||
printDotText " $pod" "$fontRed$phase$fontReset"
|
||||
else
|
||||
runSilent openlitespeedPodExec "$pod" pkill -u "$uid" -x lsphp
|
||||
printDotText " kill$fontBlue lsphp$fontReset processes for $vhost"
|
||||
fi
|
||||
done < <(awk 'NF' <<< "$podList")
|
||||
;;
|
||||
esac
|
||||
|
||||
unigmaPhpSet "$vhost" "$UNIGMA_PHP" || {
|
||||
printDotText "$vhost" "$labelFail";
|
||||
printDanger "$error"
|
||||
continue
|
||||
}
|
||||
|
||||
printDotText "$vhost" "$labelDone";
|
||||
done < <(awk 'NF' <<< "$vhostList")
|
||||
}
|
||||
@@ -35,7 +35,7 @@ function cmdWordpressPasswordSet() {
|
||||
# $@ (...): WP-CLI sub-command and arguments.
|
||||
function cmdWordpressExec() {
|
||||
local target="$1"
|
||||
shift || true
|
||||
shift
|
||||
|
||||
local vhostList error
|
||||
|
||||
@@ -43,7 +43,7 @@ function cmdWordpressExec() {
|
||||
|
||||
if [[ -z "$target" ]]; then
|
||||
printDanger "Target not specified";
|
||||
elif ! run vhostList error openlitespeedConfigVhostList; then
|
||||
elif ! run vhostList error openlitespeedVhostList; then
|
||||
printDanger "Cannot get vhost list: $error";
|
||||
elif [[ "$target" == "all" ]]; then
|
||||
local domain
|
||||
@@ -72,7 +72,7 @@ function cmdWordpressSalt() {
|
||||
|
||||
if [[ -z "$target" ]]; then
|
||||
printDanger "Target not specified";
|
||||
elif ! run vhostList error openlitespeedConfigVhostList; then
|
||||
elif ! run vhostList error openlitespeedVhostList; then
|
||||
printDanger "Cannot get vhost list: $error";
|
||||
elif [[ "$target" == "all" ]]; then
|
||||
local domain
|
||||
@@ -102,7 +102,7 @@ function cmdWordpressCheck() {
|
||||
|
||||
if [[ -z "$target" ]]; then
|
||||
printDanger "Target not specified";
|
||||
elif ! run vhostList error openlitespeedConfigVhostList; then
|
||||
elif ! run vhostList error openlitespeedVhostList; then
|
||||
printDanger "Cannot get vhost list: $error";
|
||||
elif [[ "$target" == "all" ]]; then
|
||||
local domain
|
||||
@@ -219,8 +219,8 @@ function cmdWordpressDomainUpdate() {
|
||||
wordpressSearchReplace "$domain" "$rootOld" "$siteNew"
|
||||
fi
|
||||
if [[ -n "$abspathOld" ]]; then
|
||||
printInfo "$wordpressLabel Replace in DB (6): $abspathOld --> $olsPodVhostsPath/$domain/www"
|
||||
wordpressSearchReplace "$domain" "$abspathOld" "$olsPodVhostsPath/$domain/www"
|
||||
printInfo "$wordpressLabel Replace in DB (6): $abspathOld --> /var/www/vhosts/$domain/www"
|
||||
wordpressSearchReplace "$domain" "$abspathOld" "/var/www/vhosts/$domain/www"
|
||||
fi
|
||||
|
||||
printInfo "$wordpressLabel Replace in DB (7): $hostOld --> $domain"
|
||||
|
||||
@@ -180,7 +180,7 @@ function cmdWorkerTaskHandle() {
|
||||
local output error
|
||||
local uuid="worker_$(uuidgen)"
|
||||
|
||||
if ! run vhostList error openlitespeedConfigVhostList; then
|
||||
if ! run vhostList error openlitespeedVhostList; then
|
||||
printDanger "Vhost list: $error"
|
||||
configSet "$taskFile" "status" "$taskStatusFailed"
|
||||
configSet "$taskFile" "message" "Error getting list of virtual hosts"
|
||||
@@ -192,13 +192,13 @@ function cmdWorkerTaskHandle() {
|
||||
return 1
|
||||
fi
|
||||
|
||||
if ! run output error backupSiteFiles "$domain" "$olsVhostsPath/$domain/www/$uuid"; then
|
||||
if ! run output error backupSiteFiles "$domain" "$vhostsPath/$domain/www/$uuid"; then
|
||||
printDanger "$error"
|
||||
configSet "$taskFile" "status" "$taskStatusFailed"
|
||||
configSet "$taskFile" "message" "Error create files archive: $error"
|
||||
return 1
|
||||
fi
|
||||
if ! run output error backupSiteDatabase "$domain" "$olsVhostsPath/$domain/www/$uuid.sql"; then
|
||||
if ! run output error backupSiteDatabase "$domain" "$vhostsPath/$domain/www/$uuid.sql"; then
|
||||
printDanger "$error"
|
||||
configSet "$taskFile" "status" "$taskStatusFailed"
|
||||
configSet "$taskFile" "message" "Error create database archive: $error"
|
||||
|
||||
+172
-54
@@ -112,18 +112,6 @@ function sshDirectoryDelete() {
|
||||
|| { appError "$error"; return 1; }
|
||||
}
|
||||
|
||||
function fileAtomicWrite() {
|
||||
local file="$1"
|
||||
local content="$2"
|
||||
local path tmp
|
||||
path="$(dirname "$file")"
|
||||
|
||||
mkdir -p "$path"
|
||||
tmp="$(mktemp "$path/.tmp.XXXXXX")"
|
||||
printf '%s\n' "$content" > "$tmp"
|
||||
mv -f "$tmp" "$file"
|
||||
}
|
||||
|
||||
# Create a timestamped backup copy of a file if it exists.
|
||||
# $1 (file): path to the file to back up.
|
||||
# [$2] (suffix): custom suffix for the backup file (defaults to a timestamp .bak suffix).
|
||||
@@ -336,6 +324,8 @@ function archiveExtract() {
|
||||
# $3 (precision): Precision.
|
||||
function pathSize() {
|
||||
local path="$1"
|
||||
[[ -n "$path" ]] || { appError "Path not specified"; return 1; }
|
||||
|
||||
local unit="${2:-}"
|
||||
local precision="${3:-0}"
|
||||
local divisor="1"
|
||||
@@ -344,7 +334,6 @@ function pathSize() {
|
||||
mb) divisor="1048576" ;;
|
||||
gb) divisor="1073741824" ;;
|
||||
esac
|
||||
[[ -n "$path" ]] || { appError "Path not specified"; return 1; }
|
||||
|
||||
local output error bytes
|
||||
if [[ -d "$path" ]]; then
|
||||
@@ -360,47 +349,6 @@ function pathSize() {
|
||||
LC_NUMERIC=C awk -v bytes="$bytes" -v divisor="$divisor" -v precision="$precision" 'BEGIN { printf "%.*f\n", precision, bytes / divisor }'
|
||||
}
|
||||
|
||||
function ftpPathSize() {
|
||||
local path="$1"
|
||||
local unit="${2:-}"
|
||||
local precision="${3:-0}"
|
||||
local divisor="1"
|
||||
case "${unit,,}" in
|
||||
kb) divisor="1024" ;;
|
||||
mb) divisor="1048576" ;;
|
||||
gb) divisor="1073741824" ;;
|
||||
esac
|
||||
|
||||
local output error total
|
||||
if run output error curl -sS -u "$ftpUser:$ftpPass" "ftp://$ftpHost:$ftpPort$ftpPath$path/" --connect-timeout 10; then
|
||||
total=0
|
||||
local line file size
|
||||
while IFS= read -r line; do
|
||||
file=$(awk '{print $NF}' <<< "$line")
|
||||
[[ -n "$file" && "$file" != "." && "$file" != ".." ]] || continue
|
||||
|
||||
if [[ "$line" =~ ^d ]]; then
|
||||
size=$(ftpPathSize "$path/$file") || return 1
|
||||
else
|
||||
size=$(awk '{print $5}' <<< "$line")
|
||||
[[ "$size" =~ ^[0-9]+$ ]] || continue
|
||||
fi
|
||||
(( total += size ))
|
||||
done <<< "$output"
|
||||
else
|
||||
local parent name
|
||||
parent=$(dirname "$path")
|
||||
name=$(basename "$path")
|
||||
run output error curl -sS -u "$ftpUser:$ftpPass" "ftp://$ftpHost:$ftpPort$ftpPath$parent/" --connect-timeout 10 || {
|
||||
appError "$error"; return 1
|
||||
}
|
||||
total=$(awk -v f="$name" '$NF == f {print $5}' <<< "$output")
|
||||
[[ "$total" =~ ^[0-9]+$ ]] || { appError "Cannot determine size of: $path"; return 1; }
|
||||
fi
|
||||
|
||||
LC_NUMERIC=C awk -v b="$total" -v d="$divisor" -v p="$precision" 'BEGIN { printf "%.*f\n", p, b/d }'
|
||||
}
|
||||
|
||||
# Return the contents of a file if it exists and is non-empty, otherwise write the given value to it and return it.
|
||||
# $1 (file): path to the file.
|
||||
# $2 (value): value to write when the file is missing or empty.
|
||||
@@ -666,6 +614,25 @@ function fileSignatureAclCheck() {
|
||||
[[ -z "$output" ]]
|
||||
}
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
# ===============================================================================================================
|
||||
# ===============================================================================================================
|
||||
# ===============================================================================================================
|
||||
|
||||
|
||||
# Checking the availability of a file (URL) for download.
|
||||
# Check if a URL is accessible and print the final effective URL on success.
|
||||
# $1 (url): the URL to check.
|
||||
@@ -701,6 +668,8 @@ function urlCode() {
|
||||
return 0
|
||||
}
|
||||
|
||||
|
||||
|
||||
# Derive a local filename from a URL, optionally using a custom base name.
|
||||
# $1 (url): the source URL to extract the filename from.
|
||||
# [$2] (localFileName): custom base name; if given, the URL extension is appended to it.
|
||||
@@ -724,3 +693,152 @@ function urlLocalFileGen() {
|
||||
printf '%s' "$localFileName.$ext"
|
||||
fi
|
||||
}
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
# DEPRECATED
|
||||
# Retrieves a list of files in an FTP directory along with their sizes (in ftpPath).
|
||||
#
|
||||
# $1 (assoc): An associative array where file names and their sizes will be saved.
|
||||
# $2 (path): The path to the directory on the FTP server.
|
||||
#
|
||||
# If a file is a directory, its size is set to "-1". If it's a regular file, its size is saved.
|
||||
function ftpEntrySizeList() {
|
||||
local -n assoc=$1
|
||||
local path="$2"
|
||||
|
||||
if ! run output error curl -sS -u "$ftpUser:$ftpPass" "ftp://$ftpHost:$ftpPort$ftpPath$path/" --connect-timeout 10; then
|
||||
appError "$error"
|
||||
return 1
|
||||
fi
|
||||
|
||||
local line file size
|
||||
while IFS= read -r line; do
|
||||
file=$(echo "$line" | awk '{print $NF}')
|
||||
size=$(echo "$line" | awk '{print $5}')
|
||||
if [[ -n "$file" ]] && [[ "$line" =~ ^d.* ]]; then
|
||||
assoc["$file"]="-1"
|
||||
elif [[ -n "$file" ]] && [[ -n "$size" ]]; then
|
||||
assoc["$file"]="$size"
|
||||
fi
|
||||
done <<< "$output"
|
||||
}
|
||||
|
||||
# DEPRECATED
|
||||
# Retrieves a list of files and their sizes from a remote directory via SSH (in sshPath).
|
||||
#
|
||||
# $1 (assoc): An associative array where file names and their sizes will be saved.
|
||||
# $2 (path): The path to the remote directory where file sizes need to be retrieved.
|
||||
function sshEntrySizeList() {
|
||||
local -n assoc=$1
|
||||
local path="$2"
|
||||
|
||||
if ! run output error ssh -i "$sshKeyFile" "$sshUser@$sshHost" "du -ab --max-depth=1 $sshPath$path"; then
|
||||
appError "$error"
|
||||
return 1
|
||||
fi
|
||||
output=$(echo "$output" | grep -v "[[:space:]]\+$sshPath$path$")
|
||||
|
||||
local size file
|
||||
while IFS=$'\t' read -r size file; do
|
||||
file=$(basename "$file")
|
||||
if [[ -n "$file" && -n "$size" ]]; then
|
||||
assoc["$file"]="$size"
|
||||
fi
|
||||
done <<< "$output"
|
||||
}
|
||||
|
||||
# DEPRECATED
|
||||
# Retrieves a list of files and their sizes in a specified directory on extended storage.
|
||||
#
|
||||
# $1 (assoc): An associative array where file names and their sizes will be saved.
|
||||
# $2 (path): The path to the local directory where file sizes need to be retrieved.
|
||||
function storageEntrySizeList() {
|
||||
local -A storageFunc=(
|
||||
["ftp"]=ftpEntrySizeList
|
||||
["rsync"]=ftpEntrySizeList
|
||||
["ssh"]=sshEntrySizeList
|
||||
)
|
||||
if [[ -z "${storageFunc[$storageType]}" ]]; then
|
||||
appError "Unknown value storageType: $storageType"
|
||||
return 1
|
||||
fi
|
||||
|
||||
if ! run output error "${storageFunc[$storageType]}" "$@"; then
|
||||
appError "$error"
|
||||
return 1
|
||||
fi
|
||||
}
|
||||
|
||||
# DEPRECATED
|
||||
# Retrieves a list of files and their sizes in a specified local directory (in backupPath).
|
||||
#
|
||||
# $1 (assoc): An associative array where file names and their sizes will be saved.
|
||||
# $2 (path): The path to the local directory where file sizes need to be retrieved.
|
||||
function backupEntrySizeList() {
|
||||
local -n assoc=$1
|
||||
local path="$2"
|
||||
|
||||
if ! run output error du -ab --max-depth=1 "$backupDailyPath$path"; then
|
||||
appError "$error"
|
||||
return 1
|
||||
fi
|
||||
local entryList
|
||||
entryList=$(echo "$output" | grep -v "[[:space:]]\+$backupDailyPath$path$")
|
||||
|
||||
local file size
|
||||
while IFS=$'\t' read -r size file; do
|
||||
file=$(basename "$file")
|
||||
if [[ -n "$file" && -n "$size" ]]; then
|
||||
assoc["$file"]="$size"
|
||||
fi
|
||||
done <<< "$entryList"
|
||||
}
|
||||
|
||||
|
||||
# DEPRECATED
|
||||
# List entries in a backup daily directory path.
|
||||
# $1 (path): sub-path within backupDailyPath to list.
|
||||
# [$2] (type): entry type filter (f: files, d: directories).
|
||||
function backupEntryList() {
|
||||
if ! run output error fileList "$backupDailyPath$1" "$2"; then
|
||||
appError "$error"
|
||||
return 1
|
||||
fi
|
||||
|
||||
printf '%s\n' "$output"
|
||||
}
|
||||
|
||||
@@ -27,7 +27,7 @@ function numFormat() {
|
||||
# $2 (items): array elements to search in (passed as individual arguments).
|
||||
function arrayContains() {
|
||||
local needle="${1-}"
|
||||
shift || true
|
||||
shift
|
||||
|
||||
local item
|
||||
for item in "$@"; do
|
||||
@@ -113,64 +113,6 @@ function domainToUser() {
|
||||
printf '%s' "${base:0:21}-${hash}"
|
||||
}
|
||||
|
||||
function domainToUid() {
|
||||
local domain="${1-}"
|
||||
local username uid
|
||||
|
||||
if [[ -z "$domain" ]]; then
|
||||
appError "Domain not specified"
|
||||
return 1
|
||||
fi
|
||||
|
||||
username=$(domainToUser "$domain")
|
||||
if [[ -z "$username" ]]; then
|
||||
appError "Cannot compute username for: $domain"
|
||||
return 1
|
||||
fi
|
||||
|
||||
uid=$(id -u "$username" 2>/dev/null)
|
||||
if [[ -z "$uid" ]]; then
|
||||
appError "No such user: $username"
|
||||
return 1
|
||||
fi
|
||||
|
||||
if [[ "$uid" == "0" ]]; then
|
||||
appError "Refusing to return root UID for: $domain"
|
||||
return 1
|
||||
fi
|
||||
|
||||
printf '%s' "$uid"
|
||||
}
|
||||
|
||||
function domainToGid() {
|
||||
local domain="${1-}"
|
||||
local username gid
|
||||
|
||||
if [[ -z "$domain" ]]; then
|
||||
appError "Domain not specified"
|
||||
return 1
|
||||
fi
|
||||
|
||||
username=$(domainToUser "$domain")
|
||||
if [[ -z "$username" ]]; then
|
||||
appError "Cannot compute username for: $domain"
|
||||
return 1
|
||||
fi
|
||||
|
||||
gid=$(id -g "$username" 2>/dev/null)
|
||||
if [[ -z "$gid" ]]; then
|
||||
appError "No such user: $username"
|
||||
return 1
|
||||
fi
|
||||
|
||||
if [[ "$gid" == "0" ]]; then
|
||||
appError "Refusing to return root GID for: $domain"
|
||||
return 1
|
||||
fi
|
||||
|
||||
printf '%s' "$gid"
|
||||
}
|
||||
|
||||
# Generate random string from domain
|
||||
function domainToRandom() {
|
||||
local domain="${1-}"
|
||||
@@ -216,7 +158,7 @@ function run() {
|
||||
# Run command, discard stdout
|
||||
function runError() {
|
||||
local -n __runErrorErr="$1"
|
||||
shift || true
|
||||
shift
|
||||
|
||||
local __runErrorOutput __runErrorError status
|
||||
run __runErrorOutput __runErrorError "$@"
|
||||
|
||||
@@ -9,7 +9,7 @@ defined $mode && length $mode or die "mode is required\n";
|
||||
|
||||
sub mask_to_re {
|
||||
my ($mask) = @_;
|
||||
return if !defined($mask) || $mask eq '';
|
||||
return undef if !defined($mask) || $mask eq '';
|
||||
$mask = quotemeta($mask);
|
||||
$mask =~ s/\\\*/.*/g;
|
||||
return qr/\A$mask\z/;
|
||||
@@ -43,70 +43,34 @@ sub fmt_line {
|
||||
|
||||
sub brace_delta {
|
||||
my ($line) = @_;
|
||||
return ($line =~ tr/\{//) - ($line =~ tr/\}//);
|
||||
my $o = () = $line =~ /\{/g;
|
||||
my $c = () = $line =~ /\}/g;
|
||||
return $o - $c;
|
||||
}
|
||||
|
||||
sub key_add {
|
||||
my ($lines, $section_re, $key, $value) = @_;
|
||||
# die "value is required for add\n" if !defined($value) || $value eq '';
|
||||
sub find_section {
|
||||
my ($lines, $re) = @_;
|
||||
|
||||
if ($section_re eq '') {
|
||||
my $depth = 0;
|
||||
for (my $i = 0; $i <= $#$lines; $i++) {
|
||||
next unless $lines->[$i] =~ /^(\h*)$re\h*\{\h*(?:\R)?$/;
|
||||
|
||||
for my $line (@$lines) {
|
||||
if ($depth == 0 && line_matches_exact($line, $key, $value)) {
|
||||
return;
|
||||
}
|
||||
$depth += brace_delta($line);
|
||||
}
|
||||
|
||||
my $new = fmt_line('', $key, $value);
|
||||
|
||||
my $root_pos;
|
||||
my $first_block_pos;
|
||||
$depth = 0;
|
||||
|
||||
for (my $i = 0; $i <= $#$lines; $i++) {
|
||||
my $line = $lines->[$i];
|
||||
my $indent = $1 . ' ';
|
||||
my $depth = 1;
|
||||
|
||||
for (my $j = $i + 1; $j <= $#$lines; $j++) {
|
||||
$depth += brace_delta($lines->[$j]);
|
||||
if ($depth == 0) {
|
||||
$root_pos = $i
|
||||
if !defined($root_pos) && $line =~ /^\h*serverName\h+\S*/;
|
||||
|
||||
$first_block_pos = $i
|
||||
if !defined($first_block_pos) && $line =~ /^\h*\S.*\{\h*(?:\R)?$/;
|
||||
return ($i, $j, $indent);
|
||||
}
|
||||
|
||||
$depth += brace_delta($line);
|
||||
}
|
||||
|
||||
if (defined $root_pos) {
|
||||
splice @$lines, $root_pos + 1, 0, $new;
|
||||
} elsif (defined $first_block_pos) {
|
||||
splice @$lines, $first_block_pos, 0, $new;
|
||||
} else {
|
||||
push @$lines, $new;
|
||||
}
|
||||
|
||||
return;
|
||||
die "section '$re' is not closed\n";
|
||||
}
|
||||
|
||||
my ($start, $end, $indent) = block_find($lines, $section_re);
|
||||
|
||||
my $depth = 1;
|
||||
for my $i ($start + 1 .. $end - 1) {
|
||||
my $line = $lines->[$i];
|
||||
if ($depth == 1 && line_matches_exact($line, $key, $value)) {
|
||||
return;
|
||||
}
|
||||
$depth += brace_delta($line);
|
||||
}
|
||||
|
||||
my $new = fmt_line($indent, $key, $value);
|
||||
splice @$lines, $end, 0, $new;
|
||||
die "section '$re' not found\n";
|
||||
}
|
||||
|
||||
sub key_del {
|
||||
sub delete_key {
|
||||
my ($lines, $section_re, $key, $mask) = @_;
|
||||
my $value_re = mask_to_re($mask);
|
||||
|
||||
@@ -124,7 +88,7 @@ sub key_del {
|
||||
return;
|
||||
}
|
||||
|
||||
my ($start, $end, undef) = block_find($lines, $section_re);
|
||||
my ($start, $end, undef) = find_section($lines, $section_re);
|
||||
|
||||
my @out;
|
||||
push @out, @$lines[0 .. $start];
|
||||
@@ -141,45 +105,111 @@ sub key_del {
|
||||
@$lines = @out;
|
||||
}
|
||||
|
||||
sub block_find {
|
||||
my ($lines, $re) = @_;
|
||||
sub add_key {
|
||||
my ($lines, $section_re, $key, $value) = @_;
|
||||
die "value is required for add\n" if !defined($value) || $value eq '';
|
||||
|
||||
for (my $i = 0; $i <= $#$lines; $i++) {
|
||||
next unless $lines->[$i] =~ /^(\h*)$re\h*\{\h*(?:\R)?$/;
|
||||
if ($section_re eq '') {
|
||||
my $depth = 0;
|
||||
|
||||
my $indent = $1 . ' ';
|
||||
my $depth = 1;
|
||||
|
||||
for (my $j = $i + 1; $j <= $#$lines; $j++) {
|
||||
$depth += brace_delta($lines->[$j]);
|
||||
if ($depth == 0) {
|
||||
return ($i, $j, $indent);
|
||||
for my $line (@$lines) {
|
||||
if ($depth == 0 && line_matches_exact($line, $key, $value)) {
|
||||
return;
|
||||
}
|
||||
$depth += brace_delta($line);
|
||||
}
|
||||
|
||||
die "block '$re' is not closed\n";
|
||||
my $new = fmt_line('', $key, $value);
|
||||
|
||||
my $root_pos;
|
||||
my $first_section_pos;
|
||||
$depth = 0;
|
||||
|
||||
for (my $i = 0; $i <= $#$lines; $i++) {
|
||||
my $line = $lines->[$i];
|
||||
|
||||
if ($depth == 0) {
|
||||
$root_pos = $i
|
||||
if !defined($root_pos) && $line =~ /^\h*serverName\h+\S*/;
|
||||
|
||||
$first_section_pos = $i
|
||||
if !defined($first_section_pos) && $line =~ /^\h*\S.*\{\h*(?:\R)?$/;
|
||||
}
|
||||
|
||||
$depth += brace_delta($line);
|
||||
}
|
||||
|
||||
if (defined $root_pos) {
|
||||
splice @$lines, $root_pos + 1, 0, $new;
|
||||
} elsif (defined $first_section_pos) {
|
||||
splice @$lines, $first_section_pos, 0, $new;
|
||||
} else {
|
||||
push @$lines, $new;
|
||||
}
|
||||
|
||||
return;
|
||||
}
|
||||
|
||||
die "block '$re' not found\n";
|
||||
my ($start, $end, $indent) = find_section($lines, $section_re);
|
||||
|
||||
my $depth = 1;
|
||||
for my $i ($start + 1 .. $end - 1) {
|
||||
my $line = $lines->[$i];
|
||||
if ($depth == 1 && line_matches_exact($line, $key, $value)) {
|
||||
return;
|
||||
}
|
||||
$depth += brace_delta($line);
|
||||
}
|
||||
|
||||
my $new = fmt_line($indent, $key, $value);
|
||||
splice @$lines, $end, 0, $new;
|
||||
}
|
||||
|
||||
sub block_add {
|
||||
my ($lines, $header) = @_;
|
||||
return if !defined($header) || $header eq '';
|
||||
sub build_vhost_section {
|
||||
my ($domain) = @_;
|
||||
return if !defined($domain) || $domain eq '';
|
||||
|
||||
my @out;
|
||||
push @out, "virtualhost $domain {\n";
|
||||
push @out, fmt_line(' ', 'vhRoot', "/var/www/vhosts/$domain");
|
||||
push @out, fmt_line(' ', 'configFile', "/usr/local/lsws/conf/vhosts/$domain.conf");
|
||||
push @out, fmt_line(' ', 'allowSymbolLink', '1');
|
||||
push @out, fmt_line(' ', 'enableScript', '1');
|
||||
push @out, fmt_line(' ', 'restrained', '1');
|
||||
push @out, fmt_line(' ', 'setUIDMode', '2');
|
||||
push @out, "}\n";
|
||||
|
||||
return join('', @out);
|
||||
}
|
||||
|
||||
sub has_vhost_section {
|
||||
my ($lines, $name) = @_;
|
||||
|
||||
for my $line (@$lines) {
|
||||
return if $line =~ /^\h*\Q$header\E\h*\{/;
|
||||
return 1 if $line =~ /^\h*virtualhost\h+\Q$name\E\h*\{/;
|
||||
}
|
||||
|
||||
return 0;
|
||||
}
|
||||
|
||||
sub add_vhost_section {
|
||||
my ($lines, $name) = @_;
|
||||
|
||||
return if !defined($name) || $name eq '';
|
||||
return if has_vhost_section($lines, $name);
|
||||
|
||||
my @section = split /(?<=\n)/, build_vhost_section($name), -1;
|
||||
pop @section if @section && $section[-1] eq '';
|
||||
|
||||
if (@$lines && $lines->[-1] !~ /\n\z/) {
|
||||
$lines->[-1] .= "\n";
|
||||
}
|
||||
|
||||
push @$lines, "\n" if @$lines && $lines->[-1] !~ /^\s*$/;
|
||||
push @$lines, "$header {\n";
|
||||
push @$lines, "}\n";
|
||||
push @$lines, @section;
|
||||
}
|
||||
|
||||
sub block_del {
|
||||
sub delete_named_section {
|
||||
my ($lines, $header_re) = @_;
|
||||
|
||||
my @out;
|
||||
@@ -207,19 +237,7 @@ sub block_del {
|
||||
return $deleted;
|
||||
}
|
||||
|
||||
sub suspended_rebuild {
|
||||
my ($lines, @list) = @_;
|
||||
|
||||
@list = grep { defined($_) && $_ ne '' } @list;
|
||||
|
||||
key_del($lines, '', 'suspendedVhosts', '');
|
||||
|
||||
if (@list) {
|
||||
key_add($lines, '', 'suspendedVhosts', join(',', @list));
|
||||
}
|
||||
}
|
||||
|
||||
sub suspended_list {
|
||||
sub get_suspended_vhosts {
|
||||
my ($lines) = @_;
|
||||
|
||||
my $depth = 0;
|
||||
@@ -238,20 +256,61 @@ sub suspended_list {
|
||||
return;
|
||||
}
|
||||
|
||||
sub suspended_add {
|
||||
my ($lines, $domain) = @_;
|
||||
return if !defined($domain) || $domain eq '';
|
||||
sub set_suspended_vhosts {
|
||||
my ($lines, @list) = @_;
|
||||
|
||||
my @current = suspended_list($lines);
|
||||
return if grep { $_ eq $domain } @current;
|
||||
suspended_rebuild($lines, @current, $domain);
|
||||
@list = grep { defined($_) && $_ ne '' } @list;
|
||||
|
||||
delete_key($lines, '', 'suspendedVhosts', '');
|
||||
|
||||
if (@list) {
|
||||
add_key($lines, '', 'suspendedVhosts', join(',', @list));
|
||||
}
|
||||
}
|
||||
|
||||
sub suspended_del {
|
||||
sub suspend_vhost {
|
||||
my ($lines, $domain) = @_;
|
||||
return if !defined($domain) || $domain eq '';
|
||||
|
||||
suspended_rebuild($lines, grep { $_ ne $domain } suspended_list($lines));
|
||||
my @current = get_suspended_vhosts($lines);
|
||||
|
||||
my @new = ($domain);
|
||||
for my $item (@current) {
|
||||
push @new, $item if $item ne $domain;
|
||||
}
|
||||
|
||||
set_suspended_vhosts($lines, @new);
|
||||
}
|
||||
|
||||
sub unsuspend_vhost {
|
||||
my ($lines, $domain) = @_;
|
||||
return if !defined($domain) || $domain eq '';
|
||||
|
||||
my @current = get_suspended_vhosts($lines);
|
||||
my @new = grep { $_ ne $domain } @current;
|
||||
|
||||
set_suspended_vhosts($lines, @new);
|
||||
}
|
||||
|
||||
sub get_listener_http_maps {
|
||||
my ($lines) = @_;
|
||||
|
||||
my ($start, $end, undef) = find_section($lines, 'listener\h+HTTP');
|
||||
|
||||
my @maps;
|
||||
|
||||
for my $i ($start + 1 .. $end - 1) {
|
||||
my $clean = $lines->[$i];
|
||||
$clean =~ s/#.*$//;
|
||||
$clean =~ s/^\s+|\s+$//g;
|
||||
next if $clean eq '';
|
||||
|
||||
if ($clean =~ /^map\s+(\S+)\s+(\S+)$/i) {
|
||||
push @maps, [$1, $2];
|
||||
}
|
||||
}
|
||||
|
||||
return @maps;
|
||||
}
|
||||
|
||||
sub vhost_list {
|
||||
@@ -262,7 +321,7 @@ sub vhost_list {
|
||||
if $type !~ /\A(?:all|up|down)\z/;
|
||||
|
||||
my @all;
|
||||
my %down = map { $_ => 1 } suspended_list($lines);
|
||||
my %down = map { $_ => 1 } get_suspended_vhosts($lines);
|
||||
|
||||
for my $line (@$lines) {
|
||||
my $clean = $line;
|
||||
@@ -284,30 +343,44 @@ sub vhost_list {
|
||||
}
|
||||
}
|
||||
|
||||
sub vhost_del {
|
||||
my ($lines, $domain) = @_;
|
||||
sub vhost_list_map {
|
||||
my ($lines, $type) = @_;
|
||||
$type //= 'all';
|
||||
|
||||
key_del($lines, 'listener\h+HTTP', 'map', "$domain *");
|
||||
block_del($lines, 'virtualhost\h+' . quotemeta($domain));
|
||||
die "unknown vhost map list type '$type'\n"
|
||||
if $type !~ /\A(?:all|up|down)\z/;
|
||||
|
||||
my %down = map { $_ => 1 } get_suspended_vhosts($lines);
|
||||
my %seen;
|
||||
|
||||
for my $map (get_listener_http_maps($lines)) {
|
||||
my ($vhost, $domain) = @$map;
|
||||
|
||||
next if $vhost ne $domain;
|
||||
next if $seen{$vhost}++;
|
||||
|
||||
if ($type eq 'down') {
|
||||
next if !exists $down{$vhost};
|
||||
} elsif ($type eq 'up') {
|
||||
next if exists $down{$vhost};
|
||||
}
|
||||
|
||||
print "$vhost\n";
|
||||
}
|
||||
}
|
||||
|
||||
sub vhost_set {
|
||||
my ($lines, $vhRoot, $domain, @aliases) = @_;
|
||||
sub alias_list {
|
||||
my ($lines) = @_;
|
||||
|
||||
vhost_del($lines, $domain);
|
||||
block_add($lines, "virtualhost $domain");
|
||||
my %seen;
|
||||
|
||||
my $block_re = 'virtualhost\h+' . quotemeta($domain);
|
||||
key_add($lines, $block_re, 'vhRoot', $vhRoot);
|
||||
key_add($lines, $block_re, 'configFile', "/usr/local/lsws/conf/vhosts/$domain.conf");
|
||||
key_add($lines, $block_re, 'allowSymbolLink', '1');
|
||||
key_add($lines, $block_re, 'enableScript', '1');
|
||||
key_add($lines, $block_re, 'restrained', '1');
|
||||
key_add($lines, $block_re, 'setUIDMode', '2');
|
||||
for my $map (get_listener_http_maps($lines)) {
|
||||
my ($vhost, $domain) = @$map;
|
||||
|
||||
key_add($lines, 'listener\h+HTTP', 'map', "$domain $domain");
|
||||
for my $alias (@aliases) {
|
||||
key_add($lines, 'listener\h+HTTP', 'map', "$domain $alias");
|
||||
next if $vhost eq $domain;
|
||||
next if $seen{$domain}++;
|
||||
|
||||
print "$domain\n";
|
||||
}
|
||||
}
|
||||
|
||||
@@ -317,140 +390,19 @@ sub vhost_alias {
|
||||
die "virtual host name is required\n"
|
||||
if !defined($name) || $name eq '';
|
||||
|
||||
my ($start, $end) = block_find($lines, 'listener\h+HTTP');
|
||||
|
||||
my %seen;
|
||||
|
||||
for my $i ($start + 1 .. $end - 1) {
|
||||
my $clean = $lines->[$i];
|
||||
$clean =~ s/#.*$//;
|
||||
$clean =~ s/^\s+|\s+$//g;
|
||||
next if $clean eq '';
|
||||
next unless $clean =~ /^map\s+(\S+)\s+(\S+)$/i;
|
||||
for my $map (get_listener_http_maps($lines)) {
|
||||
my ($vhost, $domain) = @$map;
|
||||
|
||||
my ($vhost, $domain) = ($1, $2);
|
||||
|
||||
next if $name ne 'all' && $vhost ne $name;
|
||||
next if $domain eq $vhost;
|
||||
next if $vhost ne $name;
|
||||
next if $domain eq $name;
|
||||
next if $seen{$domain}++;
|
||||
|
||||
print "$domain\n";
|
||||
}
|
||||
}
|
||||
|
||||
sub member_list {
|
||||
my ($lines, $template, $type) = @_;
|
||||
|
||||
my ($t_start, $t_end) = block_find($lines, 'vhTemplate\h+' . quotemeta($template));
|
||||
|
||||
die "unknown member list type '$type'\n"
|
||||
if $type !~ /\A(?:all|up|down)\z/;
|
||||
|
||||
my %down = map { $_ => 1 } suspended_list($lines);
|
||||
|
||||
my $depth = 0;
|
||||
for my $i ($t_start + 1 .. $t_end - 1) {
|
||||
my $line = $lines->[$i];
|
||||
|
||||
if ($depth == 0 && $line =~ /^\h*member\h+([^\s\{]+)/i) {
|
||||
my $name = $1;
|
||||
if ( $type eq 'all'
|
||||
|| ($type eq 'down' && exists $down{$name})
|
||||
|| ($type eq 'up' && !exists $down{$name})) {
|
||||
print "$name\n";
|
||||
}
|
||||
}
|
||||
|
||||
$depth += brace_delta($line);
|
||||
}
|
||||
}
|
||||
|
||||
sub member_del {
|
||||
my ($lines, $template, $domain) = @_;
|
||||
|
||||
my ($t_start, $t_end) = block_find($lines, 'vhTemplate\h+' . quotemeta($template));
|
||||
|
||||
my $depth = 0;
|
||||
for my $i ($t_start + 1 .. $t_end - 1) {
|
||||
my $line = $lines->[$i];
|
||||
|
||||
if ($depth == 0 && $line =~ /^\h*member\h+\Q$domain\E\h*(\{)?\h*(?:\R)?$/) {
|
||||
my $m_end = $i;
|
||||
|
||||
if (defined $1) {
|
||||
my $d = 1;
|
||||
for my $j ($i + 1 .. $t_end - 1) {
|
||||
$d += brace_delta($lines->[$j]);
|
||||
if ($d == 0) { $m_end = $j; last; }
|
||||
}
|
||||
die "member '$domain' block is not closed\n" if $m_end == $i;
|
||||
}
|
||||
|
||||
splice @$lines, $i, $m_end - $i + 1;
|
||||
return;
|
||||
}
|
||||
|
||||
$depth += brace_delta($line);
|
||||
}
|
||||
}
|
||||
|
||||
sub member_set {
|
||||
my ($lines, $template, $domain, @aliases) = @_;
|
||||
|
||||
member_del($lines, $template, $domain);
|
||||
|
||||
my ($t_start, $t_end, $indent) = block_find($lines, 'vhTemplate\h+' . quotemeta($template));
|
||||
|
||||
my @new;
|
||||
if (@aliases) {
|
||||
push @new, fmt_line($indent, 'member', "$domain {");
|
||||
push @new, fmt_line($indent . ' ', 'vhAliases', join(', ', @aliases));
|
||||
push @new, "$indent}\n";
|
||||
} else {
|
||||
push @new, fmt_line($indent, 'member', $domain);
|
||||
}
|
||||
|
||||
splice @$lines, $t_end, 0, @new;
|
||||
}
|
||||
|
||||
sub member_alias {
|
||||
my ($lines, $template, $domain) = @_;
|
||||
|
||||
my ($t_start, $t_end) = block_find($lines, 'vhTemplate\h+' . quotemeta($template));
|
||||
|
||||
my $depth = 0;
|
||||
for my $i ($t_start + 1 .. $t_end - 1) {
|
||||
my $line = $lines->[$i];
|
||||
|
||||
if ($depth == 0 && $line =~ /^\h*member\h+(\S+)\h*\{\h*(?:\R)?$/) {
|
||||
my $mname = $1;
|
||||
my $match = ($domain eq 'all' || $domain eq $mname);
|
||||
|
||||
if ($match) {
|
||||
my $d = 1;
|
||||
for my $j ($i + 1 .. $t_end - 1) {
|
||||
if ($d == 1) {
|
||||
my @m = parse_kv_line($lines->[$j], 'vhAliases');
|
||||
if (@m) {
|
||||
for my $a (split /\h*,\h*/, $m[1]) {
|
||||
next if $a eq '';
|
||||
print "$a\n";
|
||||
}
|
||||
last;
|
||||
}
|
||||
}
|
||||
$d += brace_delta($lines->[$j]);
|
||||
last if $d == 0;
|
||||
}
|
||||
|
||||
return unless $domain eq 'all';
|
||||
}
|
||||
}
|
||||
|
||||
$depth += brace_delta($line);
|
||||
}
|
||||
}
|
||||
|
||||
open my $fh, '<', $file or die "cannot read '$file': $!\n";
|
||||
local $/;
|
||||
my $content = <$fh>;
|
||||
@@ -458,121 +410,89 @@ close $fh;
|
||||
|
||||
my @L = split /(?<=\n)/, $content, -1;
|
||||
|
||||
if ($mode eq 'key_add') {
|
||||
my ($block_re, $key, $value) = @args;
|
||||
defined $block_re or die "block_re is required\n";
|
||||
defined $key or die "key is required\n";
|
||||
defined $value or die "value is required\n";
|
||||
key_add(\@L, $block_re, $key, $value);
|
||||
}
|
||||
elsif ($mode eq 'key_set') {
|
||||
my ($block_re, $key, $value) = @args;
|
||||
defined $block_re or die "block_re is required\n";
|
||||
defined $key or die "key is required\n";
|
||||
defined $value or die "value is required\n";
|
||||
key_del(\@L, $block_re, $key, '');
|
||||
key_add(\@L, $block_re, $key, $value);
|
||||
}
|
||||
elsif ($mode eq 'key_mask_set') {
|
||||
my ($block_re, $key, $mask, $value) = @args;
|
||||
defined $block_re or die "block_re is required\n";
|
||||
defined $key or die "key is required\n";
|
||||
defined $mask or die "mask is required\n";
|
||||
defined $value or die "value is required\n";
|
||||
key_del(\@L, $block_re, $key, $mask);
|
||||
key_add(\@L, $block_re, $key, $value);
|
||||
}
|
||||
elsif ($mode eq 'key_del') {
|
||||
my ($block_re, $key, $mask) = @args;
|
||||
defined $block_re or die "block_re is required\n";
|
||||
if ($mode eq 'del') {
|
||||
my ($section_re, $key, $mask) = @args;
|
||||
defined $section_re or die "section_re is required\n";
|
||||
defined $key or die "key is required\n";
|
||||
$mask //= '';
|
||||
key_del(\@L, $block_re, $key, $mask);
|
||||
delete_key(\@L, $section_re, $key, $mask);
|
||||
}
|
||||
elsif ($mode eq 'key_mask_del') {
|
||||
my ($block_re, $key, $mask) = @args;
|
||||
defined $block_re or die "block_re is required\n";
|
||||
elsif ($mode eq 'add') {
|
||||
my ($section_re, $key, $value) = @args;
|
||||
defined $section_re or die "section_re is required\n";
|
||||
defined $key or die "key is required\n";
|
||||
defined $value or die "value is required\n";
|
||||
add_key(\@L, $section_re, $key, $value);
|
||||
}
|
||||
elsif ($mode eq 'set') {
|
||||
my ($section_re, $key, $value) = @args;
|
||||
defined $section_re or die "section_re is required\n";
|
||||
defined $key or die "key is required\n";
|
||||
defined $value or die "value is required\n";
|
||||
delete_key(\@L, $section_re, $key, '');
|
||||
add_key(\@L, $section_re, $key, $value);
|
||||
}
|
||||
elsif ($mode eq 'set_masked') {
|
||||
my ($section_re, $key, $mask, $value) = @args;
|
||||
defined $section_re or die "section_re is required\n";
|
||||
defined $key or die "key is required\n";
|
||||
defined $mask or die "mask is required\n";
|
||||
key_del(\@L, $block_re, $key, $mask);
|
||||
defined $value or die "value is required\n";
|
||||
delete_key(\@L, $section_re, $key, $mask);
|
||||
add_key(\@L, $section_re, $key, $value);
|
||||
}
|
||||
elsif ($mode eq 'block_add') {
|
||||
my ($header) = @args;
|
||||
defined $header && length $header or die "block header is required\n";
|
||||
block_add(\@L, $header);
|
||||
elsif ($mode eq 'del_masked') {
|
||||
my ($section_re, $key, $mask) = @args;
|
||||
defined $section_re or die "section_re is required\n";
|
||||
defined $key or die "key is required\n";
|
||||
defined $mask or die "mask is required\n";
|
||||
delete_key(\@L, $section_re, $key, $mask);
|
||||
}
|
||||
elsif ($mode eq 'block_del') {
|
||||
my ($header_re) = @args;
|
||||
defined $header_re && length $header_re or die "block header pattern is required\n";
|
||||
block_del(\@L, $header_re);
|
||||
elsif ($mode eq 'vhost_add') {
|
||||
my ($name) = @args;
|
||||
defined $name && length $name or die "virtual host name is required\n";
|
||||
add_vhost_section(\@L, $name);
|
||||
}
|
||||
elsif ($mode eq 'suspended_list') {
|
||||
print "$_\n" for suspended_list(\@L);
|
||||
exit 0;
|
||||
elsif ($mode eq 'vhost_del') {
|
||||
my ($name) = @args;
|
||||
defined $name && length $name or die "virtual host name is required\n";
|
||||
my $quoted = quotemeta($name);
|
||||
delete_named_section(\@L, "virtualhost\\h+$quoted");
|
||||
}
|
||||
elsif ($mode eq 'suspended_del') {
|
||||
my ($domain) = @args;
|
||||
defined $domain && length $domain or die "domain is required\n";
|
||||
suspended_del(\@L, $domain);
|
||||
elsif ($mode eq 'vhost_down') {
|
||||
my ($name) = @args;
|
||||
defined $name && length $name or die "virtual host name is required\n";
|
||||
suspend_vhost(\@L, $name);
|
||||
}
|
||||
elsif ($mode eq 'suspended_add') {
|
||||
my ($domain) = @args;
|
||||
defined $domain && length $domain or die "domain is required\n";
|
||||
suspended_add(\@L, $domain);
|
||||
elsif ($mode eq 'vhost_up') {
|
||||
my ($name) = @args;
|
||||
defined $name && length $name or die "virtual host name is required\n";
|
||||
unsuspend_vhost(\@L, $name);
|
||||
}
|
||||
elsif ($mode eq 'vhost_list') {
|
||||
my ($type) = @args;
|
||||
vhost_list(\@L, $type // 'all');
|
||||
exit 0;
|
||||
}
|
||||
elsif ($mode eq 'vhost_del') {
|
||||
my ($domain) = @args;
|
||||
defined $domain && length $domain or die "domain is required\n";
|
||||
vhost_del(\@L, $domain);
|
||||
elsif ($mode eq 'vhost_list_map') {
|
||||
my ($type) = @args;
|
||||
vhost_list_map(\@L, $type // 'all');
|
||||
exit 0;
|
||||
}
|
||||
elsif ($mode eq 'vhost_set') {
|
||||
my ($vhRoot, $domain, @aliases) = @args;
|
||||
defined $vhRoot && length $vhRoot or die "vhRoot is required\n";
|
||||
defined $domain && length $domain or die "domain is required\n";
|
||||
vhost_set(\@L, $vhRoot, $domain, @aliases);
|
||||
elsif ($mode eq 'alias_list') {
|
||||
alias_list(\@L);
|
||||
exit 0;
|
||||
}
|
||||
elsif ($mode eq 'vhost_alias') {
|
||||
my ($name) = @args;
|
||||
vhost_alias(\@L, $name);
|
||||
exit 0;
|
||||
}
|
||||
elsif ($mode eq 'member_list') {
|
||||
my ($template, $type) = @args;
|
||||
defined $template && length $template or die "template is required\n";
|
||||
defined $type && length $type or die "type is required\n";
|
||||
member_list(\@L, $template, $type);
|
||||
exit 0;
|
||||
}
|
||||
elsif ($mode eq 'member_del') {
|
||||
my ($template, $domain) = @args;
|
||||
defined $template && length $template or die "template is required\n";
|
||||
defined $domain && length $domain or die "domain is required\n";
|
||||
member_del(\@L, $template, $domain);
|
||||
}
|
||||
elsif ($mode eq 'member_set') {
|
||||
my ($template, $domain, @aliases) = @args;
|
||||
defined $template && length $template or die "template is required\n";
|
||||
defined $domain && length $domain or die "domain is required\n";
|
||||
member_set(\@L, $template, $domain, @aliases);
|
||||
}
|
||||
elsif ($mode eq 'member_alias') {
|
||||
my ($template, $domain) = @args;
|
||||
defined $template && length $template or die "template is required\n";
|
||||
defined $domain && length $domain or die "domain is required\n";
|
||||
member_alias(\@L, $template, $domain);
|
||||
exit 0;
|
||||
}
|
||||
else {
|
||||
die "unknown mode '$mode'\n";
|
||||
}
|
||||
|
||||
$content = join '', @L;
|
||||
$content =~ s/\n{3,}/\n\n/g;
|
||||
|
||||
open my $out, '>', $file or die "cannot write '$file': $!\n";
|
||||
print {$out} $content;
|
||||
|
||||
@@ -30,7 +30,7 @@ function backupSiteFiles() {
|
||||
compressProgram="pigz -p $pigzThreads"
|
||||
fi
|
||||
|
||||
archiveCreate "$olsVhostsPath/$domain" "$file" "$compressProgram"
|
||||
archiveCreate "$vhostsPath/$domain" "$file" "$compressProgram"
|
||||
}
|
||||
|
||||
# Creates a database backup for a site.
|
||||
@@ -83,7 +83,7 @@ function backupSite() {
|
||||
;;
|
||||
esac
|
||||
|
||||
cp -f -- "$olsVhostsConfigPath/$domain.conf" "$path/$domain.conf" || {
|
||||
cp -f -- "$openlitespeedVhostsPath/$domain.conf" "$path/$domain.conf" || {
|
||||
appError "Failed to copy vhost config: $domain"
|
||||
return 1
|
||||
}
|
||||
|
||||
@@ -582,7 +582,7 @@ SH
|
||||
|
||||
# Parses the OLS error log since $diagSince and appends categorized error counters to the diag file.
|
||||
function diagOlsErrorSummary() {
|
||||
local openlitespeedErrorLog="$olsLogsPath/error.log"
|
||||
local openlitespeedErrorLog="$openlitespeedLogsPath/error.log"
|
||||
local cutoff
|
||||
|
||||
cutoff="$(diagCutoffEpoch)"
|
||||
|
||||
@@ -163,19 +163,19 @@ function mariadbDatabaseClean() {
|
||||
function mariadbExport() {
|
||||
local execFn="$1"
|
||||
[[ -n "$execFn" ]] || { appError "Exec function not specified"; return 1; }
|
||||
shift || true
|
||||
shift
|
||||
|
||||
local username="$1"
|
||||
[[ -n "$username" ]] || { appError "Username not specified"; return 1; }
|
||||
shift || true
|
||||
shift
|
||||
|
||||
local password="$1"
|
||||
[[ -n "$password" ]] || { appError "Password not specified"; return 1; }
|
||||
shift || true
|
||||
shift
|
||||
|
||||
local database="$1"
|
||||
[[ -n "$database" ]] || { appError "Database not specified"; return 1; }
|
||||
shift || true
|
||||
shift
|
||||
|
||||
local file="$1"
|
||||
if [[ -z "$file" ]]; then
|
||||
@@ -183,7 +183,7 @@ function mariadbExport() {
|
||||
&& file="$appDataPath/$mariadbMasterKube/${appDate}_${appTime}_full.sql.tar.gz" \
|
||||
|| file="$appDataPath/$mariadbMasterKube/${appDate}_${appTime}_$database.sql.tar.gz"
|
||||
fi
|
||||
shift || true
|
||||
shift
|
||||
|
||||
local -a params
|
||||
if [[ $# -gt 0 ]]; then
|
||||
|
||||
@@ -11,8 +11,8 @@ function metricKube() {
|
||||
mkdir -p -- "$metricPromPath" || return 1
|
||||
|
||||
local vhostAllCount vhostUpCount
|
||||
vhostAllCount=$(openlitespeedConfigVhostList all | grep -c . || true)
|
||||
vhostUpCount=$(openlitespeedConfigVhostList up | grep -c . || true)
|
||||
vhostAllCount=$(openlitespeedVhostList all | grep -c . || true)
|
||||
vhostUpCount=$(openlitespeedVhostList up | grep -c . || true)
|
||||
|
||||
local appTimestamp
|
||||
appTimestamp=$(date -d "$appDate ${appTime//-/:}" +%s)
|
||||
@@ -37,8 +37,8 @@ function metricKube() {
|
||||
read -r _req _lim <<< "$_line"
|
||||
slaveMemReq=$(sizeToBytes "$_req"); slaveMemLim=$(sizeToBytes "$_lim")
|
||||
|
||||
_line=$(k3sRun get pods -l "app=$olsKube" \
|
||||
-o jsonpath="{.items[0].spec.containers[?(@.name=='${olsKube}')].resources.requests.memory} {.items[0].spec.containers[?(@.name=='${olsKube}')].resources.limits.memory}" 2>/dev/null)
|
||||
_line=$(k3sRun get pods -l "app=$openlitespeedKube" \
|
||||
-o jsonpath="{.items[0].spec.containers[?(@.name=='${openlitespeedKube}')].resources.requests.memory} {.items[0].spec.containers[?(@.name=='${openlitespeedKube}')].resources.limits.memory}" 2>/dev/null)
|
||||
read -r _req _lim <<< "$_line"
|
||||
olsMemReq=$(sizeToBytes "$_req"); olsMemLim=$(sizeToBytes "$_lim")
|
||||
|
||||
@@ -97,7 +97,7 @@ function metricLsphp() {
|
||||
mkdir -p -- "$metricPromPath" || return 1
|
||||
|
||||
local podList error
|
||||
run podList error k3sPodListStatus "$olsKube" || return 1
|
||||
run podList error k3sPodListStatus "$openlitespeedKube" || return 1
|
||||
|
||||
local pod phase output cpu mem count domain
|
||||
{
|
||||
@@ -110,10 +110,8 @@ function metricLsphp() {
|
||||
|
||||
while IFS='|' read -r pod phase; do
|
||||
[[ "$phase" == "Running" ]] || continue
|
||||
# run output error openlitespeedPodExec "$pod" sh -c "ps aux | grep lsphp | grep -v grep | awk '{u=\$1;cpu[u]+=\$3;mem[u]+=\$4;count[u]++} END {for(u in cpu){name=u;cmd=\"find $olsPodPrivatePath -maxdepth 1 -uid \"u\" -type d 2>/dev/null\";if((cmd|getline dir)>0&&dir!=\"\"){n=split(dir,a,\"/\");name=a[n]};close(cmd);print cpu[u],mem[u],count[u],name}}'" || continue
|
||||
run output error openlitespeedPodExec "$pod" sh -c "ps aux | awk '/lsphp/ && !/nobody/ {u=\$1;cpu[u]+=\$3;mem[u]+=\$4;count[u]++} END {for(u in cpu){name=u;cmd=\"find $olsPodPrivatePath -maxdepth 1 -uid \"u\" -type d 2>/dev/null\";if((cmd|getline dir)>0&&dir!=\"\"){n=split(dir,a,\"/\");name=a[n]};close(cmd);printf \"%.1f\\t%.1f\\t%d\\t%s\\n\",cpu[u],mem[u],count[u],name}}'" || continue
|
||||
|
||||
while IFS=$'\t' read -r cpu mem count domain; do
|
||||
run output error openlitespeedPodExec "$pod" sh -c "ps aux | grep lsphp | grep -v grep | awk '{u=\$1;cpu[u]+=\$3;mem[u]+=\$4;count[u]++} END {for(u in cpu){name=u;cmd=\"find /var/www/data -maxdepth 1 -uid \"u\" -type d 2>/dev/null\";if((cmd|getline dir)>0&&dir!=\"\"){n=split(dir,a,\"/\");name=a[n]};close(cmd);print cpu[u],mem[u],count[u],name}}'" || continue
|
||||
while IFS=' ' read -r cpu mem count domain; do
|
||||
[[ -n "$domain" ]] || continue
|
||||
printf 'lsphp_cpu_percent{domain="%s",pod="%s"} %s\n' "$domain" "$pod" "$cpu"
|
||||
printf 'lsphp_memory_percent{domain="%s",pod="%s"} %s\n' "$domain" "$pod" "$mem"
|
||||
@@ -137,13 +135,13 @@ function metricSites() {
|
||||
dataJson='{}'
|
||||
|
||||
local error vhostList
|
||||
run vhostList error openlitespeedConfigVhostList || {
|
||||
run vhostList error openlitespeedVhostList all || {
|
||||
appError "Error retrieving vhost list: $error"
|
||||
return 1
|
||||
}
|
||||
while IFS= read -r domain <&3; do
|
||||
local diskUsage domainJson
|
||||
diskUsage="$(pathSize "$olsVhostsPath/$domain" "mb" || true)"
|
||||
diskUsage="$(pathSize "$vhostsPath/$domain" "mb" || true)"
|
||||
[[ -n "$diskUsage" ]] || continue
|
||||
|
||||
domainJson="$(
|
||||
|
||||
@@ -1,18 +1,16 @@
|
||||
# Executes a command inside the OLS deployment container.
|
||||
# $@ (...): command and arguments to execute.
|
||||
function openlitespeedExec() {
|
||||
k3sRun exec deploy/"$olsKube" -c "$olsKube" -- "$@"
|
||||
}
|
||||
# [ Config editor ] ===========================================================
|
||||
|
||||
# Executes a command inside a specific OLS pod.
|
||||
# $1 (pod): pod name.
|
||||
# $2+ (...): command and arguments to execute.
|
||||
function openlitespeedPodExec() {
|
||||
local pod="$1"
|
||||
[[ -n "$pod" ]] || { appError "Pod not specified"; return 1; }
|
||||
shift || true
|
||||
# Normalizes an OpenLiteSpeed configuration file.
|
||||
# Collapses three or more consecutive blank lines into two.
|
||||
# [$1] (file): config file path (defaults to $openlitespeedConfigFile).
|
||||
function openlitespeedConfigNormalize() {
|
||||
local file="${1:-$openlitespeedConfigFile}"
|
||||
[[ -n "$file" ]] || { appError "Config file not specified"; return 1; }
|
||||
|
||||
k3sRun exec pod/"$pod" -c "$olsKube" -- "$@"
|
||||
perl -0pi -e 's/\n{3,}/\n\n/g' "$file" || {
|
||||
appError "Failed normalize config file: $file"
|
||||
return 1
|
||||
}
|
||||
}
|
||||
|
||||
# Edits an OpenLiteSpeed configuration file via the OLS config editor script.
|
||||
@@ -36,313 +34,118 @@ function openlitespeedConfigEditFile() {
|
||||
# Edits the main OLS config file.
|
||||
# $@ (...): edit mode and arguments.
|
||||
function openlitespeedConfigEdit() {
|
||||
openlitespeedConfigEditFile "$olsConfigFile" "$@"
|
||||
openlitespeedConfigEditFile "$openlitespeedConfigFile" "$@"
|
||||
}
|
||||
|
||||
# Adds a value to the main OLS config.
|
||||
function openlitespeedConfigKeyAdd() {
|
||||
openlitespeedConfigEdit key_add "$@"
|
||||
}
|
||||
|
||||
# Sets a value in the main OLS config.
|
||||
function openlitespeedConfigKeySet() {
|
||||
openlitespeedConfigEdit key_set "$@"
|
||||
}
|
||||
|
||||
# Sets a masked value in the main OLS config.
|
||||
function openlitespeedConfigKeyMaskSet() {
|
||||
openlitespeedConfigEdit key_mask_set "$@"
|
||||
# Edits the OLS WebAdmin config file.
|
||||
# $@ (...): edit mode and arguments.
|
||||
function openlitespeedAdminConfigEdit() {
|
||||
openlitespeedConfigEditFile "$openlitespeedAdminPath/admin_config.conf" "$@"
|
||||
}
|
||||
|
||||
# Deletes a value from the main OLS config.
|
||||
function openlitespeedConfigKeyDel() {
|
||||
openlitespeedConfigEdit key_del "$@"
|
||||
function openlitespeedConfigEditDel() {
|
||||
openlitespeedConfigEdit del "$@"
|
||||
}
|
||||
|
||||
# Deletes masked values from the main OLS config.
|
||||
function openlitespeedConfigKeyMaskDel() {
|
||||
openlitespeedConfigEdit key_mask_del "$@"
|
||||
function openlitespeedConfigEditDelMasked() {
|
||||
openlitespeedConfigEdit del_masked "$@"
|
||||
}
|
||||
|
||||
# Adds a generic section to the main OLS config.
|
||||
# $1 (header): section header text, e.g. "listener HTTP".
|
||||
function openlitespeedConfigBlockAdd() {
|
||||
openlitespeedConfigEdit block_add "$@"
|
||||
# Adds a value to the main OLS config.
|
||||
function openlitespeedConfigEditAdd() {
|
||||
openlitespeedConfigEdit add "$@"
|
||||
}
|
||||
|
||||
# Deletes a generic section from the main OLS config.
|
||||
# $1 (header_re): regex pattern matching the section header.
|
||||
function openlitespeedConfigBlockDel() {
|
||||
openlitespeedConfigEdit block_del "$@"
|
||||
# Sets a value in the main OLS config.
|
||||
function openlitespeedConfigEditSet() {
|
||||
openlitespeedConfigEdit set "$@"
|
||||
}
|
||||
|
||||
# Sets a masked value in the main OLS config.
|
||||
function openlitespeedConfigEditSetMasked() {
|
||||
openlitespeedConfigEdit set_masked "$@"
|
||||
}
|
||||
|
||||
# Adds a virtual host entry to the main OLS config.
|
||||
# $1 (domain): virtual host name.
|
||||
function openlitespeedConfigVHostAdd() {
|
||||
local domain="$1"
|
||||
[[ -n "$domain" ]] || { appError "Domain not specified"; return 1; }
|
||||
openlitespeedConfigEdit vhost_add "$domain"
|
||||
}
|
||||
|
||||
# Deletes a virtual host entry from the main OLS config.
|
||||
# $1 (domain): virtual host name.
|
||||
function openlitespeedConfigVHostDel() {
|
||||
local domain="$1"
|
||||
[[ -n "$domain" ]] || { appError "Domain not specified"; return 1; }
|
||||
openlitespeedConfigEdit vhost_del "$domain"
|
||||
}
|
||||
|
||||
# Sets a value in the OLS WebAdmin config.
|
||||
function openlitespeedAdminConfigEditSet() {
|
||||
openlitespeedAdminConfigEdit set "$@"
|
||||
}
|
||||
|
||||
# Lists OLS virtual hosts filtered by state.
|
||||
# [$1] (type): filter type: all, up, or down (defaults to all).
|
||||
function openlitespeedConfigVhostList() {
|
||||
function openlitespeedVhostList() {
|
||||
local type="${1:-all}"
|
||||
arrayContains "$type" "all" "up" "down" || { appError "Unknown type: $type"; return 1; }
|
||||
|
||||
case "$olsVhostMode" in
|
||||
standalone) openlitespeedConfigEdit vhost_list "$type" || return 1 ;;
|
||||
template) openlitespeedConfigEdit member_list "$olsVhostTemplate" "$type" || return 1 ;;
|
||||
esac
|
||||
openlitespeedConfigEdit vhost_list "$type"
|
||||
}
|
||||
|
||||
function openlitespeedConfigVhostSet() {
|
||||
local domain="$1"
|
||||
[[ -n "$domain" ]] || { appError "Domain not specified"; return 1; }
|
||||
shift
|
||||
|
||||
case "$olsVhostMode" in
|
||||
# standalone) openlitespeedConfigEdit vhost_set "$olsPodVhostsPath/$domain" "$domain" "$@" || return 1 ;;
|
||||
standalone) openlitespeedConfigEdit vhost_set "$olsPodVhostsPath/\$VH_NAME" "$domain" "$@" || return 1 ;;
|
||||
template) openlitespeedConfigEdit member_set "$olsVhostTemplate" "$domain" "$@" || return 1 ;;
|
||||
esac
|
||||
# Lists OLS virtual hosts with their map entries, filtered by state.
|
||||
# [$1] (type): filter type: all, up, or down (defaults to all).
|
||||
function openlitespeedVhostListMap() {
|
||||
local type="${1:-all}"
|
||||
arrayContains "$type" "all" "up" "down" || { appError "Unknown type: $type"; return 1; }
|
||||
openlitespeedConfigEdit vhost_list_map "$type"
|
||||
}
|
||||
|
||||
# Deletes a virtual host entry from the main OLS config.
|
||||
function openlitespeedConfigVhostDel() {
|
||||
local domain="$1"
|
||||
[[ -n "$domain" ]] || { appError "Domain not specified"; return 1; }
|
||||
|
||||
case "$olsVhostMode" in
|
||||
standalone) openlitespeedConfigEdit vhost_del "$domain" || return 1 ;;
|
||||
template) openlitespeedConfigEdit member_del "$olsVhostTemplate" "$domain" || return 1 ;;
|
||||
esac
|
||||
# Lists configured OLS aliases.
|
||||
function openlitespeedAliasList() {
|
||||
openlitespeedConfigEdit alias_list
|
||||
}
|
||||
|
||||
# Lists aliases assigned to a virtual host.
|
||||
# $1 (domain): site domain name.
|
||||
function openlitespeedConfigVhostAliasList() {
|
||||
function openlitespeedVhostAlias() {
|
||||
local domain="$1"
|
||||
[[ -n "$domain" ]] || { appError "Domain not specified"; return 1; }
|
||||
|
||||
case "$olsVhostMode" in
|
||||
standalone) openlitespeedConfigEdit vhost_alias "$domain" || return 1 ;;
|
||||
template) openlitespeedConfigEdit member_alias "$olsVhostTemplate" "$domain" || return 1 ;;
|
||||
esac
|
||||
openlitespeedConfigEdit vhost_alias "$domain"
|
||||
}
|
||||
|
||||
# Lists configured OLS aliases.
|
||||
function openlitespeedConfigAliasList() {
|
||||
case "$olsVhostMode" in
|
||||
standalone) openlitespeedConfigEdit vhost_alias all || return 1 ;;
|
||||
template) openlitespeedConfigEdit member_alias "$olsVhostTemplate" all || return 1 ;;
|
||||
esac
|
||||
# Executes a command inside the OLS deployment container.
|
||||
# $@ (...): command and arguments to execute.
|
||||
function openlitespeedExec() {
|
||||
k3sRun exec deploy/"$openlitespeedKube" -c "$openlitespeedKube" -- "$@"
|
||||
}
|
||||
|
||||
# Marks a virtual host as active.
|
||||
# $1 (domain): site domain name.
|
||||
function openlitespeedConfigVhostUp() {
|
||||
local domain="$1"
|
||||
[[ -n "$domain" ]] || { appError "Domain not specified"; return 1; }
|
||||
openlitespeedConfigEdit suspended_del "$domain" || return 1
|
||||
}
|
||||
# Executes a command inside a specific OLS pod.
|
||||
# $1 (pod): pod name.
|
||||
# $2+ (...): command and arguments to execute.
|
||||
function openlitespeedPodExec() {
|
||||
local pod="$1"
|
||||
[[ -n "$pod" ]] || { appError "Pod not specified"; return 1; }
|
||||
shift
|
||||
|
||||
# Marks a virtual host as suspended.
|
||||
# $1 (domain): site domain name.
|
||||
function openlitespeedConfigVhostDown() {
|
||||
local domain="$1"
|
||||
[[ -n "$domain" ]] || { appError "Domain not specified"; return 1; }
|
||||
openlitespeedConfigEdit suspended_add "$domain" || return 1
|
||||
}
|
||||
|
||||
function openlitespeedConfigRebuild() {
|
||||
local children php block
|
||||
children=$(configGet "$appAssetsPath/openlitespeed/profiles/memory-$kubeMemoryProfile.config" "children")
|
||||
|
||||
fileBackup "$olsConfigFile"
|
||||
|
||||
openlitespeedConfigBlockDel "wsgiDefaults"
|
||||
openlitespeedConfigBlockDel "nodeDefaults"
|
||||
openlitespeedConfigBlockDel "railsDefaults"
|
||||
openlitespeedConfigBlockDel "vh[Tt]emplate\h+centralConfigLog"
|
||||
openlitespeedConfigBlockDel "vh[Tt]emplate\h+EasyRailsWithSuEXEC"
|
||||
openlitespeedConfigBlockDel "vh[Tt]emplate\h+docker"
|
||||
openlitespeedConfigBlockDel "listener\h+Default"
|
||||
openlitespeedConfigBlockDel "virtual[Hh]ost\h+Example"
|
||||
openlitespeedConfigKeySet '' 'useIpInProxyHeader' '2'
|
||||
openlitespeedConfigKeySet 'fileAccessControl' 'checkSymbolLink' '1'
|
||||
openlitespeedConfigKeySet 'accessControl' 'deny' ''
|
||||
openlitespeedConfigKeySet 'accessControl' 'allow' '10.42.0.0/16T, 10.43.0.0/16T'
|
||||
|
||||
local phpList=("" "${olsPhpList[@]}")
|
||||
for php in "${phpList[@]}"; do
|
||||
block="extProcessor lsphp$php"
|
||||
openlitespeedConfigBlockDel "ext[Pp]rocessor lsphp$php"
|
||||
openlitespeedConfigBlockAdd "$block"
|
||||
openlitespeedConfigKeyAdd "$block" 'type' 'lsapi'
|
||||
openlitespeedConfigKeyAdd "$block" 'address' "uds://tmp/lshttpd/lsphp$php.sock"
|
||||
openlitespeedConfigKeyAdd "$block" 'path' "/usr/local/lsws/lsphp$php/bin/lsphp"
|
||||
openlitespeedConfigKeyAdd "$block" 'maxConns' "$children"
|
||||
openlitespeedConfigKeyAdd "$block" 'env' "PHP_LSAPI_CHILDREN=$children"
|
||||
openlitespeedConfigKeyAdd "$block" 'env' 'PHP_INI_SCAN_DIR=:/etc/ols-php-ini:/var/www/private/$VH_NAME/php'
|
||||
openlitespeedConfigKeyAdd "$block" 'env' 'LSAPI_AVOID_FORK=0'
|
||||
openlitespeedConfigKeyAdd "$block" 'env' 'LSAPI_MAX_IDLE=120'
|
||||
openlitespeedConfigKeyAdd "$block" 'env' 'LSAPI_MAX_IDLE_CHILDREN=1'
|
||||
openlitespeedConfigKeyAdd "$block" 'env' 'LSAPI_PGRP_MAX_IDLE=300'
|
||||
openlitespeedConfigKeyAdd "$block" 'env' 'LSAPI_MAX_PROCESS_TIME=300'
|
||||
openlitespeedConfigKeyAdd "$block" 'env' 'LSAPI_SLOW_REQ_MSECS=5000'
|
||||
openlitespeedConfigKeyAdd "$block" 'initTimeout' '60'
|
||||
openlitespeedConfigKeyAdd "$block" 'retryTimeout' '0'
|
||||
openlitespeedConfigKeyAdd "$block" 'persistConn' '1'
|
||||
openlitespeedConfigKeyAdd "$block" 'respBuffer' '0'
|
||||
openlitespeedConfigKeyAdd "$block" 'autoStart' '2'
|
||||
openlitespeedConfigKeyAdd "$block" 'backlog' '100'
|
||||
openlitespeedConfigKeyAdd "$block" 'instances' '1'
|
||||
openlitespeedConfigKeyAdd "$block" 'priority' '0'
|
||||
openlitespeedConfigKeyAdd "$block" 'memSoftLimit' '0'
|
||||
openlitespeedConfigKeyAdd "$block" 'memHardLimit' '0'
|
||||
openlitespeedConfigKeyAdd "$block" 'procSoftLimit' '700'
|
||||
openlitespeedConfigKeyAdd "$block" 'procHardLimit' '800'
|
||||
|
||||
openlitespeedConfigKeyAdd "script[Hh]andler" add "lsapi:lsphp$php lsphp$php"
|
||||
done
|
||||
openlitespeedConfigKeySet "extProcessor\h+lsphp" 'path' 'fcgi-bin/lsphp'
|
||||
|
||||
# module cache
|
||||
block="module cache"
|
||||
openlitespeedConfigBlockDel "module\h+cache"
|
||||
openlitespeedConfigBlockAdd "$block"
|
||||
openlitespeedConfigKeyAdd "$block" 'ls_enabled' '1'
|
||||
openlitespeedConfigKeyAdd "$block" 'checkPrivateCache' '1'
|
||||
openlitespeedConfigKeyAdd "$block" 'checkPublicCache' '1'
|
||||
openlitespeedConfigKeyAdd "$block" 'maxCacheObjSize' '10000000'
|
||||
openlitespeedConfigKeyAdd "$block" 'maxStaleAge' '200'
|
||||
openlitespeedConfigKeyAdd "$block" 'qsCache' '1'
|
||||
openlitespeedConfigKeyAdd "$block" 'reqCookieCache' '1'
|
||||
openlitespeedConfigKeyAdd "$block" 'respCookieCache' '1'
|
||||
openlitespeedConfigKeyAdd "$block" 'ignoreReqCacheCtrl' '1'
|
||||
openlitespeedConfigKeyAdd "$block" 'ignoreRespCacheCtrl' '0'
|
||||
openlitespeedConfigKeyAdd "$block" 'enableCache' '0'
|
||||
openlitespeedConfigKeyAdd "$block" 'expireInSeconds' '3600'
|
||||
openlitespeedConfigKeyAdd "$block" 'enablePrivateCache' '0'
|
||||
openlitespeedConfigKeyAdd "$block" 'privateExpireInSeconds' '3600'
|
||||
}
|
||||
|
||||
function openlitespeedVhostSet() {
|
||||
local domain
|
||||
domain=$(domainPrepare "$1")
|
||||
domainCheck "$domain" || return 1
|
||||
shift || true
|
||||
|
||||
local -a aliasesRaw=("$@")
|
||||
local -a aliases=()
|
||||
local aliasRaw alias error
|
||||
for aliasRaw in "${aliasesRaw[@]}"; do
|
||||
alias="$(domainPrepare "$aliasRaw")"
|
||||
[[ -n "$alias" ]] || continue
|
||||
[[ "$alias" == "$domain" ]] && continue
|
||||
runError error domainCheck "$alias" || { appError "$alias: $error"; return 1; }
|
||||
arrayContains "$alias" "${aliases[@]}" || aliases+=("$alias")
|
||||
done
|
||||
|
||||
local vhostAliasList vhostList aliasList
|
||||
run vhostAliasList error openlitespeedConfigVhostAliasList "$domain" || { appError "Failed get list of vhost alias: $error"; return 1; }
|
||||
run vhostList error openlitespeedConfigVhostList || { appError "Failed get list of vhost: $error"; return 1; }
|
||||
run aliasList error openlitespeedConfigAliasList || { appError "Failed get list of alias: $error"; return 1; }
|
||||
|
||||
# For a new domain vhostAliasList is empty, so this covers both create and update
|
||||
local aliasListOther
|
||||
aliasListOther=$(grep -Fvx -f <(printf '%s\n' "$vhostAliasList") <<< "$aliasList" || true)
|
||||
for alias in "${aliases[@]}"; do
|
||||
listContains "$alias" "$vhostList" && { appError "$alias: Is already exists as vhost"; return 1; }
|
||||
listContains "$alias" "$aliasListOther" && { appError "$alias: Is already exists as alias"; return 1; }
|
||||
done
|
||||
|
||||
local aliasValue=''
|
||||
[[ ${#aliases[@]} -gt 0 ]] && aliasValue="$(IFS=','; printf '%s\n' "${aliases[*]}")"
|
||||
|
||||
fileBackup "$olsConfigFile" || return 1
|
||||
openlitespeedConfigVhostSet "$domain" "${aliases[@]}" || return 1
|
||||
|
||||
local domainConfigFile="$appDataPath/config/$domain.config"
|
||||
configSet "$domainConfigFile" alias "$aliasValue" || { appError "Failed set alias in $domainConfigFile"; return 1; }
|
||||
|
||||
if [[ "$olsVhostMode" == "standalone" ]]; then
|
||||
local vHostFile="$olsVhostsConfigPath/$domain.conf"
|
||||
if [[ ! -f "$vHostFile" ]]; then
|
||||
local profileFile memory_limit max_execution_time post_max_size upload_max_filesize
|
||||
profileFile="$appAssetsPath/openlitespeed/profiles/memory-$kubeMemoryProfile.config"
|
||||
[[ -f "$profileFile" ]] || { appError "Profile not found: $profileFile"; return 1; }
|
||||
memory_limit=$(configGet "$profileFile" "memory_limit")
|
||||
max_execution_time=$(configGet "$profileFile" "max_execution_time")
|
||||
post_max_size=$(configGet "$profileFile" "post_max_size")
|
||||
upload_max_filesize=$(configGet "$profileFile" "upload_max_filesize")
|
||||
|
||||
# cp -f -- "$appAssetsPath/openlitespeed/vhost.conf" "$vHostFile" || { appError "Copy vhost template failed"; return 1; }
|
||||
# -e "s|{{domain}}|$domain|g" \
|
||||
cp -f -- "$appAssetsPath/openlitespeed/vhosts/$olsVhostFile" "$vHostFile" || { appError "Copy vhost template failed"; return 1; }
|
||||
sed -i \
|
||||
-e "s|{{memory_limit}}|$memory_limit|g" \
|
||||
-e "s|{{max_execution_time}}|$max_execution_time|g" \
|
||||
-e "s|{{post_max_size}}|$post_max_size|g" \
|
||||
-e "s|{{upload_max_filesize}}|$upload_max_filesize|g" \
|
||||
-- "$vHostFile" || { appError "Template substitution failed: $vHostFile"; return 1; }
|
||||
fi
|
||||
fi
|
||||
|
||||
printf '%s' "$aliasValue"
|
||||
return 0
|
||||
}
|
||||
|
||||
# Removes a virtual host from the OLS main config, listener map, and config files.
|
||||
# Idempotent: safe to call even if the vhost does not exist.
|
||||
# $1 (domain): site domain name.
|
||||
function openlitespeedVhostConfigDel() {
|
||||
local domain
|
||||
domain=$(domainPrepare "$1")
|
||||
domainCheck "$domain" || return 1
|
||||
|
||||
fileBackup "$olsConfigFile" || return 1
|
||||
openlitespeedConfigVhostUp "$domain"
|
||||
openlitespeedConfigVhostDel "$domain"
|
||||
|
||||
if [[ "$olsVhostMode" == "standalone" ]]; then
|
||||
rm -f -- "$olsVhostsConfigPath/$domain.conf" &>/dev/null
|
||||
rm -f -- "$olsVhostsConfigPath/$domain.conf0" &>/dev/null
|
||||
rm -f -- "$olsVhostsConfigPath/$domain.txt" &>/dev/null
|
||||
fi
|
||||
}
|
||||
|
||||
# Marks a virtual host as active.
|
||||
# $1 (domain): site domain name.
|
||||
function openlitespeedVhostConfigUp() {
|
||||
local domain vhostList error
|
||||
domain=$(domainPrepare "$1")
|
||||
domainCheck "$domain" || return 1
|
||||
|
||||
run vhostList error openlitespeedConfigVhostList || return 1
|
||||
listContains "$domain" "$vhostList" || return 1
|
||||
|
||||
openlitespeedConfigVhostUp "$domain"
|
||||
}
|
||||
|
||||
# Marks a virtual host as suspended.
|
||||
# $1 (domain): site domain name.
|
||||
function openlitespeedVhostConfigDown() {
|
||||
local domain vhostList error
|
||||
domain=$(domainPrepare "$1")
|
||||
domainCheck "$domain" || return 1
|
||||
|
||||
run vhostList error openlitespeedConfigVhostList || return 1
|
||||
runSilent fileCheckLineLength "$olsConfigFile" 8000 || { appError "fileCheckLineLength 8000"; return 1; }
|
||||
listContains "$domain" "$vhostList" || return 1
|
||||
|
||||
openlitespeedConfigVhostDown "$domain"
|
||||
k3sRun exec pod/"$pod" -c "$openlitespeedKube" -- "$@"
|
||||
}
|
||||
|
||||
# Rebuilds filesystem layout, ownership, and permissions for a virtual host.
|
||||
# $1 (vhostPath): virtual host chroot path.
|
||||
# $2 (privatePath): virtual host private path.
|
||||
# $2 (vhostDataPath): virtual host data path.
|
||||
# $3 (ug): system user/group name for the site.
|
||||
function openlitespeedVhostPermissionSet() {
|
||||
function openlitespeedVhostRebuildPath() {
|
||||
local vhostPath="$1"
|
||||
local privatePath="$2"
|
||||
local vhostDataPath="$2"
|
||||
local ug="$3"
|
||||
[[ -n "$vhostPath" ]] || { appError "vhostPath not specified"; return 1; }
|
||||
[[ -n "$privatePath" ]] || { appError "privatePath not specified"; return 1; }
|
||||
[[ -n "$ug" ]] || { appError "ug not specified"; return 1; }
|
||||
[[ -n "$vhostPath" ]] || { appError "vhostPath not specified"; return 1; }
|
||||
[[ -n "$vhostDataPath" ]] || { appError "vhostDataPath not specified"; return 1; }
|
||||
[[ -n "$ug" ]] || { appError "ug not specified"; return 1; }
|
||||
|
||||
# Create site directories
|
||||
mkdir -p -- "$vhostPath"/{www,tmp,session} || { appError "Create vhost directories failed: $vhostPath"; return 1; }
|
||||
@@ -367,23 +170,22 @@ function openlitespeedVhostPermissionSet() {
|
||||
find "$vhostPath/session" -type f -exec chmod 600 -- {} + || { appError "Change permissions of session files failed"; return 1; }
|
||||
|
||||
# Vhost data directory and bootstrap.php
|
||||
mkdir -p -- "$privatePath" || { appError "Create vhost private directory failed: $privatePath"; return 1; }
|
||||
# mkdir -p -- "$privatePath/php" || { appError "Create vhost private/php directory failed: $privatePath"; return 1; }
|
||||
touch -- "$privatePath/bootstrap.php" || { appError "Create bootstrap.php failed: $privatePath/bootstrap.php"; return 1; }
|
||||
chown -R -- "$ug:$ug" "$privatePath" || { appError "Change owner of vhost private directory failed: $privatePath"; return 1; }
|
||||
find "$privatePath" -type d -exec chmod 700 -- {} + || { appError "Change permissions of vhost private directories failed"; return 1; }
|
||||
find "$privatePath" -type f -exec chmod 600 -- {} + || { appError "Change permissions of vhost private files failed"; return 1; }
|
||||
mkdir -p -- "$vhostDataPath" || { appError "Create vhost data directory failed: $vhostDataPath"; return 1; }
|
||||
touch -- "$vhostDataPath/bootstrap.php" || { appError "Create bootstrap.php failed: $vhostDataPath/bootstrap.php"; return 1; }
|
||||
chown -R -- "$ug:$ug" "$vhostDataPath" || { appError "Change owner of vhost data directory failed: $vhostDataPath"; return 1; }
|
||||
find "$vhostDataPath" -type d -exec chmod 700 -- {} + || { appError "Change permissions of vhost data directories failed"; return 1; }
|
||||
find "$vhostDataPath" -type f -exec chmod 600 -- {} + || { appError "Change permissions of vhost data files failed"; return 1; }
|
||||
}
|
||||
|
||||
# Rebuilds ACL rules for a virtual host.
|
||||
# Resets existing ACLs, then grants OLS nobody user read access to www/data and rw to tmp/session.
|
||||
# $1 (vhostPath): virtual host chroot path.
|
||||
# $2 (privatePath): virtual host private path.
|
||||
function openlitespeedVhostAclSet() {
|
||||
# $2 (vhostDataPath): virtual host data path.
|
||||
function openlitespeedVhostRebuildACL() {
|
||||
local vhostPath="$1"
|
||||
local privatePath="$2"
|
||||
[[ -n "$vhostPath" ]] || { appError "vhostPath not specified"; return 1; }
|
||||
[[ -n "$privatePath" ]] || { appError "privatePath not specified"; return 1; }
|
||||
local vhostDataPath="$2"
|
||||
[[ -n "$vhostPath" ]] || { appError "vhostPath not specified"; return 1; }
|
||||
[[ -n "$vhostDataPath" ]] || { appError "vhostDataPath not specified"; return 1; }
|
||||
|
||||
# ACL reset: vhostPath
|
||||
setfacl -R -b -- "$vhostPath" || { appError "Clean ACL rules for vhost path failed: $vhostPath"; return 1; }
|
||||
@@ -399,25 +201,70 @@ function openlitespeedVhostAclSet() {
|
||||
find "$vhostPath/tmp" "$vhostPath/session" -type d -exec setfacl -m u:nobody:rwx,m:rwx,d:u:nobody:rwx,d:m:rwx -- {} + || { appError "Set ACL for nobody on tmp/session directories failed"; return 1; }
|
||||
find "$vhostPath/tmp" "$vhostPath/session" -type f -exec setfacl -m u:nobody:rw,m:rw -- {} + || { appError "Set ACL for nobody on tmp/session files failed"; return 1; }
|
||||
|
||||
# ACL reset: privatePath
|
||||
setfacl -R -b -- "$privatePath" || { appError "Clean ACL rules for vhost private path failed: $privatePath"; return 1; }
|
||||
find "$privatePath" -type d -exec setfacl -k -- {} + || { appError "Clean default ACL rules for vhost private directories failed: $privatePath"; return 1; }
|
||||
# ACL reset: vhostDataPath
|
||||
setfacl -R -b -- "$vhostDataPath" || { appError "Clean ACL rules for vhost data path failed: $vhostDataPath"; return 1; }
|
||||
find "$vhostDataPath" -type d -exec setfacl -k -- {} + || { appError "Clean default ACL rules for vhost data directories failed: $vhostDataPath"; return 1; }
|
||||
|
||||
# ACL for OLS user nobody: privatePath
|
||||
find "$privatePath" -type d -exec setfacl -m u:nobody:rx,m:rx,d:u:nobody:rx,d:m:rx -- {} + || { appError "Set ACL for nobody on vhost private directories failed"; return 1; }
|
||||
find "$privatePath" -type f -exec setfacl -m u:nobody:r,m:r -- {} + || { appError "Set ACL for nobody on vhost private files failed"; return 1; }
|
||||
# ACL for OLS user nobody: vhostDataPath
|
||||
find "$vhostDataPath" -type d -exec setfacl -m u:nobody:rx,m:rx,d:u:nobody:rx,d:m:rx -- {} + || { appError "Set ACL for nobody on vhost data directories failed"; return 1; }
|
||||
find "$vhostDataPath" -type f -exec setfacl -m u:nobody:r,m:r -- {} + || { appError "Set ACL for nobody on vhost data files failed"; return 1; }
|
||||
}
|
||||
|
||||
# Sets user disk and inode quota for a virtual host.
|
||||
# Requires user quota to be already enabled and active on the target filesystem.
|
||||
# $1 (domain): site domain name.
|
||||
function openlitespeedVhostRebuildQuota() {
|
||||
local domain
|
||||
domain=$(domainPrepare "$1")
|
||||
domainCheck "$domain" || return 1
|
||||
|
||||
local ug
|
||||
ug=$(domainToUser "$domain")
|
||||
|
||||
local quotaMount
|
||||
quotaMount=$(findmnt -no TARGET --target "$vhostsPath")
|
||||
[[ -n "$quotaMount" ]] || { appError "Quota mount not found: $vhostsPath"; return 1; }
|
||||
|
||||
local quotaBlockLimit quotaInodeLimit
|
||||
quotaBlockLimit=$(siteConfigGetOrSet "$domain" "quotaBlockLimit" "$openlitespeedQuotaBlockLimit")
|
||||
quotaInodeLimit=$(siteConfigGetOrSet "$domain" "quotaInodeLimit" "$openlitespeedQuotaInodeLimit")
|
||||
setquota -u "$ug" "$quotaBlockLimit" "$quotaBlockLimit" "$quotaInodeLimit" "$quotaInodeLimit" "$quotaMount" || {
|
||||
appError "Set quota failed: ug=$ug mount=$quotaMount"
|
||||
return 1
|
||||
}
|
||||
}
|
||||
|
||||
# Checks whether user quota support is ready on the virtual host filesystem.
|
||||
function openlitespeedQuotaCheck() {
|
||||
local quotaMount
|
||||
quotaMount=$(findmnt -no TARGET --target "$vhostsPath")
|
||||
[[ -n "$quotaMount" ]] || { appError "Quota mount not found: $vhostsPath"; return 1; }
|
||||
|
||||
local quotaOptions
|
||||
quotaOptions=$(findmnt -no OPTIONS --target "$quotaMount")
|
||||
[[ "$quotaOptions" == *usrquota* || "$quotaOptions" == *uquota* ]] || {
|
||||
appError "User quota is not enabled: mount=$quotaMount options=$quotaOptions"
|
||||
return 1
|
||||
}
|
||||
|
||||
quotaon -p "$quotaMount" 2>/dev/null | grep -qi "user quota on" || {
|
||||
appError "User quota is not active: mount=$quotaMount"
|
||||
return 1
|
||||
}
|
||||
|
||||
command -v setquota >/dev/null 2>&1 || { appError "setquota command not found"; return 1; }
|
||||
}
|
||||
|
||||
# Prints disk and inode quota hard limits for a user on the virtual host filesystem.
|
||||
# Output format: <blockLimit> <inodeLimit>
|
||||
# $1 (user): username or numeric UID.
|
||||
function openlitespeedVhostQuotaGet() {
|
||||
function openlitespeedVhostQuota() {
|
||||
local user="$1"
|
||||
[[ -n "$user" ]] || { appError "User not specified"; return 1; }
|
||||
|
||||
local quotaMount
|
||||
quotaMount=$(findmnt -no TARGET --target "$olsVhostsPath")
|
||||
[[ -n "$quotaMount" ]] || { appError "Quota mount not found: $olsVhostsPath"; return 1; }
|
||||
quotaMount=$(findmnt -no TARGET --target "$vhostsPath")
|
||||
[[ -n "$quotaMount" ]] || { appError "Quota mount not found: $vhostsPath"; return 1; }
|
||||
|
||||
local quotaLimits error
|
||||
run quotaLimits error quota -u "$user" --filesystem "$quotaMount" || { appError "$error"; return 1; }
|
||||
@@ -427,35 +274,11 @@ function openlitespeedVhostQuotaGet() {
|
||||
printf '%s\n' "$quotaLimits"
|
||||
}
|
||||
|
||||
# Sets user disk and inode quota for a virtual host.
|
||||
# Requires user quota to be already enabled and active on the target filesystem.
|
||||
# $1 (domain): site domain name.
|
||||
function openlitespeedVhostQuotaSet() {
|
||||
local domain
|
||||
domain=$(domainPrepare "$1")
|
||||
domainCheck "$domain" || return 1
|
||||
|
||||
local ug
|
||||
ug=$(domainToUser "$domain")
|
||||
|
||||
local quotaMount
|
||||
quotaMount=$(findmnt -no TARGET --target "$olsVhostsPath")
|
||||
[[ -n "$quotaMount" ]] || { appError "Quota mount not found: $olsVhostsPath"; return 1; }
|
||||
|
||||
local quotaBlockLimit quotaInodeLimit
|
||||
quotaBlockLimit=$(siteConfigGetOrSet "$domain" "quotaBlockLimit" "$olsQuotaBlockLimit")
|
||||
quotaInodeLimit=$(siteConfigGetOrSet "$domain" "quotaInodeLimit" "$olsQuotaInodeLimit")
|
||||
setquota -u "$ug" "$quotaBlockLimit" "$quotaBlockLimit" "$quotaInodeLimit" "$quotaInodeLimit" "$quotaMount" || {
|
||||
appError "Set quota failed: ug=$ug mount=$quotaMount"
|
||||
return 1
|
||||
}
|
||||
}
|
||||
|
||||
# Configures XFS project quota for a virtual host.
|
||||
# $1 (vhostPath): virtual host path to assign to an XFS project.
|
||||
# $2 (projectId): numeric XFS project ID.
|
||||
# $3 (projectName): XFS project name.
|
||||
function openlitespeedVhostXfsSet() {
|
||||
function openlitespeedVhostRebuildXFS() {
|
||||
local vhostPath="$1"
|
||||
local projectId="$2"
|
||||
local projectName="$3"
|
||||
@@ -474,7 +297,7 @@ function openlitespeedVhostXfsSet() {
|
||||
quotaMount=$(findmnt -no TARGET --target "$vhostPath")
|
||||
[[ -n "$quotaMount" ]] || { appError "Detect XFS quota mount failed: $vhostPath"; return 1; }
|
||||
[[ "$quotaMount" == '/' || "$vhostPath" == "$quotaMount"/* ]] || {
|
||||
appError "XFS quota mount mismatch: vhostPath=$vhostPath quotaMount=$quotaMount expected=$olsVhostsPath"
|
||||
appError "XFS quota mount mismatch: vhostPath=$vhostPath quotaMount=$quotaMount expected=$vhostsPath"
|
||||
return 1
|
||||
}
|
||||
|
||||
@@ -512,10 +335,10 @@ function openlitespeedVhostRebuild() {
|
||||
domain=$(domainPrepare "$1")
|
||||
domainCheck "$domain" || return 1
|
||||
|
||||
local ug vhostPath privatePath
|
||||
local ug vhostPath vhostDataPath
|
||||
ug=$(domainToUser "$domain")
|
||||
vhostPath="$olsVhostsPath/$domain"
|
||||
privatePath="$olsPrivatePath/$domain"
|
||||
vhostPath="$vhostsPath/$domain"
|
||||
vhostDataPath="$openlitespeedVhostDataPath/$domain"
|
||||
|
||||
# User and group
|
||||
if ! getent group "$ug" >/dev/null 2>&1; then
|
||||
@@ -527,39 +350,158 @@ function openlitespeedVhostRebuild() {
|
||||
usermod -g "$ug" -d "$vhostPath" -s /usr/sbin/nologin -- "$ug" >/dev/null 2>&1 || { appError "Update user failed: $ug"; return 1; }
|
||||
fi
|
||||
|
||||
openlitespeedVhostPermissionSet "$vhostPath" "$privatePath" "$ug" || return 1
|
||||
openlitespeedVhostAclSet "$vhostPath" "$privatePath" || return 1
|
||||
openlitespeedVhostRebuildPath "$vhostPath" "$vhostDataPath" "$ug" || return 1
|
||||
openlitespeedVhostRebuildACL "$vhostPath" "$vhostDataPath" || return 1
|
||||
|
||||
# Quota
|
||||
# openlitespeedVhostQuotaSet "$domain" || return 1
|
||||
# openlitespeedVhostRebuildQuota "$domain" || return 1
|
||||
|
||||
# XFS [ NO USE ! | Only for XFS + prjquota ]
|
||||
# local uId
|
||||
# uId=$(id -u "$ug" 2>/dev/null)
|
||||
# [[ -n "$uId" ]] || { appError "Get user id failed: $ug"; return 1; }
|
||||
# openlitespeedVhostXfsSet "$vhostPath" "$uId" "$domain" || return 1
|
||||
# openlitespeedVhostRebuildXFS "$vhostPath" "$uId" "$domain" || return 1
|
||||
}
|
||||
|
||||
# Edits the OLS WebAdmin config file.
|
||||
# $@ (...): edit mode and arguments.
|
||||
function openlitespeedAdminConfigEdit() {
|
||||
openlitespeedConfigEditFile "$olsAdminPath/admin_config.conf" "$@"
|
||||
# Creates or deletes OLS config entries for a virtual host.
|
||||
# On create, generates the vhost config file from template if it does not exist.
|
||||
# $1 (domain): site domain name.
|
||||
# [$2] (option): action: create or delete (defaults to create).
|
||||
function openlitespeedConfigRebuild() {
|
||||
local domain
|
||||
domain=$(domainPrepare "$1")
|
||||
domainCheck "$domain" || return 1
|
||||
|
||||
local option="${2:-create}"
|
||||
case "$option" in
|
||||
create|delete) ;;
|
||||
*)
|
||||
appError "Unknown option: $option"
|
||||
return 1
|
||||
;;
|
||||
esac
|
||||
|
||||
fileBackup "$openlitespeedConfigFile" || return 1
|
||||
|
||||
openlitespeedConfigVHostDel "$domain" || return 1
|
||||
|
||||
local vHostFile="$openlitespeedVhostsPath/$domain.conf"
|
||||
if [[ "$option" == "create" ]]; then
|
||||
openlitespeedConfigEditAdd 'listener\h+HTTP' map "$domain $domain" || return 1
|
||||
openlitespeedConfigVHostAdd "$domain" || return 1
|
||||
|
||||
if [[ ! -f "$vHostFile" ]]; then
|
||||
local profileFile memory_limit max_execution_time post_max_size upload_max_filesize
|
||||
profileFile="$appAssetsPath/openlitespeed/profiles/memory-$kubeMemoryProfile.config"
|
||||
[[ -f "$profileFile" ]] || { appError "Profile not found: $profileFile"; return 1; }
|
||||
memory_limit=$(configGet "$profileFile" "memory_limit")
|
||||
max_execution_time=$(configGet "$profileFile" "max_execution_time")
|
||||
post_max_size=$(configGet "$profileFile" "post_max_size")
|
||||
upload_max_filesize=$(configGet "$profileFile" "upload_max_filesize")
|
||||
|
||||
cp -f -- "$appAssetsPath/openlitespeed/vhost.conf" "$vHostFile" || { appError "Copy vhost template failed"; return 1; }
|
||||
sed -i \
|
||||
-e "s|{{domain}}|$domain|g" \
|
||||
-e "s|{{memory_limit}}|$memory_limit|g" \
|
||||
-e "s|{{max_execution_time}}|$max_execution_time|g" \
|
||||
-e "s|{{post_max_size}}|$post_max_size|g" \
|
||||
-e "s|{{upload_max_filesize}}|$upload_max_filesize|g" \
|
||||
-- "$vHostFile" || { appError "Template substitution failed: $vHostFile"; return 1; }
|
||||
fi
|
||||
else
|
||||
openlitespeedConfigEditDelMasked 'listener\h+HTTP' map "$domain *" || return 1
|
||||
rm -f -- "$vHostFile"
|
||||
rm -f -- "$openlitespeedVhostsPath/$domain.conf0"
|
||||
rm -f -- "$openlitespeedVhostsPath/$domain.txt"
|
||||
openlitespeedConfigEdit vhost_up "$domain"
|
||||
fi
|
||||
|
||||
openlitespeedConfigNormalize "$openlitespeedConfigFile" || return 1
|
||||
}
|
||||
|
||||
# Sets a value in the OLS WebAdmin config.
|
||||
function openlitespeedAdminConfigKeySet() {
|
||||
openlitespeedAdminConfigEdit key_set "$@"
|
||||
# Sets the domain aliases for a virtual host, updating both site config and OLS listener map.
|
||||
# $1 (domain): primary site domain name.
|
||||
# $@ (...): alias domain names to assign.
|
||||
function openlitespeedAliasSet() {
|
||||
local domain
|
||||
domain=$(domainPrepare "$1")
|
||||
domainCheck "$domain" || return 1
|
||||
shift
|
||||
|
||||
local -a aliasesRaw=("$@")
|
||||
local -a aliases=()
|
||||
|
||||
run vhostList error openlitespeedVhostList || { appError "Failed get list of virtual hosts: $error"; return 1; }
|
||||
listContains "$domain" "$vhostList" || { appError "Domain is not exists in OpenLiteSpeed config"; return 1; }
|
||||
|
||||
for aliasRaw in "${aliasesRaw[@]}"; do
|
||||
alias="$(domainPrepare "$aliasRaw")"
|
||||
[[ -n "$alias" ]] || continue
|
||||
[[ "$alias" == "$domain" ]] && continue
|
||||
arrayContains "$alias" "${aliases[@]}" || aliases+=("$alias")
|
||||
done
|
||||
|
||||
for alias in "${aliases[@]}"; do
|
||||
runError error domainCheck "$alias" || { appError "$alias: $error"; return 1; }
|
||||
listContains "$alias" "$vhostList" && { appError "$alias: Is already exists as virtual host"; return 1; }
|
||||
done
|
||||
|
||||
local aliasValue=''
|
||||
[[ ${#aliases[@]} -gt 0 ]] && aliasValue="$(IFS=','; printf '%s\n' "${aliases[*]}")"
|
||||
|
||||
local domainConfigFile="$appDataPath/config/$domain.config"
|
||||
configSet "$domainConfigFile" alias "$aliasValue" || { appError "Failed set alias in $domainConfigFile"; return 1; }
|
||||
|
||||
fileBackup "$openlitespeedConfigFile" || return 1
|
||||
openlitespeedConfigEditDelMasked 'listener\h+HTTP' map "$domain *" || return 1
|
||||
openlitespeedConfigEditAdd 'listener\h+HTTP' map "$domain $domain" || return 1
|
||||
for alias in "${aliases[@]}"; do
|
||||
openlitespeedConfigEditAdd 'listener\h+HTTP' map "$domain $alias" || return 1
|
||||
done
|
||||
|
||||
printf '%s' "$aliasValue"
|
||||
return 0
|
||||
}
|
||||
|
||||
# Updates the Traefik middleware IP whitelist for the OLS admin panel from $olsAdminWhiteList.
|
||||
# Marks a virtual host as suspended.
|
||||
# $1 (domain): site domain name.
|
||||
function openlitespeedVHostDown() {
|
||||
local domain
|
||||
domain=$(domainPrepare "$1")
|
||||
domainCheck "$domain" || return 1
|
||||
|
||||
local vhostList error
|
||||
run vhostList error openlitespeedVhostList || return 1
|
||||
runSilent fileCheckLineLength "$openlitespeedConfigFile" 8000 || { appError "fileCheckLineLength 8000"; return 1; }
|
||||
if listContains "$domain" "$vhostList"; then
|
||||
openlitespeedConfigEdit vhost_down "$domain" || return 1
|
||||
fi
|
||||
}
|
||||
|
||||
# Marks a virtual host as active.
|
||||
# $1 (domain): site domain name.
|
||||
function openlitespeedVHostUp() {
|
||||
local domain
|
||||
domain=$(domainPrepare "$1")
|
||||
domainCheck "$domain" || return 1
|
||||
|
||||
local vhostList error
|
||||
run vhostList error openlitespeedVhostList || return 1
|
||||
|
||||
if listContains "$domain" "$vhostList"; then
|
||||
openlitespeedConfigEdit vhost_up "$domain" || return 1
|
||||
fi
|
||||
}
|
||||
|
||||
# Updates the Traefik middleware IP whitelist for the OLS admin panel from $openlitespeedAdminWhiteList.
|
||||
function openlitespeedAdminWhiteList() {
|
||||
local ipList=() whiteList error
|
||||
for i in "${!olsAdminWhiteList[@]}"; do
|
||||
ipList[$i]="\"${olsAdminWhiteList[$i]}\""
|
||||
for i in "${!openlitespeedAdminWhiteList[@]}"; do
|
||||
ipList[$i]="\"${openlitespeedAdminWhiteList[$i]}\""
|
||||
done
|
||||
whiteList=$(IFS=','; printf '%s' "${ipList[*]}")
|
||||
|
||||
runError error k3sRun patch middleware "$olsKube-admin-allowlist" --type=merge -p "{\"spec\":{\"ipWhiteList\":{\"sourceRange\":[${whiteList}]}}}" \
|
||||
runError error k3sRun patch middleware "$openlitespeedKube-admin-allowlist" --type=merge -p "{\"spec\":{\"ipWhiteList\":{\"sourceRange\":[${whiteList}]}}}" \
|
||||
|| { appError "$error"; return 1; }
|
||||
|
||||
printf '%s' "$whiteList"
|
||||
@@ -576,30 +518,9 @@ function openlitespeedAdminAllowList() {
|
||||
local allowList
|
||||
allowList=$(IFS=','; printf '%s' "${ipList[*]}")
|
||||
|
||||
fileBackup "$olsAdminPath/admin_config.conf" || return 1
|
||||
openlitespeedAdminConfigKeySet 'accessControl' 'deny' 'ALL' || return 1
|
||||
openlitespeedAdminConfigKeySet 'accessControl' 'allow' "$allowList" || return 1
|
||||
fileBackup "$openlitespeedAdminPath/admin_config.conf" || return 1
|
||||
openlitespeedAdminConfigEditSet 'accessControl' deny 'ALL' || return 1
|
||||
openlitespeedAdminConfigEditSet 'accessControl' allow "$allowList" || return 1
|
||||
|
||||
printf '%s' "$allowList"
|
||||
}
|
||||
|
||||
# Checks whether user quota support is ready on the virtual host filesystem.
|
||||
function openlitespeedQuotaCheck() {
|
||||
local quotaMount
|
||||
quotaMount=$(findmnt -no TARGET --target "$olsVhostsPath")
|
||||
[[ -n "$quotaMount" ]] || { appError "Quota mount not found: $olsVhostsPath"; return 1; }
|
||||
|
||||
local quotaOptions
|
||||
quotaOptions=$(findmnt -no OPTIONS --target "$quotaMount")
|
||||
[[ "$quotaOptions" == *usrquota* || "$quotaOptions" == *uquota* ]] || {
|
||||
appError "User quota is not enabled: mount=$quotaMount options=$quotaOptions"
|
||||
return 1
|
||||
}
|
||||
|
||||
quotaon -p "$quotaMount" 2>/dev/null | grep -qi "user quota on" || {
|
||||
appError "User quota is not active: mount=$quotaMount"
|
||||
return 1
|
||||
}
|
||||
|
||||
command -v setquota >/dev/null 2>&1 || { appError "setquota command not found"; return 1; }
|
||||
}
|
||||
|
||||
@@ -9,7 +9,7 @@ function postfixExec() {
|
||||
function postfixPodExec() {
|
||||
local pod="$1"
|
||||
[[ -n "$pod" ]] || { appError "Pod not specified"; return 1; }
|
||||
shift || true
|
||||
shift
|
||||
|
||||
k3sRun exec pod/"$pod" -c "$postfixKube" -- "$@"
|
||||
}
|
||||
@@ -24,38 +24,340 @@ function postfixReload() {
|
||||
postfixExec postfix reload
|
||||
}
|
||||
|
||||
# Creates or updates a Postfix SASL user.
|
||||
# $1 (login): SASL username.
|
||||
# $2 (password): password.
|
||||
function postfixUserSet() {
|
||||
local login="$1" password="$2"
|
||||
[[ -n "$login" ]] || { appError "Login not specified"; return 1; }
|
||||
[[ -n "$password" ]] || { appError "Password not specified"; return 1; }
|
||||
# Rebuilds lmdb maps for domains, aliases, and senders.
|
||||
function postfixPostmapRebuild() {
|
||||
touch "$postfixConfigPath/$postfixDomainsFile" || return 1
|
||||
touch "$postfixConfigPath/$postfixAliasesFile" || return 1
|
||||
touch "$postfixConfigPath/$postfixSendersFile" || return 1
|
||||
|
||||
local error
|
||||
runError error postfixExec \
|
||||
env SASL_LOGIN="$login" SASL_PWD="$password" SASL_DB="/config/sasldb2" SASL_REALM="$postfixDefaultRealm" \
|
||||
sh -lc 'printf "%s\n" "$SASL_PWD" | saslpasswd2 -p -c -f "$SASL_DB" -u "$SASL_REALM" "$SASL_LOGIN"' || {
|
||||
appError "Failed to create/update SASL user $login: $error"
|
||||
return 1
|
||||
}
|
||||
runError error postfixExec postmap "lmdb:/config/$postfixDomainsFile" || { appError "Failed rebuild $postfixDomainsFile: $error"; return 1; }
|
||||
runError error postfixExec postmap "lmdb:/config/$postfixAliasesFile" || { appError "Failed rebuild $postfixAliasesFile: $error"; return 1; }
|
||||
runError error postfixExec postmap "lmdb:/config/$postfixSendersFile" || { appError "Failed rebuild $postfixSendersFile: $error"; return 1; }
|
||||
}
|
||||
|
||||
# Deletes a Postfix SASL user.
|
||||
# Sets or removes a key/value in a postfix map file.
|
||||
# $1 (file): path to the map file.
|
||||
# $2 (key): map key.
|
||||
# [$3] (value): map value; omit to delete the key.
|
||||
function postfixConfigSet() {
|
||||
local file="$1" key="$2" value="$3"
|
||||
[[ -n "$file" ]] || { appError "File not specified"; return 1; }
|
||||
[[ -n "$key" ]] || { appError "Key not specified"; return 1; }
|
||||
|
||||
value="${value//$'\r'/ }"
|
||||
value="${value//$'\n'/ }"
|
||||
local output error
|
||||
|
||||
if [[ ! -f "$file" ]]; then
|
||||
mkdir -p "$(dirname -- "$file")" || { appError "Failed to create folder"; return 1; }
|
||||
install -o root -g root -m 644 /dev/null "$file" || { appError "Failed to create file"; return 1; }
|
||||
else
|
||||
runError error sed -i -E "/^[[:space:]]*${key}[[:space:]]+/d" "$file" || { appError "Error writing to a file: $error"; return 1; }
|
||||
fi
|
||||
|
||||
if [[ -n "$value" ]]; then
|
||||
runShell output error printf "%s\n" "$key $value" ">>" "$file" || { appError "Error writing to a file: $error"; return 1; }
|
||||
fi
|
||||
}
|
||||
|
||||
# Sets or removes a domain entry in the virtual domains map.
|
||||
# $1 (domain): site domain name.
|
||||
# [$2] (value): map value; omit to delete.
|
||||
function postfixVirtualDomainSet() {
|
||||
local domain
|
||||
domain=$(domainPrepare "$1")
|
||||
postfixConfigSet "$postfixConfigPath/$postfixDomainsFile" "$domain" "$2"
|
||||
}
|
||||
|
||||
# Sets or removes an entry in the virtual aliases map.
|
||||
function postfixVirtualAliasSet() {
|
||||
postfixConfigSet "$postfixConfigPath/$postfixAliasesFile" "$@"
|
||||
}
|
||||
|
||||
# Sets or removes a domain entry in the virtual domains map (lmdb-safe variant).
|
||||
# $1 (key): map key.
|
||||
# [$2] (value): map value; omit to delete.
|
||||
function postfixVirtualDomainSet2() {
|
||||
local key="$1"
|
||||
[[ -n "$key" ]] || { appError "Key not specified"; return 1; }
|
||||
local value="$2"
|
||||
local file="$postfixConfigPath/$postfixDomainsFile"
|
||||
|
||||
local escaped
|
||||
escaped=$(printf '%s\n' "$key" | sed 's/[.[\*^$()+?{}|\\/]/\\&/g')
|
||||
sed -i "/^${escaped}[[:space:]]/d" "$file" || { appError "Failed to clean old key in $file"; return 1; }
|
||||
|
||||
if [[ -n "$value" ]]; then
|
||||
printf '%s %s\n' "$key" "$value" >> "$file" || { appError "Failed to append to $file"; return 1; }
|
||||
fi
|
||||
}
|
||||
|
||||
# Adds or removes a (sender, login) pair from the owners file and rebuilds senders map.
|
||||
# $1 (sender): sender address.
|
||||
# $2 (login): SASL login.
|
||||
# [$3] (save): non-empty to add; omit to remove.
|
||||
function postfixSenderOwnerSet() {
|
||||
local sender="$1" login="$2" save="$3"
|
||||
[[ -n "$sender" ]] || { appError "Sender not set"; return 1; }
|
||||
[[ -n "$login" ]] || { appError "Login not set"; return 1; }
|
||||
local ownersFile="$postfixConfigPath/$postfixSendersFile.owners"
|
||||
touch "$ownersFile" || return 1
|
||||
|
||||
local tmp
|
||||
tmp=$(mktemp)
|
||||
awk -v s="$sender" -v l="$login" '!(NF>=2 && $1==s && $2==l)' "$ownersFile" >"$tmp"
|
||||
if [[ -n "$save" ]]; then
|
||||
printf '%s %s\n' "$sender" "$login" >>"$tmp"
|
||||
fi
|
||||
mv -f "$tmp" "$ownersFile"
|
||||
|
||||
postfixSendersRebuild
|
||||
}
|
||||
|
||||
# Sets or removes an entry in the virtual aliases map (lmdb-safe variant).
|
||||
# $1 (key): map key.
|
||||
# [$2] (value): map value; omit to delete.
|
||||
function postfixVirtualAliasSet2() {
|
||||
local key="$1"
|
||||
[[ -n "$key" ]] || { appError "Key not specified"; return 1; }
|
||||
local value="$2"
|
||||
local file="$postfixConfigPath/$postfixAliasesFile"
|
||||
|
||||
local escaped
|
||||
escaped=$(printf '%s\n' "$key" | sed 's/[.[\*^$()+?{}|\\/]/\\&/g')
|
||||
sed -i "/^${escaped}[[:space:]]/d" "$file" || { appError "Failed to clean old key in $file"; return 1; }
|
||||
|
||||
if [[ -n "$value" ]]; then
|
||||
printf '%s %s\n' "$key" "$value" >> "$file" || { appError "Failed to append to $file"; return 1; }
|
||||
fi
|
||||
}
|
||||
|
||||
# Rebuilds the senders map from the .owners file, deduplicating per sender.
|
||||
function postfixSendersRebuild() {
|
||||
local ownersFile="$postfixConfigPath/$postfixSendersFile.owners"
|
||||
local outFile="$postfixConfigPath/$postfixSendersFile"
|
||||
|
||||
touch "$ownersFile" || return 1
|
||||
|
||||
local tmpNorm tmpOut
|
||||
tmpNorm=$(mktemp)
|
||||
tmpOut=$(mktemp)
|
||||
|
||||
awk 'NF>=2 && $1 !~ /^#/ { print $1, $2 }' "$ownersFile" >"$tmpNorm"
|
||||
|
||||
awk '
|
||||
{ s=$1; o=$2; k=s SUBSEP o;
|
||||
if (!seen[k]++) {
|
||||
if (list[s]=="") list[s]=o; else list[s]=list[s] "," o;
|
||||
if (!sseen[s]++) order[++n]=s;
|
||||
}
|
||||
}
|
||||
END { for (i=1; i<=n; i++) { s=order[i]; print s " " list[s]; } }
|
||||
' "$tmpNorm" >"$tmpOut"
|
||||
|
||||
mv -f "$tmpOut" "$outFile"
|
||||
rm -f "$tmpNorm" 2>/dev/null || true
|
||||
}
|
||||
|
||||
# Creates, updates, or deletes a Postfix SASL user.
|
||||
# $1 (login): SASL username.
|
||||
function postfixUserRemove() {
|
||||
local login="$1"
|
||||
# [$2] (password): password; omit to delete the user.
|
||||
function postfixSaslUserSet() {
|
||||
local login="$1" password="$2"
|
||||
[[ -n "$login" ]] || { appError "Login not specified"; return 1; }
|
||||
|
||||
local error
|
||||
runError error postfixExec saslpasswd2 -d -f "/config/sasldb2" -u "$postfixDefaultRealm" "$login" || {
|
||||
appError "Failed to delete SASL user $login"
|
||||
if [[ -z "$password" ]]; then
|
||||
runError error postfixExec saslpasswd2 -d -f "/config/sasldb2" -u "$postfixDefaultRealm" "$login" || {
|
||||
appError "Failed to delete SASL user $login"
|
||||
return 1
|
||||
}
|
||||
else
|
||||
runError error postfixExec \
|
||||
env SASL_LOGIN="$login" SASL_PWD="$password" SASL_DB="/config/sasldb2" SASL_REALM="$postfixDefaultRealm" \
|
||||
sh -lc 'printf "%s\n" "$SASL_PWD" | saslpasswd2 -p -c -f "$SASL_DB" -u "$SASL_REALM" "$SASL_LOGIN"' || {
|
||||
appError "Failed to create/update SASL user $login: $error"
|
||||
return 1
|
||||
}
|
||||
fi
|
||||
}
|
||||
|
||||
# Lists all domains from the virtual domains map file.
|
||||
function postfixDomainList() {
|
||||
local file="$postfixConfigPath/$postfixDomainsFile"
|
||||
[[ -f "$file" ]] || { appError "Domains file not found: $file"; return 1; }
|
||||
|
||||
awk '
|
||||
/^[[:space:]]*$/ { next }
|
||||
/^[[:space:]]*#/ { next }
|
||||
{ print $1 }
|
||||
' "$file" | sort -u
|
||||
}
|
||||
|
||||
# Registers a domain in Postfix: creates SASL user, sets sender ownership, optionally adds alias.
|
||||
# $1 (domain): site domain name.
|
||||
function postfixDomainAdd() {
|
||||
local domain="$1"
|
||||
[[ -n "$domain" ]] || { appError "Domain not specified"; return 1; }
|
||||
|
||||
local pfxId
|
||||
pfxId=$(postfixDomain2id "$domain")
|
||||
local postfixUser postfixPass
|
||||
postfixUser=$(siteConfigGetOrSet "$domain" "postfixUser" "$pfxId")
|
||||
postfixPass=$(siteConfigGetOrCreate "$domain" "postfixPass")
|
||||
|
||||
postfixSenderOwnerSet "$postfixPostmaster" "$postfixUser@$postfixDefaultRealm" "SAVE" || return 1
|
||||
postfixSaslUserSet "$postfixUser" "$postfixPass" || return 1
|
||||
|
||||
local postfixForwardTo
|
||||
postfixForwardTo=$(siteConfigGet "$domain" "postfixForwardTo")
|
||||
if [[ -n "$postfixForwardTo" ]]; then
|
||||
postfixVirtualAliasSet "@$domain" "$postfixForwardTo"
|
||||
postfixVirtualDomainSet "$domain" "OK" || return 1
|
||||
fi
|
||||
}
|
||||
|
||||
# Removes a domain from Postfix: clears SASL user, sender ownership, alias, and domain entry.
|
||||
# $1 (domain): site domain name.
|
||||
function postfixDomainRemove() {
|
||||
local domain="$1"
|
||||
[[ -n "$domain" ]] || { appError "Domain not specified"; return 1; }
|
||||
|
||||
local postfixUser
|
||||
postfixUser=$(siteConfigGet "$domain" "postfixUser")
|
||||
[[ -n "$postfixUser" ]] || { appError "postfixUser not found"; return 1; }
|
||||
|
||||
postfixVirtualDomainSet "$domain"
|
||||
postfixSenderOwnerSet "$postfixPostmaster" "$postfixUser@$postfixDefaultRealm"
|
||||
postfixSaslUserSet "$postfixUser"
|
||||
postfixVirtualAliasSet "@$domain"
|
||||
}
|
||||
|
||||
# Registers a domain in Postfix and rebuilds lmdb maps.
|
||||
# $1 (domain): site domain name.
|
||||
function postfixConfigRebuild() {
|
||||
local domain error
|
||||
domain=$(domainPrepare "$1")
|
||||
runError error domainCheck "$domain" || { appError "$error"; return 1; }
|
||||
runError error postfixDomainAdd "$domain" || { appError "$error"; return 1; }
|
||||
postfixPostmapRebuild
|
||||
}
|
||||
|
||||
# Reloads the opendkim daemon.
|
||||
function postfixDkimReload() {
|
||||
postfixExec sh -lc "pkill -HUP -f '/usr/sbin/opendkim' 2>/dev/null"
|
||||
}
|
||||
|
||||
# Lists domains that have DKIM key material present.
|
||||
function postfixDkimList() {
|
||||
ls -1 "$postfixDkimPath"/keys/*.txt 2>/dev/null | xargs -n1 basename | sed "s/\.txt$//" || true
|
||||
}
|
||||
|
||||
# Generates a DKIM keypair for a domain and updates SigningTable/KeyTable.
|
||||
# $1 (domain): domain name.
|
||||
function postfixDkimAdd() {
|
||||
local domain="$1"
|
||||
[[ -n "$domain" ]] || { appError "Domain not specified"; return 1; }
|
||||
|
||||
if ! test -s "$postfixDkimPath/keys/$domain.private" || ! test -s "$postfixDkimPath/keys/$domain.txt"; then
|
||||
postfixExec sh -lc "
|
||||
set -e
|
||||
|
||||
mkdir -p /etc/opendkim/keys
|
||||
touch /etc/opendkim/SigningTable /etc/opendkim/KeyTable
|
||||
|
||||
opendkim-genkey -b 2048 -r -D '/etc/opendkim/keys' -d '$domain' -s '$postfixDkimSelector'
|
||||
mv -f \"/etc/opendkim/keys/$postfixDkimSelector.private\" \"/etc/opendkim/keys/$domain.private\"
|
||||
mv -f \"/etc/opendkim/keys/$postfixDkimSelector.txt\" \"/etc/opendkim/keys/$domain.txt\"
|
||||
|
||||
chown opendkim:opendkim \"/etc/opendkim/keys/$domain.private\" \"/etc/opendkim/keys/$domain.txt\" || true
|
||||
chmod 0600 \"/etc/opendkim/keys/$domain.private\"
|
||||
chmod 0644 \"/etc/opendkim/keys/$domain.txt\"
|
||||
" || { appError "Failed to add DKIM for $domain"; return 1; }
|
||||
fi
|
||||
|
||||
sed -i "/^\*@$domain[[:space:]]/d" "$postfixDkimPath/SigningTable"
|
||||
sed -i "/^$postfixDkimSelector\._domainkey\.$domain[[:space:]]/d" "$postfixDkimPath/KeyTable"
|
||||
|
||||
echo "*@$domain $postfixDkimSelector._domainkey.$domain" >> "$postfixDkimPath/SigningTable"
|
||||
echo "$postfixDkimSelector._domainkey.$domain $domain:$postfixDkimSelector:/etc/opendkim/keys/$domain.private" >> "$postfixDkimPath/KeyTable"
|
||||
|
||||
postfixDkimReload
|
||||
}
|
||||
|
||||
# Autocreates DKIM keys if missing and returns the TXT record, or lists available domains.
|
||||
# [$1] (domain): domain name; omit to list all domains.
|
||||
function postfixDkimGet() {
|
||||
local domain="$1"
|
||||
if [[ -z "$domain" ]]; then
|
||||
postfixDkimList
|
||||
return
|
||||
fi
|
||||
|
||||
if [[ ! "$domain" =~ ^[A-Za-z0-9]([A-Za-z0-9-]{0,61}[A-Za-z0-9])?(\.[A-Za-z0-9]([A-Za-z0-9-]{0,61}[A-Za-z0-9])?)+$ ]]; then
|
||||
appError "Invalid domain: $domain"
|
||||
return 1
|
||||
fi
|
||||
|
||||
postfixDkimAdd "$domain" || { appError "Failed to create DKIM for $domain"; return 1; }
|
||||
cat "$postfixDkimPath/keys/$domain.txt" 2>/dev/null || true
|
||||
}
|
||||
|
||||
# Removes DKIM key material for a domain and reloads opendkim.
|
||||
# $1 (domain): domain name.
|
||||
function postfixDkimRemove() {
|
||||
local domain="$1"
|
||||
[[ -n "$domain" ]] || { appError "Domain not specified"; return 1; }
|
||||
|
||||
sed -i "/^\*@$domain[[:space:]]/d" "$postfixDkimPath/SigningTable"
|
||||
sed -i "/^$postfixDkimSelector\._domainkey\.$domain[[:space:]]/d" "$postfixDkimPath/KeyTable"
|
||||
|
||||
postfixDkimReload
|
||||
}
|
||||
|
||||
# Sends mail through Postfix from a raw RFC822 message file.
|
||||
# $1 (mailFrom): envelope sender address.
|
||||
# $2 (msgFile): path to the RFC822 message file.
|
||||
function postfixMailSendFromFile() {
|
||||
local mailFrom="$1" msgFile="$2"
|
||||
[[ -n "$mailFrom" ]] || { appError "Mail not specified"; return 1; }
|
||||
[[ -n "$msgFile" ]] || { appError "File not specified"; return 1; }
|
||||
|
||||
local output error
|
||||
runShell output error postfixExec sh -lc "sendmail -v -oi -t -f '$mailFrom'" "<" "$msgFile" || {
|
||||
[[ -n "$error" ]] && appError "$error"
|
||||
return 1
|
||||
}
|
||||
printf '%s' "$output"
|
||||
}
|
||||
|
||||
# Lists aliases from the virtual aliases map file.
|
||||
function postfixAliasList() {
|
||||
local file="$postfixConfigPath/$postfixAliasesFile"
|
||||
[[ -f "$file" ]] || { appError "Aliases file not found: $file"; return 1; }
|
||||
|
||||
awk '
|
||||
/^[[:space:]]*$/ { next }
|
||||
/^[[:space:]]*#/ { next }
|
||||
{ print $1 " -> " $2 }
|
||||
' "$file" | sort -u
|
||||
}
|
||||
|
||||
# Lists senders from the senders owners file.
|
||||
function postfixSendersList() {
|
||||
local file="$postfixConfigPath/$postfixSendersFile.owners"
|
||||
[[ -f "$file" ]] || { appError "Senders file not found: $file"; return 1; }
|
||||
|
||||
awk '
|
||||
/^[[:space:]]*$/ { next }
|
||||
/^[[:space:]]*#/ { next }
|
||||
{ print $1 " -> " $2 }
|
||||
' "$file" | sort -u
|
||||
}
|
||||
|
||||
# Lists all SASL users from the sasldb2 database.
|
||||
function postfixUserList() {
|
||||
function postfixSaslUserList() {
|
||||
local output error
|
||||
run output error postfixExec sasldblistusers2 -f /config/sasldb2 || { appError "$error"; return 1; }
|
||||
|
||||
@@ -65,128 +367,25 @@ function postfixUserList() {
|
||||
' <<<"$output"
|
||||
}
|
||||
|
||||
# Rebuilds the senders map from the current SASL user list.
|
||||
function postfixSendersRebuild() {
|
||||
local outFile="$postfixConfigPath/$postfixSendersFile"
|
||||
# Returns the value for a key in a postfix map file; exits non-zero if not found.
|
||||
# $1 (file): path to the map file.
|
||||
# $2 (key): map key to look up.
|
||||
function postfixMapHas() {
|
||||
local file="$1" key="$2"
|
||||
[[ -n "$file" ]] || { appError "File not specified"; return 1; }
|
||||
[[ -f "$file" ]] || { appError "File not found"; return 1; }
|
||||
[[ -n "$key" ]] || { appError "Key not specified"; return 1; }
|
||||
|
||||
local saslList error
|
||||
run saslList error postfixUserList || { appError "Failed to get SASL list: $error"; return 1; }
|
||||
|
||||
local logins
|
||||
logins=$(awk 'NF' <<<"$saslList" | paste -sd ',' -)
|
||||
|
||||
local tmpOut
|
||||
tmpOut=$(mktemp)
|
||||
[[ -n "$logins" ]] && printf '%s %s\n' "$postfixPostmaster" "$logins" > "$tmpOut"
|
||||
mv -f "$tmpOut" "$outFile"
|
||||
awk -v k="$key" 'NF>=2 && $1==k {print $2; found=1} END {exit !found}' "$file"
|
||||
}
|
||||
|
||||
function postfixConfigRebuild() {
|
||||
local domain="$1"
|
||||
if [[ -n "$domain" ]]; then
|
||||
postfixDomainSet "$domain"
|
||||
fi
|
||||
# Checks whether (postmaster, login) pair exists in the senders owners file.
|
||||
# $1 (login): SASL login to look up.
|
||||
function postfixSenderOwnerHas() {
|
||||
local login="$1"
|
||||
[[ -n "$login" ]] || { appError "Login not specified"; return 1; }
|
||||
local file="$postfixConfigPath/$postfixSendersFile.owners"
|
||||
[[ -f "$file" ]] || { appError "File not found"; return 1; }
|
||||
|
||||
local error
|
||||
# runError error postfixExec postmap "lmdb:/config/$postfixDomainsFile" || { appError "Failed rebuild $postfixDomainsFile: $error"; return 1; }
|
||||
# runError error postfixExec postmap "lmdb:/config/$postfixAliasesFile" || { appError "Failed rebuild $postfixAliasesFile: $error"; return 1; }
|
||||
runError error postfixExec postmap "lmdb:/config/$postfixSendersFile" || { appError "Failed rebuild $postfixSendersFile: $error"; return 1; }
|
||||
}
|
||||
|
||||
function postfixDomainSet() {
|
||||
local domain="$1"
|
||||
[[ -n "$domain" ]] || { appError "Domain not specified"; return 1; }
|
||||
domainCheck "$domain" || return 1
|
||||
|
||||
local pfxId
|
||||
pfxId=$(postfixDomain2id "$domain")
|
||||
local postfixUser postfixPass
|
||||
postfixUser=$(siteConfigGetOrSet "$domain" "postfixUser" "$pfxId")
|
||||
postfixPass=$(siteConfigGetOrCreate "$domain" "postfixPass")
|
||||
|
||||
postfixUserSet "$postfixUser" "$postfixPass" || return 1
|
||||
postfixSendersRebuild
|
||||
postfixConfigRebuild
|
||||
}
|
||||
|
||||
function postfixDomainRemove() {
|
||||
local domain="$1"
|
||||
[[ -n "$domain" ]] || { appError "Domain not specified"; return 1; }
|
||||
|
||||
local postfixUser
|
||||
postfixUser=$(siteConfigGet "$domain" "postfixUser")
|
||||
[[ -n "$postfixUser" ]] || { appError "postfixUser not found"; return 1; }
|
||||
|
||||
postfixUserRemove "$postfixUser"
|
||||
postfixSendersRebuild
|
||||
postfixConfigRebuild
|
||||
}
|
||||
|
||||
# Reloads the opendkim daemon.
|
||||
function postfixDkimReload() {
|
||||
postfixExec sh -lc "pkill -HUP -f '/usr/sbin/opendkim' 2>/dev/null" || true
|
||||
}
|
||||
|
||||
# Lists domains that have DKIM key material present.
|
||||
function postfixDkimList() {
|
||||
local f
|
||||
for f in "$postfixDkimPath/keys/"*.txt; do
|
||||
[[ -f "$f" ]] || continue
|
||||
basename -- "$f" .txt
|
||||
done
|
||||
}
|
||||
|
||||
# Generates a DKIM keypair for a domain and updates SigningTable/KeyTable.
|
||||
# $1 (domain): domain name.
|
||||
function postfixDkimAdd() {
|
||||
local domain="$1"
|
||||
[[ -n "$domain" ]] || { appError "Domain not specified"; return 1; }
|
||||
|
||||
if [[ ! -s "$postfixDkimPath/keys/$domain.private" || ! -s "$postfixDkimPath/keys/$domain.txt" ]]; then
|
||||
postfixExec sh -lc "
|
||||
set -e
|
||||
mkdir -p /etc/opendkim/keys
|
||||
opendkim-genkey -b 2048 -r -D '/etc/opendkim/keys' -d '$domain' -s '$postfixDkimSelector'
|
||||
mv -f \"/etc/opendkim/keys/$postfixDkimSelector.private\" \"/etc/opendkim/keys/$domain.private\"
|
||||
mv -f \"/etc/opendkim/keys/$postfixDkimSelector.txt\" \"/etc/opendkim/keys/$domain.txt\"
|
||||
chown opendkim:opendkim \"/etc/opendkim/keys/$domain.private\" \"/etc/opendkim/keys/$domain.txt\" || true
|
||||
chmod 0600 \"/etc/opendkim/keys/$domain.private\"
|
||||
chmod 0644 \"/etc/opendkim/keys/$domain.txt\"
|
||||
" || { appError "Failed to generate DKIM keys for $domain"; return 1; }
|
||||
fi
|
||||
|
||||
local domainEsc="${domain//./\\.}"
|
||||
local selectorEsc="${postfixDkimSelector//./\\.}"
|
||||
sed -i "/^\*@${domainEsc}[[:space:]]/d" "$postfixDkimPath/SigningTable"
|
||||
sed -i "/^${selectorEsc}\._domainkey\.${domainEsc}[[:space:]]/d" "$postfixDkimPath/KeyTable"
|
||||
|
||||
printf '*@%s %s._domainkey.%s\n' "$domain" "$postfixDkimSelector" "$domain" >> "$postfixDkimPath/SigningTable"
|
||||
printf '%s._domainkey.%s %s:%s:/etc/opendkim/keys/%s.private\n' \
|
||||
"$postfixDkimSelector" "$domain" "$domain" "$postfixDkimSelector" "$domain" >> "$postfixDkimPath/KeyTable"
|
||||
|
||||
postfixDkimReload
|
||||
}
|
||||
|
||||
# Ensures DKIM keys exist for a domain and returns the TXT record.
|
||||
# $1 (domain): domain name.
|
||||
function postfixDkimGet() {
|
||||
local domain="$1"
|
||||
[[ -n "$domain" ]] || { appError "Domain not specified"; return 1; }
|
||||
domainCheck "$domain" || return 1
|
||||
postfixDkimAdd "$domain" || return 1
|
||||
cat "$postfixDkimPath/keys/$domain.txt" 2>/dev/null || true
|
||||
}
|
||||
|
||||
# Removes DKIM table entries for a domain and reloads opendkim.
|
||||
# $1 (domain): domain name.
|
||||
function postfixDkimRemove() {
|
||||
local domain="$1"
|
||||
[[ -n "$domain" ]] || { appError "Domain not specified"; return 1; }
|
||||
|
||||
local domainEsc="${domain//./\\.}"
|
||||
local selectorEsc="${postfixDkimSelector//./\\.}"
|
||||
sed -i "/^\*@${domainEsc}[[:space:]]/d" "$postfixDkimPath/SigningTable"
|
||||
sed -i "/^${selectorEsc}\._domainkey\.${domainEsc}[[:space:]]/d" "$postfixDkimPath/KeyTable"
|
||||
|
||||
postfixDkimReload
|
||||
awk -v s="$postfixPostmaster" -v l="$login" 'NF>=2 && $1==s && $2==l {found=1} END{exit !found}' "$file"
|
||||
}
|
||||
|
||||
@@ -11,7 +11,7 @@ function redisExec() {
|
||||
function redisPodExec() {
|
||||
local pod="$1"
|
||||
[[ -n "$pod" ]] || { appError "Pod not specified"; return 1; }
|
||||
shift || true
|
||||
shift
|
||||
|
||||
local container="$redisKube"
|
||||
[[ "$pod" == "$redisSentinelKube-"* ]] && container="$redisSentinelKube"
|
||||
@@ -33,7 +33,7 @@ function redisExecCli() {
|
||||
# $2+ (...): redis-cli arguments.
|
||||
function redisPodExecCli() {
|
||||
local pod="$1"
|
||||
shift || true
|
||||
shift
|
||||
|
||||
local -a cmd=(redis-cli --no-auth-warning)
|
||||
[[ -n "$redisRootPass" ]] && cmd+=(-a "$redisRootPass")
|
||||
|
||||
@@ -5,7 +5,7 @@ function siteConfigGet() {
|
||||
local domain
|
||||
domain=$(domainPrepare "$1")
|
||||
domainCheck "$domain" || return 1
|
||||
shift || true
|
||||
shift
|
||||
|
||||
configGet "$appDataPath/config/$domain.config" "$@"
|
||||
}
|
||||
@@ -17,7 +17,7 @@ function siteConfigSet() {
|
||||
local domain
|
||||
domain=$(domainPrepare "$1")
|
||||
domainCheck "$domain" || return 1
|
||||
shift || true
|
||||
shift
|
||||
|
||||
configSet "$appDataPath/config/$domain.config" "$@"
|
||||
}
|
||||
@@ -29,7 +29,7 @@ function siteConfigGetOrSet() {
|
||||
local domain
|
||||
domain=$(domainPrepare "$1")
|
||||
domainCheck "$domain" || return 1
|
||||
shift || true
|
||||
shift
|
||||
|
||||
configGetOrSet "$appDataPath/config/$domain.config" "$@"
|
||||
}
|
||||
@@ -41,7 +41,7 @@ function siteConfigGetOrCreate() {
|
||||
local domain
|
||||
domain=$(domainPrepare "$1")
|
||||
domainCheck "$domain" || return 1
|
||||
shift || true
|
||||
shift
|
||||
|
||||
configGetOrCreate "$appDataPath/config/$domain.config" "$@"
|
||||
}
|
||||
@@ -65,19 +65,19 @@ function siteAdd() {
|
||||
return 1
|
||||
fi
|
||||
|
||||
local targetPath="$olsVhostsPath/$domain"
|
||||
local targetPath="$vhostsPath/$domain"
|
||||
[[ ! -e "$targetPath" ]] || { appError "The directory or file exists: $targetPath"; return 1; }
|
||||
|
||||
# OpenLiteSpeed
|
||||
local vhostList aliasList error
|
||||
if ! run vhostList error openlitespeedConfigVhostList; then
|
||||
if ! run vhostList error openlitespeedVhostList all; then
|
||||
appError "Error retrieving vhost list: $error"
|
||||
return 1
|
||||
elif listContains "$domain" "$vhostList"; then
|
||||
appError "Domain already exists in OpenLiteSpeed config: $domain"
|
||||
return 1
|
||||
fi
|
||||
if ! run aliasList error openlitespeedConfigAliasList; then
|
||||
if ! run aliasList error openlitespeedAliasList; then
|
||||
appError "Error retrieving alias list: $error"
|
||||
return 1
|
||||
elif listContains "$domain" "$aliasList"; then
|
||||
@@ -187,7 +187,7 @@ function siteAdd() {
|
||||
return 1
|
||||
fi
|
||||
|
||||
if ! runError error openlitespeedVhostSet "$domain"; then
|
||||
if ! runError error openlitespeedConfigRebuild "$domain"; then
|
||||
_siteAddRollback "Failed OLS config rebuild: $error"
|
||||
return 1
|
||||
fi
|
||||
@@ -220,14 +220,14 @@ function siteAdd() {
|
||||
return 1
|
||||
fi
|
||||
|
||||
if ! runError error postfixDomainSet "$domain"; then
|
||||
if ! runError error postfixDomainAdd "$domain"; then
|
||||
_siteAddRollback "Failed add domain in Postfix: $error"
|
||||
return 1
|
||||
fi
|
||||
# if ! runError error postfixPostmapRebuild; then
|
||||
# _siteAddRollback "Failed postmap rebuild: $error"
|
||||
# return 1
|
||||
# fi
|
||||
if ! runError error postfixPostmapRebuild; then
|
||||
_siteAddRollback "Failed postmap rebuild: $error"
|
||||
return 1
|
||||
fi
|
||||
|
||||
printf '%s' "$domain"
|
||||
}
|
||||
@@ -259,20 +259,25 @@ function siteRemove() {
|
||||
fi
|
||||
|
||||
runSilent postfixDomainRemove "$domain"
|
||||
runSilent postfixPostmapRebuild
|
||||
runSilent systemHostRemove "$domain"
|
||||
runSilent openlitespeedVhostConfigDel "$domain"
|
||||
runSilent openlitespeedConfigRebuild "$domain" delete
|
||||
runSilent openlitespeedConfigEdit vhost_up "$domain"
|
||||
|
||||
rm -f -- "$appDataPath/config/$domain.config" &>/dev/null
|
||||
[[ -n "$domain" && "$domain" != "/" ]] && rm -rf -- "$olsVhostsPath/$domain" &>/dev/null
|
||||
rm -f "$openlitespeedVhostsPath/$domain.conf" &>/dev/null
|
||||
rm -f "$openlitespeedVhostsPath/$domain.conf0" &>/dev/null
|
||||
rm -f "$openlitespeedVhostsPath/$domain.conf.txt" &>/dev/null
|
||||
rm -f "$appDataPath/config/$domain.config" &>/dev/null
|
||||
[[ -n "$domain" && "$domain" != "/" ]] && rm -rf "$vhostsPath/$domain" &>/dev/null
|
||||
|
||||
local ug
|
||||
ug=$(domainToUser "$domain")
|
||||
if [[ -n "$ug" && "$ug" != "root" ]]; then
|
||||
if id "$ug" >/dev/null 2>&1; then
|
||||
userdel "$ug" &>/dev/null
|
||||
runSilent userdel "$ug"
|
||||
fi
|
||||
if getent group "$ug" >/dev/null 2>&1; then
|
||||
groupdel "$ug" &>/dev/null
|
||||
runSilent groupdel "$ug"
|
||||
fi
|
||||
fi
|
||||
|
||||
@@ -297,7 +302,7 @@ function siteCopy() {
|
||||
fi
|
||||
|
||||
local vhostList
|
||||
if ! run vhostList error openlitespeedConfigVhostList; then
|
||||
if ! run vhostList error openlitespeedVhostList all; then
|
||||
appError "Error retrieving vhost list: $error"
|
||||
return 1
|
||||
elif ! listContains "$domain" "$vhostList"; then
|
||||
@@ -309,7 +314,7 @@ function siteCopy() {
|
||||
fi
|
||||
|
||||
local aliasList
|
||||
if ! run aliasList error openlitespeedConfigAliasList; then
|
||||
if ! run aliasList error openlitespeedAliasList; then
|
||||
appError "Error retrieving alias list: $error"
|
||||
return 1
|
||||
elif listContains "$domainNew" "$aliasList"; then
|
||||
@@ -330,7 +335,7 @@ function siteCopy() {
|
||||
return 1
|
||||
fi
|
||||
|
||||
if ! runError error siteAdd "$domainNew" "$olsVhostsPath/$domain/www" "$databaseFile"; then
|
||||
if ! runError error siteAdd "$domainNew" "$vhostsPath/$domain/www" "$databaseFile"; then
|
||||
appError "$domainNew: Create site: $error"
|
||||
return 1
|
||||
fi
|
||||
@@ -365,13 +370,11 @@ function siteRename() {
|
||||
fi
|
||||
|
||||
local aliasList
|
||||
if run aliasList error openlitespeedConfigVhostAliasList "$domain" && [[ -n "$aliasList" ]]; then
|
||||
if run aliasList error openlitespeedVhostAlias "$domain" && [[ -n "$aliasList" ]]; then
|
||||
local -a aliases
|
||||
mapfile -t aliases <<< "$aliasList"
|
||||
# openlitespeedVhostAliasSet "$domain"
|
||||
# openlitespeedVhostAliasSet "$domainNew" "${aliases[@]}"
|
||||
openlitespeedVhostSet "$domain"
|
||||
openlitespeedVhostSet "$domainNew" "${aliases[@]}"
|
||||
openlitespeedAliasSet "$domain"
|
||||
openlitespeedAliasSet "$domainNew" "${aliases[@]}"
|
||||
fi
|
||||
|
||||
runSilent siteRemove "$domain" || true
|
||||
@@ -387,7 +390,7 @@ function sitePasswordReset() {
|
||||
domainCheck "$domain" || return 1
|
||||
|
||||
local error vhostList
|
||||
run vhostList error openlitespeedConfigVhostList || { appError "Failed get list of vhosts: $error"; return 1; }
|
||||
run vhostList error openlitespeedVhostList || { appError "Failed get list of virtual hosts: $error"; return 1; }
|
||||
listContains "$domain" "$vhostList" || { appError "Domain is not exists in OpenLiteSpeed config"; return 1; }
|
||||
|
||||
local result=0
|
||||
@@ -420,7 +423,7 @@ function siteAuthReset() {
|
||||
domainCheck "$domain" || return 1
|
||||
|
||||
local error vhostList
|
||||
run vhostList error openlitespeedConfigVhostList || { appError "Failed get list of vhosts: $error"; return 1; }
|
||||
run vhostList error openlitespeedVhostList || { appError "Failed get list of virtual hosts: $error"; return 1; }
|
||||
listContains "$domain" "$vhostList" || { appError "Domain is not exists in OpenLiteSpeed config"; return 1; }
|
||||
|
||||
local result=0
|
||||
|
||||
@@ -196,7 +196,7 @@ function sftpAccessEnable() {
|
||||
local output error ug
|
||||
ug=$(domainToUser "$domain")
|
||||
id "$ug" >/dev/null 2>&1 || { appError "User does not exist: $ug"; return 1; }
|
||||
[[ -d "$olsVhostsPath/$domain/www" ]] || { appError "Vhost www directory does not exist: $olsVhostsPath/$domain/www"; return 1; }
|
||||
[[ -d "$vhostsPath/$domain/www" ]] || { appError "Vhost www directory does not exist: $vhostsPath/$domain/www"; return 1; }
|
||||
|
||||
if ! id -nG "$ug" | tr ' ' '\n' | grep -Fxq "$sftpAccessGroup"; then
|
||||
run output error usermod -aG "$sftpAccessGroup" "$ug" || { appError "Add user $ug to $sftpAccessGroup: $error"; return 1; }
|
||||
|
||||
@@ -1,116 +0,0 @@
|
||||
function unigmaGetTxt() {
|
||||
local domain="$1"
|
||||
local raw
|
||||
|
||||
raw=$(dig +short +time=2 +tries=1 TXT "$domain.settings.wedos-int.dev" 2>/dev/null)
|
||||
[[ -n "$raw" ]] || return 1
|
||||
|
||||
printf '%s\n' "$raw" | tr -d '"' | tr '\n' ' '
|
||||
}
|
||||
|
||||
function unigmaParse() {
|
||||
local raw="$1"
|
||||
UNIGMA_PHP="" UNIGMA_MEM="" UNIGMA_EXEC=""
|
||||
|
||||
local IFS=';' pair key value
|
||||
for pair in $raw; do
|
||||
pair="$(sed 's/^[[:space:]]*//;s/[[:space:]]*$//' <<< "$pair")"
|
||||
[[ -z "$pair" || "$pair" != *"="* ]] && continue
|
||||
|
||||
key="$(sed 's/^[[:space:]]*//;s/[[:space:]]*$//' <<< "${pair%%=*}")"
|
||||
value="$(sed 's/^[[:space:]]*//;s/[[:space:]]*$//' <<< "${pair#*=}")"
|
||||
|
||||
case "$key" in
|
||||
php) UNIGMA_PHP="$value" ;;
|
||||
mem|memory_limit) UNIGMA_MEM="$value" ;;
|
||||
exec|max_execution_time) UNIGMA_EXEC="$value" ;;
|
||||
esac
|
||||
done
|
||||
}
|
||||
|
||||
function unigmaIniSet() {
|
||||
local domain="$1"
|
||||
local mem="$2"
|
||||
local exec="$3"
|
||||
local file content="" existing uid gid
|
||||
|
||||
[[ -n "$mem" || -n "$exec" ]] || return 0
|
||||
|
||||
uid=$(domainToUid "$domain")
|
||||
[[ -n "$uid" ]] || { appError "Cannot resolve UID for: $domain"; return 1; }
|
||||
gid=$(domainToUid "$domain")
|
||||
[[ -n "$gid" ]] || { appError "Cannot resolve GID for: $domain"; return 1; }
|
||||
|
||||
[[ -n "$mem" ]] && content+="memory_limit = ${mem}"$'\n'
|
||||
[[ -n "$exec" ]] && content+="max_execution_time = ${exec}"$'\n'
|
||||
file="$olsPrivatePath/$domain/php/01-ols-private.ini"
|
||||
|
||||
# no change
|
||||
existing="$(cat "$file" 2>/dev/null || true)"
|
||||
[[ "${content%$'\n'}" == "$existing" ]] && return 0
|
||||
|
||||
fileAtomicWrite "$file" "$content"
|
||||
chown -- "$uid:$gid" "$file" || { appError "Change owner of file: $file"; return 1; }
|
||||
return 2
|
||||
}
|
||||
|
||||
function unigmaPhpSet() {
|
||||
local domain="$1"
|
||||
local php="$2"
|
||||
local path="$olsVhostsPath/$domain/www"
|
||||
[[ -d "$path" ]] || { appError "Directory not found: $path"; return 1; }
|
||||
|
||||
local uid gid
|
||||
uid=$(domainToUid "$domain")
|
||||
[[ -n "$uid" ]] || { appError "Cannot resolve UID for: $domain"; return 1; }
|
||||
gid=$(domainToGid "$domain")
|
||||
[[ -n "$gid" ]] || { appError "Cannot resolve GID for: $domain"; return 1; }
|
||||
|
||||
if [[ -z "$php" ]]; then
|
||||
find "$path" -maxdepth 1 -type f -name '.php[1-9][0-9]' -delete
|
||||
return 0
|
||||
fi
|
||||
|
||||
local suffix="${php//./}"
|
||||
[[ "$suffix" =~ ^[1-9][0-9]$ ]] || { appError "Incorrect PHP version: $php"; return 1; }
|
||||
|
||||
# target
|
||||
local target="$path/.php$suffix"
|
||||
|
||||
# find files .phpXX
|
||||
local -a current
|
||||
mapfile -t current < <(find "$path" -maxdepth 1 -type f -name '.php[1-9][0-9]')
|
||||
if [[ ${#current[@]} -eq 0 ]]; then
|
||||
touch "$target"
|
||||
chown -- "$uid:$gid" "$target" || true
|
||||
return 0
|
||||
fi
|
||||
|
||||
# no change
|
||||
if [[ ${#current[@]} -eq 1 && "${current[0]}" == "$target" ]]; then
|
||||
return 0
|
||||
fi
|
||||
|
||||
# rename (atomic substitution)
|
||||
mv -f "${current[0]}" "$target"
|
||||
chown -- "$uid:$gid" "$target" || true
|
||||
|
||||
# remove other files .phpXX
|
||||
if [[ ${#current[@]} -gt 1 ]]; then
|
||||
local i
|
||||
for ((i = 1; i < ${#current[@]}; i++)); do
|
||||
rm -f "${current[i]}"
|
||||
done
|
||||
fi
|
||||
}
|
||||
|
||||
function unigmaUpdate() {
|
||||
local domain="$1"
|
||||
|
||||
local raw
|
||||
raw="$(unigmaGetTxt "$domain")" || return 0
|
||||
|
||||
unigmaParse "$raw"
|
||||
unigmaIniSet "$domain" "$UNIGMA_MEM" "$UNIGMA_EXEC"
|
||||
unigmaPhpSet "$domain" "$UNIGMA_PHP"
|
||||
}
|
||||
@@ -33,16 +33,16 @@ function wordpressExec() {
|
||||
local domain="$1"
|
||||
[[ -n "$domain" ]] || { appError "Domain not specified"; return 1; }
|
||||
domain=$(domainPrepare "$domain")
|
||||
shift || true
|
||||
shift
|
||||
|
||||
openlitespeedExec wp --path="$olsPodVhostsPath/$domain/www" --allow-root --skip-plugins --skip-themes --require="$olsPodPrivatePath/$domain/bootstrap.php" --exec='error_reporting(0);define("WP_DEBUG",false);' "$@"
|
||||
openlitespeedExec wp --path=/var/www/vhosts/"$domain"/www --allow-root --skip-plugins --skip-themes --require=/var/www/data/"$domain"/bootstrap.php --exec='error_reporting(0);define("WP_DEBUG",false);' "$@"
|
||||
}
|
||||
|
||||
function wordpressSalt() {
|
||||
local domain="$1"
|
||||
[[ -n "$domain" ]] || { appError "Domain not specified"; return 1; }
|
||||
domain=$(domainPrepare "$domain")
|
||||
shift || true
|
||||
shift
|
||||
|
||||
wordpressExec "$domain" config shuffle-salts;
|
||||
}
|
||||
@@ -76,7 +76,7 @@ function wordpressConfigUpdate() {
|
||||
|
||||
local ug bootstrapFile tmpFile
|
||||
ug=$(domainToUser "$domain")
|
||||
bootstrapFile="$olsPrivatePath/$domain/bootstrap.php"
|
||||
bootstrapFile="$openlitespeedVhostDataPath/$domain/bootstrap.php"
|
||||
tmpFile="$bootstrapFile".tmp
|
||||
|
||||
local databaseName databaseUser databasePass redisUser redisPass postfixUser postfixPass key
|
||||
@@ -91,11 +91,6 @@ function wordpressConfigUpdate() {
|
||||
[[ -n "${!key}" ]] || { appError "wordpressConfigUpdate: $key is empty"; return 1; }
|
||||
done
|
||||
|
||||
# aliases...
|
||||
local aliasList aliasFirst error
|
||||
run aliasList error openlitespeedConfigVhostAliasList "$domain"
|
||||
aliasFirst=$(awk 'NR==1' <<< "$aliasList")
|
||||
|
||||
cat > "$tmpFile" <<PHP
|
||||
<?php
|
||||
|
||||
@@ -115,13 +110,8 @@ define('SODEW_SMTP_USER', '${postfixUser}@${postfixDefaultRealm}');
|
||||
define('SODEW_SMTP_PASS', '$postfixPass');
|
||||
define('SODEW_SMTP_HOST', '$postfixHost');
|
||||
define('SODEW_SMTP_POSTMASTER', '$postfixPostmaster');
|
||||
|
||||
define('HOSTING_WP_DOMAIN', "$domain");
|
||||
PHP
|
||||
|
||||
# adding a constant for the alias — if it exists
|
||||
[[ -n "$aliasFirst" ]] && printf "define('HOSTING_WP_INTERNAL_URL', '%s');\n" "$aliasFirst" >> "$tmpFile"
|
||||
|
||||
chown -R -- "$ug:$ug" "$tmpFile" || { appError "Change owner of vhost data directory failed: $tmpFile"; return 1; }
|
||||
chmod 600 -- "$tmpFile" || { appError "Change permissions of vhost data files failed: $tmpFile"; return 1; }
|
||||
mv -f -- "$tmpFile" "$bootstrapFile" || return 1
|
||||
@@ -134,7 +124,7 @@ function wordpressConfigDefine() {
|
||||
domain=$(domainPrepare "$1")
|
||||
domainCheck "$domain" || return 1
|
||||
|
||||
local configFile="$olsVhostsPath/$domain/www/wp-config.php"
|
||||
local configFile="$vhostsPath/$domain/www/wp-config.php"
|
||||
[[ -f "$configFile" ]] || { appError "File not found: $configFile"; return 1; }
|
||||
|
||||
local constants=(
|
||||
@@ -173,7 +163,7 @@ function wordpressConfigRebuild() {
|
||||
wordpressConfigUpdate "$domain" || return 1
|
||||
|
||||
local muPluginsPath ug
|
||||
muPluginsPath="$olsVhostsPath/$domain/www/wp-content/mu-plugins"
|
||||
muPluginsPath="$vhostsPath/$domain/www/wp-content/mu-plugins"
|
||||
ug=$(domainToUser "$domain")
|
||||
|
||||
[[ -d "$muPluginsPath" ]] || mkdir -p -- "$muPluginsPath" || { appError "Create directory failed: $muPluginsPath"; return 1; }
|
||||
@@ -288,8 +278,8 @@ function wordpressDomainUpdate() {
|
||||
wordpressSearchReplace "$domain" "$rootOld" "$siteNew"
|
||||
fi
|
||||
if [[ -n "$abspathOld" ]]; then
|
||||
printInfo "$wordpressLabel Replace in DB (6): $abspathOld --> $olsPodVhostsPath/$domain/www"
|
||||
wordpressSearchReplace "$domain" "$abspathOld" "$olsPodVhostsPath/$domain/www"
|
||||
printInfo "$wordpressLabel Replace in DB (6): $abspathOld --> /var/www/vhosts/$domain/www"
|
||||
wordpressSearchReplace "$domain" "$abspathOld" "/var/www/vhosts/$domain/www"
|
||||
fi
|
||||
|
||||
printInfo "$wordpressLabel Replace in DB (7): $hostOld --> $domain"
|
||||
|
||||
Reference in New Issue
Block a user