jina verze

This commit is contained in:
2026-08-12 10:53:04 +02:00
parent f186ec26a8
commit 93d4f24f07
43 changed files with 1686 additions and 1959 deletions
+187 -179
View File
@@ -2,7 +2,7 @@ openlitespeedLabel="[OpenLiteSpeed]"
# Renders the OpenLiteSpeed Kubernetes YAML manifest via Helm.
function cmdOpenlitespeedYamlRender() {
local templateFile="templates/$olsKube.yaml"
local templateFile="templates/$openlitespeedKube.yaml"
printSection "Render YAML file | Helm"
printDotText "Template" "$appAssetsPath/k3s/$templateFile"
@@ -26,13 +26,13 @@ function cmdOpenlitespeedYamlRender() {
}
local adminWhiteList=() adminWhiteStr
for i in "${!olsAdminWhiteList[@]}"; do
adminWhiteList[$i]="\"${olsAdminWhiteList[$i]}\""
for i in "${!openlitespeedAdminWhiteList[@]}"; do
adminWhiteList[$i]="\"${openlitespeedAdminWhiteList[$i]}\""
done
adminWhiteStr=$(IFS=','; printf '%s\n' "${adminWhiteList[*]}")
local varsFile
varsFile=$(mktemp "/tmp/$olsKube.vars.XXXXXX.yaml") || {
varsFile=$(mktemp "/tmp/$openlitespeedKube.vars.XXXXXX.yaml") || {
printDotText "render" "$labelFail"
printDanger "Create temp variables file"
return 1
@@ -42,24 +42,21 @@ function cmdOpenlitespeedYamlRender() {
cat > "$varsFile" <<EOF
openlitespeedHelm: true
namespace: $k3sNamespace
openlitespeed: $olsKube
olsPodVhostsPath: $olsPodVhostsPath
olsPodPrivatePath: $olsPodPrivatePath
olsPodPublicPath: $olsPodPublicPath
olsVhostsPath: $olsVhostsPath
olsPrivatePath: $olsPrivatePath
olsPublicPath: $olsPublicPath
olsConfigPath: $olsConfigPath
olsPhpIniPath: $olsPhpIniPath
olsLogsPath: $olsLogsPath
olsAdminPath: $olsAdminPath
olsAdminWhiteList: $adminWhiteStr
openlitespeed: $openlitespeedKube
openlitespeedConfigPath: $openlitespeedConfigPath
openlitespeedPhpIniPath: $openlitespeedPhpIniPath
openlitespeedLogsPath: $openlitespeedLogsPath
openlitespeedVhostDataPath: $openlitespeedVhostDataPath
openlitespeedVhostSharedPath: $openlitespeedVhostSharedPath
openlitespeedAdminPath: $openlitespeedAdminPath
openlitespeedAdminWhiteList: $adminWhiteStr
vhostsPath: $vhostsPath
EOF
printDotText "Result" "$olsYaml"
mkdir -p -- "$(dirname -- "$olsYaml")" || return 1
fileBackup "$olsYaml"
helm template stack "$appAssetsPath/k3s" -f "$varsFile" -f "$profileCpuFile" -f "$profileMemoryFile" --show-only "$templateFile" > "$olsYaml" || {
printDotText "Result" "$openlitespeedYaml"
mkdir -p -- "$(dirname -- "$openlitespeedYaml")" || return 1
fileBackup "$openlitespeedYaml"
helm template stack "$appAssetsPath/k3s" -f "$varsFile" -f "$profileCpuFile" -f "$profileMemoryFile" --show-only "$templateFile" > "$openlitespeedYaml" || {
printDotText "render" "$labelFail"
printDanger "Render failed"
return 1
@@ -70,35 +67,8 @@ EOF
# Initializes OpenLiteSpeed after Kubernetes deployment: patches Traefik, sets admin credentials, PHP config, rules, and restarts.
function cmdOpenlitespeedInit() {
printSection "Initialization..."
printInfo "$openlitespeedLabel Initialization..."
local ug
ug="$(stat -c "%u:%g" "$olsConfigFile")"
# Patch svc traefik
runSilent "$k3sCmd" kubectl -n kube-system patch svc traefik -p '{"spec": {"externalTrafficPolicy": "Local"}}' || {
printDotText "Patch svc traefik" "$labelFail"
return 1
}
printDotText "Patch svc traefik" "$labelDone"
cmdOpenlitespeedWaitReady || return 1
# Updating Administrator Password
runSilent cmdOpenlitespeedAdminPassUpdate "$olsAdminPass" || {
printDotText "Updating admin password" "$labelFail"
return 1
}
printDotText "Updating admin password" "$labelDone"
# Adding redirect rules
mkdir -p "$olsConfigPath/rules"
cp -n "$appAssetsPath"/openlitespeed/rules/* "$olsConfigPath/rules/"
chown -R "$ug" "$olsConfigPath/rules"
chmod 750 -R "$olsConfigPath/rules"
printDotText "Adding redirect rules" "$labelDone"
# Adding PHP configs
local profileFile="$appAssetsPath/openlitespeed/profiles/memory-$kubeMemoryProfile.config"
local children max_memory_limit memory_limit max_execution_time post_max_size upload_max_filesize
children=$(configGet "$profileFile" "children")
@@ -108,7 +78,15 @@ function cmdOpenlitespeedInit() {
post_max_size=$(configGet "$profileFile" "post_max_size")
upload_max_filesize=$(configGet "$profileFile" "upload_max_filesize")
local phpIniFile="$olsPhpIniPath/00-ols-master.ini"
"$k3sCmd" kubectl -n kube-system patch svc traefik -p '{"spec": {"externalTrafficPolicy": "Local"}}'
cmdOpenlitespeedWaitReady || return 1
cmdOpenlitespeedAdminPassUpdate "$openlitespeedAdminPass" || return 1
local ug output error
run ug error stat -c "%u:%g" "$openlitespeedConfigFile" || printDanger "$openlitespeedLabel Stat: $error"
printInfo "$openlitespeedLabel Adding PHP configs..."
local phpIniFile="$openlitespeedPhpIniPath/00-ols-master.ini"
fileBackup "$phpIniFile"
cp -f -- "$appAssetsPath/openlitespeed/php/00-ols-master.ini" "$phpIniFile"
sed -i \
@@ -119,43 +97,58 @@ function cmdOpenlitespeedInit() {
-e "s|{{post_max_size}}|$post_max_size|g" \
-e "s|{{upload_max_filesize}}|$upload_max_filesize|g" \
-- "$phpIniFile"
find "$olsPhpIniPath" -type f -exec chmod 644 {} +
printDotText "Adding PHP configs" "$labelDone"
find "$openlitespeedPhpIniPath" -type f -exec chmod 644 {} +
# Path OLS Admin config
runSilent openlitespeedAdminAllowList || {
printDotText "Path OLS Admin config" "$labelFail"
return 1
}
printDotText "Path OLS Admin config" "$labelDone"
printInfo "$openlitespeedLabel Adding redirect rules..."
mkdir -p "$openlitespeedConfigPath/rules"
cp -n "$appAssetsPath"/openlitespeed/rules/* "$openlitespeedConfigPath/rules/"
chown -R "$ug" "$openlitespeedConfigPath/rules"
chmod 750 -R "$openlitespeedConfigPath/rules"
# Path OLS config
openlitespeedConfigRebuild || {
printDotText "Path OLS config" "$labelFail"
return 1
}
printDotText "Path OLS config" "$labelDone"
printInfo "$openlitespeedLabel Path OLS config..."
fileBackup "$openlitespeedConfigFile"
openlitespeedConfigEditSet '' useIpInProxyHeader 2 || return 1
openlitespeedConfigEditSet 'fileAccessControl' checkSymbolLink 1 || return 1
openlitespeedConfigEditSet 'accessControl' allow '10.42.0.0/16T, 10.43.0.0/16T' || return 1
openlitespeedConfigEditDel 'ext[Pp]rocessor\h+lsphp' env 'PHPRC=*' || return 1
openlitespeedConfigEditSet 'ext[Pp]rocessor\h+lsphp' backlog 100 || return 1
openlitespeedConfigEditSet 'ext[Pp]rocessor\h+lsphp' procSoftLimit 700 || return 1
openlitespeedConfigEditSet 'ext[Pp]rocessor\h+lsphp' procHardLimit 800 || return 1
openlitespeedConfigEditSet 'ext[Pp]rocessor\h+lsphp' maxConns "$children" || return 1
openlitespeedConfigEditSetMasked 'ext[Pp]rocessor\h+lsphp' env 'PHP_INI_SCAN_DIR=*' 'PHP_INI_SCAN_DIR=:/etc/ols-php-ini' || return 1
openlitespeedConfigEditSetMasked 'ext[Pp]rocessor\h+lsphp' env 'PHP_LSAPI_CHILDREN=*' "PHP_LSAPI_CHILDREN=$children" || return 1
openlitespeedConfigEditSetMasked 'ext[Pp]rocessor\h+lsphp' env 'LSAPI_AVOID_FORK=*' 'LSAPI_AVOID_FORK=0' || return 1
openlitespeedConfigEditSetMasked 'ext[Pp]rocessor\h+lsphp' env 'LSAPI_MAX_IDLE=*' 'LSAPI_MAX_IDLE=120' || return 1
openlitespeedConfigEditSetMasked 'ext[Pp]rocessor\h+lsphp' env 'LSAPI_MAX_IDLE_CHILDREN=*' 'LSAPI_MAX_IDLE_CHILDREN=1' || return 1
openlitespeedConfigEditSetMasked 'ext[Pp]rocessor\h+lsphp' env 'LSAPI_PGRP_MAX_IDLE=*' 'LSAPI_PGRP_MAX_IDLE=300' || return 1
openlitespeedConfigEditSetMasked 'ext[Pp]rocessor\h+lsphp' env 'LSAPI_MAX_PROCESS_TIME=*' 'LSAPI_MAX_PROCESS_TIME=300' || return 1
openlitespeedConfigEditSetMasked 'ext[Pp]rocessor\h+lsphp' env 'LSAPI_SLOW_REQ_MSECS=*' 'LSAPI_SLOW_REQ_MSECS=5000' || return 1
printInfo "$openlitespeedLabel Path OLS Admin config..."
openlitespeedAdminAllowList || return 1
cmdOpenlitespeedRestart
cmdOpenlitespeedPhpKill all
cmdOpenlitespeedPhpRestart
printSuccess "$openlitespeedLabel Initialization completed"
}
# Updates OpenLiteSpeed Kubernetes resources (limits, replicas, etc.) without re-initialization.
function cmdOpenlitespeedUpdate() {
cmdOpenlitespeedYamlRender || return 1
cmdK3sYamlApplyEx "$olsYaml" || return 1
cmdK3sYamlApplyEx "$openlitespeedYaml" || return 1
}
# Installs OpenLiteSpeed into Kubernetes and runs initialization.
function cmdOpenlitespeedInstall() {
cmdOpenlitespeedYamlRender || return 1
cmdK3sYamlApplyEx "$olsYaml" || return 1
cmdK3sYamlApplyEx "$openlitespeedYaml" || return 1
cmdOpenlitespeedInit
}
# Uninstalls OpenLiteSpeed Kubernetes resources.
function cmdOpenlitespeedUninstall() {
"$k3sCmd" kubectl delete -f "$olsYaml"
"$k3sCmd" kubectl delete -f "$openlitespeedYaml"
}
# Waits until OpenLiteSpeed WebAdmin PHP is ready.
@@ -184,91 +177,101 @@ function cmdOpenlitespeedAdminPassUpdate() {
local encrypt output error
run encrypt error openlitespeedExec /usr/local/lsws/admin/fcgi-bin/admin_php -q /usr/local/lsws/admin/misc/htpasswd.php "$password" || {
printDotText "Get encrypt" "$labelFail"
printDanger "$error"
printDanger "$openlitespeedLabel Create pass | $error"
return 1
}
printDotText "Get encrypt" "$labelDone"
run output error openlitespeedExec bash -c "echo '$user:$encrypt' > /usr/local/lsws/admin/conf/htpasswd" || {
printDotText "Save data" "$labelFail"
printDanger "$error"
printDanger "$openlitespeedLabel Encrypt pass | $error"
return 1
}
printDotText "Save data" "$labelDone"
# if admin... save to <hostname>.openlitespeed
printSuccess "$openlitespeedLabel Authorization parameters updated"
}
# Restarts OpenLiteSpeed on all OLS pods.
function cmdOpenlitespeedRestart() {
local podList error
run podList error k3sPodListStatus "$olsKube" || { printDanger "Get pods: $error"; return 1; }
[[ -n "$podList" ]] || { printDanger "Pods not found"; return 1; }
local output error podList
local pod phase output
while IFS='|' read -r pod phase; do
printSection "$pod"
if ! run podList error k3sPodListStatus "$openlitespeedKube"; then
printDanger "Get pods: $error"
elif [[ -z "$podList" ]]; then
printDanger "Pods not found"
else
while IFS='|' read -r pod phase; do
printSection "$pod"
if [[ "$phase" != "Running" ]]; then
printDotText "Phase" "$fontRed$phase$fontReset"
else
printDotText "Phase" "$fontGreen$phase$fontReset"
if ! run output error openlitespeedPodExec "$pod" /usr/local/lsws/bin/lswsctrl restart; then
printDotText "Restart" "$labelUnknown"
printDanger "$error"
elif [[ "$output" =~ "[OK]" ]]; then
printDotText "Restart" "$fontGreen$output$fontReset"
if [[ "$phase" != "Running" ]]; then
printDotText "Phase" "$fontRed$phase$fontReset"
else
printDotText "Restart" "$fontRed$output$fontReset"
printDotText "Phase" "$fontGreen$phase$fontReset"
if ! run output error openlitespeedPodExec "$pod" /usr/local/lsws/bin/lswsctrl restart; then
printDotText "Restart" "$labelUnknown"
printDanger "$error"
elif [[ "$output" =~ "[OK]" ]]; then
printDotText "Restart" "$fontGreen$output$fontReset"
else
printDotText "Restart" "$fontRed$output$fontReset"
fi
# k3sRun wait --for=condition=Ready "pod/$pod" --timeout=10s >/dev/null 2>&1 || true
fi
fi
done < <(awk 'NF' <<< "$podList")
done < <(awk 'NF' <<< "$podList")
fi
}
# Restarts PHP workers on all OLS pods.
function cmdOpenlitespeedPhpKill() {
local target="$1"
[[ -n "$target" ]] || { printRow; printDanger "Target not specified"; return 1; }
function cmdOpenlitespeedPhpRestart() {
local output error podList
local podList error
run podList error k3sPodListStatus "$olsKube" || { printRow; printDanger "Get pods: $error"; return 1; }
[[ -n "$podList" ]] || { printRow; printDanger "Pods not found"; return 1; }
if ! run podList error k3sPodListStatus "$openlitespeedKube"; then
printDanger "Get pods: $error"
elif [[ -z "$podList" ]]; then
printDanger "Pods not found"
else
while IFS='|' read -r pod phase; do
printSection "$pod"
local uid=""
if [[ "$target" != "all" ]]; then
local vhostList
run vhostList error openlitespeedConfigVhostList || { printRow; printDanger "Cannot get vhost list: $error"; return 1; }
listContains "$target" "$vhostList" || { printRow; printDanger "Unknown domain: $target"; return 1; }
uid=$(domainToUid "$target")
[[ -n "$uid" ]] || { printDanger "Cannot resolve UID for: $target"; return 1; }
fi
local pod phase
while IFS='|' read -r pod phase; do
printSection "$pod"
if [[ "$phase" != "Running" ]]; then
printDotText "Phase" "$fontRed$phase$fontReset"
else
printDotText "Phase" "$fontGreen$phase$fontReset"
if [[ -n "$uid" ]]; then
runSilent openlitespeedPodExec "$pod" pkill -u "$uid" -x lsphp
if [[ "$phase" != "Running" ]]; then
printDotText "Phase" "$fontRed$phase$fontReset"
else
runSilent openlitespeedPodExec "$pod" pkill -x lsphp
printDotText "Phase" "$fontGreen$phase$fontReset"
run output error openlitespeedPodExec "$pod" killall -USR1 lsphp || true
printDotText "PHP" "process restart"
fi
printDotText "kill$fontBlue lsphp$fontReset processes for $target" "$labelDone"
fi
done < <(awk 'NF' <<< "$podList")
done < <(awk 'NF' <<< "$podList")
fi
}
# Restarts PHP (kill) workers on all OLS pods.
function cmdOpenlitespeedPhpKill() {
local output error podList
if ! run podList error k3sPodListStatus "$openlitespeedKube"; then
printDanger "Get pods: $error"
elif [[ -z "$podList" ]]; then
printDanger "Pods not found"
else
while IFS='|' read -r pod phase; do
printSection "$pod"
if [[ "$phase" != "Running" ]]; then
printDotText "Phase" "$fontRed$phase$fontReset"
else
printDotText "Phase" "$fontGreen$phase$fontReset"
run output error openlitespeedPodExec "$pod" pkill -9 -f lsphp || true
printDotText "PHP" "process kill"
fi
done < <(awk 'NF' <<< "$podList")
fi
}
# Prints OpenLiteSpeed and PHP versions for each OLS pod.
function cmdOpenlitespeedInfo() {
local output error podList ver pid
if ! run podList error k3sPodListStatus "$olsKube"; then
if ! run podList error k3sPodListStatus "$openlitespeedKube"; then
printDanger "Get pods: $error"
elif [[ -z "$podList" ]]; then
printDanger "Pods not found"
@@ -310,7 +313,7 @@ function cmdOpenlitespeedInfo() {
printSection "Hosts"
local vhostList vhostDown
if run output error openlitespeedConfigVhostList; then
if run output error openlitespeedVhostList; then
mapfile -t vhostList < <(awk 'NF' <<< "$output")
printDotText "all" "${#vhostList[@]}"
else
@@ -318,7 +321,7 @@ function cmdOpenlitespeedInfo() {
printDanger "$error"
fi
if run output error openlitespeedConfigVhostList "down"; then
if run output error openlitespeedVhostList "down"; then
mapfile -t vhostDownList < <(awk 'NF' <<< "$output")
printDotText "down" "${#vhostDownList[@]}"
else
@@ -326,17 +329,18 @@ function cmdOpenlitespeedInfo() {
printDanger "$error"
fi
local count="$(find "$olsVhostsPath" -mindepth 1 -maxdepth 1 -type d | wc -l)"
printDotText "directories" "$fontGray$olsVhostsPath$fontReset $count"
local count="$(find "$vhostsPath" -mindepth 1 -maxdepth 1 -type d | wc -l)"
printDotText "directories" "$fontGray$vhostsPath$fontReset $count"
}
# Marks a virtual host as suspended.
# $1 (domain): site domain name.
function cmdOpenlitespeedVhostDown() {
function cmdOpenlitespeedVHostDown() {
local error
printRow
local error
if ! runError error openlitespeedVhostConfigDown "$@"; then
if ! runError error openlitespeedVHostDown "$@"; then
printDotText "VHost down" "$labelFail"
printDanger "$error"
else
@@ -347,11 +351,12 @@ function cmdOpenlitespeedVhostDown() {
# Marks a virtual host as active.
# $1 (domain): site domain name.
function cmdOpenlitespeedVhostUp() {
function cmdOpenlitespeedVHostUp() {
local error
printRow
local error
if ! runError error openlitespeedVhostConfigUp "$@"; then
if ! runError error openlitespeedVHostUp "$@"; then
printDotText "VHost up" "$labelFail"
printDanger "$error"
else
@@ -363,10 +368,11 @@ function cmdOpenlitespeedVhostUp() {
# Lists virtual hosts with optional status filtering.
# [$1] (type): all (default) | up | down.
function cmdOpenlitespeedSiteList() {
local output error type="${1:-all}"
printRow
local output error type="${1:-all}"
if ! run output error openlitespeedConfigVhostList "$type"; then
if ! run output error openlitespeedVhostList "$type"; then
printDanger "$error"
else
printText "$output"
@@ -375,66 +381,67 @@ function cmdOpenlitespeedSiteList() {
# Updates the Traefik middleware allowlist for OpenLiteSpeed WebAdmin.
function cmdOpenlitespeedAdminWhiteList() {
local output error
printRow
local output error
run output error openlitespeedAdminWhiteList || { printDotText "Update" "$labelFail"; printDanger "$error"; return 1; }
printDotText "White list" "$output"
printDotText "Update" "$labelDone"
}
# Updates OpenLiteSpeed WebAdmin access control from current Traefik pod IPs.
function cmdOpenlitespeedAdminAllowList() {
printRow
local output error
run output error openlitespeedAdminAllowList || { printDotText "Update" "$labelFail"; printDanger "$error"; return 1; }
printDotText "Allow list: ${output:-$labelNull}"
printDotText "Update" "$labelDone"
cmdOpenlitespeedRestart
if ! run output error openlitespeedAdminWhiteList; then
printDotText "Update" "$labelFail"
printDanger "$error"
else
printDotText "White list" "$output"
printDotText "Update" "$labelDone"
fi
}
# Sets aliases for an OpenLiteSpeed virtual host.
# $1 (domain): primary site domain name.
# $@ (...): alias domain names.
function cmdOpenlitespeedVhostAliasSet() {
local domain
domain=$(domainPrepare "$1")
function cmdOpenlitespeedAliasSet() {
local output error
printRow
domainCheck "$domain" || return 1
local vhostList aliasList output error
if ! run vhostList error openlitespeedConfigVhostList; then
appError "Error retrieving vhost list: $error"
return 1
elif ! listContains "$domain" "$vhostList"; then
appError "Domain not exists in OpenLiteSpeed config: $domain"
return 1
fi
run output error openlitespeedVhostSet "$@" || {
printDotText "Set" "$labelFail"
if ! run output error openlitespeedAliasSet "$@"; then
printDanger "$error"
return 1
}
elif [[ -z "$output" ]]; then
printText "$labelNull"
cmdOpenlitespeedRestart
else
printText "$output"
cmdOpenlitespeedRestart
fi
}
printDotText "Alias" "${output:-$labelNull}"
printDotText "Set" "$labelDone"
cmdOpenlitespeedRestart
# Updates OpenLiteSpeed WebAdmin access control from current Traefik pod IPs.
function cmdOpenlitespeedAdminAllowList() {
local output error
printRow
if ! run output error openlitespeedAdminAllowList; then
printDotText "Update" "$labelFail"
printDanger "$error"
elif [[ -z "$output" ]]; then
printDotText "Allow list" "$labelNull"
printDotText "Update" "$labelDone"
cmdOpenlitespeedRestart
else
printDotText "Allow list" "$output"
printDotText "Update" "$labelDone"
cmdOpenlitespeedRestart
fi
}
# Lists aliases for a domain or all domains.
# [$1] (target): domain name, or "all" to list all.
function cmdOpenlitespeedAliasList() {
local output error domain target="$1"
printRow
local output error domain target="$1"
if [[ "$target" == all ]]; then
if ! run output error openlitespeedConfigAliasList; then
if ! run output error openlitespeedAliasList; then
printDanger "$error"
elif [[ -z "$output" ]]; then
printText "$labelNull"
@@ -443,7 +450,7 @@ function cmdOpenlitespeedAliasList() {
fi
else
domain=$(domainPrepare "$target")
if ! run output error openlitespeedConfigVhostAliasList "$domain"; then
if ! run output error openlitespeedVhostAlias "$domain"; then
printDanger "$error"
elif [[ -z "$output" ]]; then
printText "$labelNull"
@@ -455,9 +462,10 @@ function cmdOpenlitespeedAliasList() {
# Tests the OpenLiteSpeed configuration inside the container.
function cmdOpenlitespeedConfigCheck() {
local output error
printRow
local output error
run output error openlitespeedExec sh -lc "/usr/local/lsws/bin/openlitespeed -t 2>/dev/null || true"
if grep -qi 'configuration failed!' <<< "$output"; then
printDotText "Check config" "$labelFail"
@@ -475,7 +483,7 @@ function cmdOpenlitespeedVhostRebuild() {
if [[ -z "$target" ]]; then
printDanger "Target not specified";
elif ! run vhostList error openlitespeedConfigVhostList; then
elif ! run vhostList error openlitespeedVhostList; then
printDanger "Cannot get vhost list: $error";
elif [[ "$target" == "all" ]]; then
local domain