soubory SODEW
This commit is contained in:
@@ -0,0 +1,498 @@
|
||||
openlitespeedLabel="[OpenLiteSpeed]"
|
||||
|
||||
# Renders the OpenLiteSpeed Kubernetes YAML manifest via Helm.
|
||||
function cmdOpenlitespeedYamlRender() {
|
||||
local templateFile="templates/$olsKube.yaml"
|
||||
|
||||
printSection "Render YAML file | Helm"
|
||||
printDotText "Template" "$appAssetsPath/k3s/$templateFile"
|
||||
[[ -f "$appAssetsPath/k3s/$templateFile" ]] || {
|
||||
printDanger "Template file not found"
|
||||
return 1
|
||||
}
|
||||
|
||||
local profileCpuFile="$appAssetsPath/k3s/profiles/cpu-$kubeCpuProfile.yaml"
|
||||
printDotText "CPU profile" "$profileCpuFile"
|
||||
[[ -f "$profileCpuFile" ]] || {
|
||||
printDanger "CPU profile file not found"
|
||||
return 1
|
||||
}
|
||||
|
||||
local profileMemoryFile="$appAssetsPath/k3s/profiles/memory-$kubeMemoryProfile.yaml"
|
||||
printDotText "Memory profile" "$profileMemoryFile"
|
||||
[[ -f "$profileMemoryFile" ]] || {
|
||||
printDanger "Memory profile file not found"
|
||||
return 1
|
||||
}
|
||||
|
||||
local adminWhiteList=() adminWhiteStr
|
||||
for i in "${!olsAdminWhiteList[@]}"; do
|
||||
adminWhiteList[$i]="\"${olsAdminWhiteList[$i]}\""
|
||||
done
|
||||
adminWhiteStr=$(IFS=','; printf '%s\n' "${adminWhiteList[*]}")
|
||||
|
||||
local varsFile
|
||||
varsFile=$(mktemp "/tmp/$olsKube.vars.XXXXXX.yaml") || {
|
||||
printDotText "render" "$labelFail"
|
||||
printDanger "Create temp variables file"
|
||||
return 1
|
||||
}
|
||||
printDotText "Variables" "$varsFile"
|
||||
trap 'rm -f -- "$varsFile"' RETURN
|
||||
cat > "$varsFile" <<EOF
|
||||
openlitespeedHelm: true
|
||||
namespace: $k3sNamespace
|
||||
openlitespeed: $olsKube
|
||||
olsPodVhostsPath: $olsPodVhostsPath
|
||||
olsPodPrivatePath: $olsPodPrivatePath
|
||||
olsPodPublicPath: $olsPodPublicPath
|
||||
olsVhostsPath: $olsVhostsPath
|
||||
olsPrivatePath: $olsPrivatePath
|
||||
olsPublicPath: $olsPublicPath
|
||||
olsConfigPath: $olsConfigPath
|
||||
olsPhpIniPath: $olsPhpIniPath
|
||||
olsLogsPath: $olsLogsPath
|
||||
olsAdminPath: $olsAdminPath
|
||||
olsAdminWhiteList: $adminWhiteStr
|
||||
EOF
|
||||
|
||||
printDotText "Result" "$olsYaml"
|
||||
mkdir -p -- "$(dirname -- "$olsYaml")" || return 1
|
||||
fileBackup "$olsYaml"
|
||||
helm template stack "$appAssetsPath/k3s" -f "$varsFile" -f "$profileCpuFile" -f "$profileMemoryFile" --show-only "$templateFile" > "$olsYaml" || {
|
||||
printDotText "render" "$labelFail"
|
||||
printDanger "Render failed"
|
||||
return 1
|
||||
}
|
||||
|
||||
printDotText "render" "$labelDone"
|
||||
}
|
||||
|
||||
# Initializes OpenLiteSpeed after Kubernetes deployment: patches Traefik, sets admin credentials, PHP config, rules, and restarts.
|
||||
function cmdOpenlitespeedInit() {
|
||||
printSection "Initialization..."
|
||||
|
||||
local ug
|
||||
ug="$(stat -c "%u:%g" "$olsConfigFile")"
|
||||
|
||||
# Patch svc traefik
|
||||
runSilent "$k3sCmd" kubectl -n kube-system patch svc traefik -p '{"spec": {"externalTrafficPolicy": "Local"}}' || {
|
||||
printDotText "Patch svc traefik" "$labelFail"
|
||||
return 1
|
||||
}
|
||||
printDotText "Patch svc traefik" "$labelDone"
|
||||
|
||||
cmdOpenlitespeedWaitReady || return 1
|
||||
|
||||
# Updating Administrator Password
|
||||
runSilent cmdOpenlitespeedAdminPassUpdate "$olsAdminPass" || {
|
||||
printDotText "Updating admin password" "$labelFail"
|
||||
return 1
|
||||
}
|
||||
printDotText "Updating admin password" "$labelDone"
|
||||
|
||||
# Adding redirect rules
|
||||
mkdir -p "$olsConfigPath/rules"
|
||||
cp -n "$appAssetsPath"/openlitespeed/rules/* "$olsConfigPath/rules/"
|
||||
chown -R "$ug" "$olsConfigPath/rules"
|
||||
chmod 750 -R "$olsConfigPath/rules"
|
||||
printDotText "Adding redirect rules" "$labelDone"
|
||||
|
||||
# Adding PHP configs
|
||||
local profileFile="$appAssetsPath/openlitespeed/profiles/memory-$kubeMemoryProfile.config"
|
||||
local children max_memory_limit memory_limit max_execution_time post_max_size upload_max_filesize
|
||||
children=$(configGet "$profileFile" "children")
|
||||
max_memory_limit=$(configGet "$profileFile" "max_memory_limit")
|
||||
memory_limit=$(configGet "$profileFile" "memory_limit")
|
||||
max_execution_time=$(configGet "$profileFile" "max_execution_time")
|
||||
post_max_size=$(configGet "$profileFile" "post_max_size")
|
||||
upload_max_filesize=$(configGet "$profileFile" "upload_max_filesize")
|
||||
|
||||
local phpIniFile="$olsPhpIniPath/00-ols-master.ini"
|
||||
fileBackup "$phpIniFile"
|
||||
cp -f -- "$appAssetsPath/openlitespeed/php/00-ols-master.ini" "$phpIniFile"
|
||||
sed -i \
|
||||
-e "s|{{children}}|$children|g" \
|
||||
-e "s|{{max_memory_limit}}|$max_memory_limit|g" \
|
||||
-e "s|{{memory_limit}}|$memory_limit|g" \
|
||||
-e "s|{{max_execution_time}}|$max_execution_time|g" \
|
||||
-e "s|{{post_max_size}}|$post_max_size|g" \
|
||||
-e "s|{{upload_max_filesize}}|$upload_max_filesize|g" \
|
||||
-- "$phpIniFile"
|
||||
find "$olsPhpIniPath" -type f -exec chmod 644 {} +
|
||||
printDotText "Adding PHP configs" "$labelDone"
|
||||
|
||||
# Path OLS Admin config
|
||||
runSilent openlitespeedAdminAllowList || {
|
||||
printDotText "Path OLS Admin config" "$labelFail"
|
||||
return 1
|
||||
}
|
||||
printDotText "Path OLS Admin config" "$labelDone"
|
||||
|
||||
# Path OLS config
|
||||
openlitespeedConfigRebuild || {
|
||||
printDotText "Path OLS config" "$labelFail"
|
||||
return 1
|
||||
}
|
||||
printDotText "Path OLS config" "$labelDone"
|
||||
|
||||
cmdOpenlitespeedRestart
|
||||
cmdOpenlitespeedPhpKill all
|
||||
}
|
||||
|
||||
# Updates OpenLiteSpeed Kubernetes resources (limits, replicas, etc.) without re-initialization.
|
||||
function cmdOpenlitespeedUpdate() {
|
||||
cmdOpenlitespeedYamlRender || return 1
|
||||
cmdK3sYamlApplyEx "$olsYaml" || return 1
|
||||
}
|
||||
|
||||
# Installs OpenLiteSpeed into Kubernetes and runs initialization.
|
||||
function cmdOpenlitespeedInstall() {
|
||||
cmdOpenlitespeedYamlRender || return 1
|
||||
cmdK3sYamlApplyEx "$olsYaml" || return 1
|
||||
cmdOpenlitespeedInit
|
||||
}
|
||||
|
||||
# Uninstalls OpenLiteSpeed Kubernetes resources.
|
||||
function cmdOpenlitespeedUninstall() {
|
||||
"$k3sCmd" kubectl delete -f "$olsYaml"
|
||||
}
|
||||
|
||||
# Waits until OpenLiteSpeed WebAdmin PHP is ready.
|
||||
function cmdOpenlitespeedWaitReady() {
|
||||
local tries=${k3sReadyRetries:-10}
|
||||
local sleepSec=${k3sReadySleep:-2}
|
||||
local i output error
|
||||
for ((i=1; i<=tries; i++)); do
|
||||
run output error openlitespeedExec /usr/local/lsws/admin/fcgi-bin/admin_php -v && return 0
|
||||
printWarning "$openlitespeedLabel Waiting..."
|
||||
sleep "$sleepSec"
|
||||
done
|
||||
|
||||
printDanger "$openlitespeedLabel Not ready after ${tries} tries"
|
||||
return 1
|
||||
}
|
||||
|
||||
# Updates OpenLiteSpeed WebAdmin credentials.
|
||||
# $1 (password): WebAdmin password.
|
||||
# [$2] (user): WebAdmin username (default: admin).
|
||||
function cmdOpenlitespeedAdminPassUpdate() {
|
||||
local password="$1"
|
||||
[[ -n "$password" ]] || { printDanger "$openlitespeedLabel Password not specified"; return 1; }
|
||||
|
||||
local user="${2:-admin}"
|
||||
local encrypt output error
|
||||
|
||||
run encrypt error openlitespeedExec /usr/local/lsws/admin/fcgi-bin/admin_php -q /usr/local/lsws/admin/misc/htpasswd.php "$password" || {
|
||||
printDotText "Get encrypt" "$labelFail"
|
||||
printDanger "$error"
|
||||
return 1
|
||||
}
|
||||
printDotText "Get encrypt" "$labelDone"
|
||||
|
||||
run output error openlitespeedExec bash -c "echo '$user:$encrypt' > /usr/local/lsws/admin/conf/htpasswd" || {
|
||||
printDotText "Save data" "$labelFail"
|
||||
printDanger "$error"
|
||||
return 1
|
||||
}
|
||||
printDotText "Save data" "$labelDone"
|
||||
|
||||
# if admin... save to <hostname>.openlitespeed
|
||||
}
|
||||
|
||||
# Restarts OpenLiteSpeed on all OLS pods.
|
||||
function cmdOpenlitespeedRestart() {
|
||||
local podList error
|
||||
run podList error k3sPodListStatus "$olsKube" || { printDanger "Get pods: $error"; return 1; }
|
||||
[[ -n "$podList" ]] || { printDanger "Pods not found"; return 1; }
|
||||
|
||||
local pod phase output
|
||||
while IFS='|' read -r pod phase; do
|
||||
printSection "$pod"
|
||||
|
||||
if [[ "$phase" != "Running" ]]; then
|
||||
printDotText "Phase" "$fontRed$phase$fontReset"
|
||||
else
|
||||
printDotText "Phase" "$fontGreen$phase$fontReset"
|
||||
|
||||
if ! run output error openlitespeedPodExec "$pod" /usr/local/lsws/bin/lswsctrl restart; then
|
||||
printDotText "Restart" "$labelUnknown"
|
||||
printDanger "$error"
|
||||
elif [[ "$output" =~ "[OK]" ]]; then
|
||||
printDotText "Restart" "$fontGreen$output$fontReset"
|
||||
else
|
||||
printDotText "Restart" "$fontRed$output$fontReset"
|
||||
fi
|
||||
fi
|
||||
done < <(awk 'NF' <<< "$podList")
|
||||
}
|
||||
|
||||
# Restarts PHP workers on all OLS pods.
|
||||
function cmdOpenlitespeedPhpKill() {
|
||||
local target="$1"
|
||||
[[ -n "$target" ]] || { printRow; printDanger "Target not specified"; return 1; }
|
||||
|
||||
local podList error
|
||||
run podList error k3sPodListStatus "$olsKube" || { printRow; printDanger "Get pods: $error"; return 1; }
|
||||
[[ -n "$podList" ]] || { printRow; printDanger "Pods not found"; return 1; }
|
||||
|
||||
local uid=""
|
||||
if [[ "$target" != "all" ]]; then
|
||||
local vhostList
|
||||
run vhostList error openlitespeedConfigVhostList || { printRow; printDanger "Cannot get vhost list: $error"; return 1; }
|
||||
listContains "$target" "$vhostList" || { printRow; printDanger "Unknown domain: $target"; return 1; }
|
||||
uid=$(domainToUid "$target")
|
||||
[[ -n "$uid" ]] || { printDanger "Cannot resolve UID for: $target"; return 1; }
|
||||
fi
|
||||
|
||||
local pod phase
|
||||
while IFS='|' read -r pod phase; do
|
||||
printSection "$pod"
|
||||
|
||||
if [[ "$phase" != "Running" ]]; then
|
||||
printDotText "Phase" "$fontRed$phase$fontReset"
|
||||
else
|
||||
printDotText "Phase" "$fontGreen$phase$fontReset"
|
||||
|
||||
if [[ -n "$uid" ]]; then
|
||||
runSilent openlitespeedPodExec "$pod" pkill -u "$uid" -x lsphp
|
||||
else
|
||||
runSilent openlitespeedPodExec "$pod" pkill -x lsphp
|
||||
fi
|
||||
printDotText "kill$fontBlue lsphp$fontReset processes for $target" "$labelDone"
|
||||
fi
|
||||
done < <(awk 'NF' <<< "$podList")
|
||||
}
|
||||
|
||||
# Prints OpenLiteSpeed and PHP versions for each OLS pod.
|
||||
function cmdOpenlitespeedInfo() {
|
||||
local output error podList ver pid
|
||||
|
||||
if ! run podList error k3sPodListStatus "$olsKube"; then
|
||||
printDanger "Get pods: $error"
|
||||
elif [[ -z "$podList" ]]; then
|
||||
printDanger "Pods not found"
|
||||
else
|
||||
while IFS='|' read -r pod phase; do
|
||||
printSection "$pod"
|
||||
|
||||
if [[ "$phase" != "Running" ]]; then
|
||||
printDotText "Phase" "$fontRed$phase$fontReset"
|
||||
else
|
||||
printDotText "Phase" "$fontGreen$phase$fontReset"
|
||||
|
||||
if ! run output error openlitespeedPodExec "$pod" /usr/local/lsws/bin/lswsctrl status; then
|
||||
printDotText "Status" "$labelUnknown"
|
||||
printDanger "$error"
|
||||
elif [[ "$output" =~ "running" ]]; then
|
||||
printDotText "OpenLiteSpeed status" "$fontGreen$output$fontReset"
|
||||
else
|
||||
printDotText "OpenLiteSpeed status" "$fontRed$output$fontReset"
|
||||
fi
|
||||
|
||||
if run output error openlitespeedPodExec "$pod" /usr/local/lsws/bin/lshttpd -v; then
|
||||
ver=$(awk 'NR==1{print $1, $2}' <<< "$output")
|
||||
printDotText "OpenLiteSpeed version" "$ver"
|
||||
else
|
||||
printDotText "OpenLiteSpeed version" "$labelUnknown"
|
||||
printDanger "$error"
|
||||
fi
|
||||
|
||||
if run output error openlitespeedPodExec "$pod" php -r 'echo PHP_VERSION, "\n";'; then
|
||||
printDotText "PHP version" "$output"
|
||||
else
|
||||
printDotText "PHP version" "$labelUnknown"
|
||||
printDanger "$error"
|
||||
fi
|
||||
fi
|
||||
done < <(awk 'NF' <<< "$podList")
|
||||
fi
|
||||
|
||||
printSection "Hosts"
|
||||
local vhostList vhostDown
|
||||
if run output error openlitespeedConfigVhostList; then
|
||||
mapfile -t vhostList < <(awk 'NF' <<< "$output")
|
||||
printDotText "all" "${#vhostList[@]}"
|
||||
else
|
||||
printDotText "all" "$labelUnknown"
|
||||
printDanger "$error"
|
||||
fi
|
||||
|
||||
if run output error openlitespeedConfigVhostList "down"; then
|
||||
mapfile -t vhostDownList < <(awk 'NF' <<< "$output")
|
||||
printDotText "down" "${#vhostDownList[@]}"
|
||||
else
|
||||
printDotText "down" "$labelUnknown"
|
||||
printDanger "$error"
|
||||
fi
|
||||
|
||||
local count="$(find "$olsVhostsPath" -mindepth 1 -maxdepth 1 -type d | wc -l)"
|
||||
printDotText "directories" "$fontGray$olsVhostsPath$fontReset $count"
|
||||
}
|
||||
|
||||
# Marks a virtual host as suspended.
|
||||
# $1 (domain): site domain name.
|
||||
function cmdOpenlitespeedVhostDown() {
|
||||
printRow
|
||||
|
||||
local error
|
||||
if ! runError error openlitespeedVhostConfigDown "$@"; then
|
||||
printDotText "VHost down" "$labelFail"
|
||||
printDanger "$error"
|
||||
else
|
||||
printDotText "VHost down" "$labelPass"
|
||||
cmdOpenlitespeedRestart
|
||||
fi
|
||||
}
|
||||
|
||||
# Marks a virtual host as active.
|
||||
# $1 (domain): site domain name.
|
||||
function cmdOpenlitespeedVhostUp() {
|
||||
printRow
|
||||
|
||||
local error
|
||||
if ! runError error openlitespeedVhostConfigUp "$@"; then
|
||||
printDotText "VHost up" "$labelFail"
|
||||
printDanger "$error"
|
||||
else
|
||||
printDotText "VHost up" "$labelPass"
|
||||
cmdOpenlitespeedRestart
|
||||
fi
|
||||
}
|
||||
|
||||
# Lists virtual hosts with optional status filtering.
|
||||
# [$1] (type): all (default) | up | down.
|
||||
function cmdOpenlitespeedSiteList() {
|
||||
printRow
|
||||
|
||||
local output error type="${1:-all}"
|
||||
if ! run output error openlitespeedConfigVhostList "$type"; then
|
||||
printDanger "$error"
|
||||
else
|
||||
printText "$output"
|
||||
fi
|
||||
}
|
||||
|
||||
# Updates the Traefik middleware allowlist for OpenLiteSpeed WebAdmin.
|
||||
function cmdOpenlitespeedAdminWhiteList() {
|
||||
printRow
|
||||
|
||||
local output error
|
||||
run output error openlitespeedAdminWhiteList || { printDotText "Update" "$labelFail"; printDanger "$error"; return 1; }
|
||||
|
||||
printDotText "White list" "$output"
|
||||
printDotText "Update" "$labelDone"
|
||||
}
|
||||
|
||||
# Updates OpenLiteSpeed WebAdmin access control from current Traefik pod IPs.
|
||||
function cmdOpenlitespeedAdminAllowList() {
|
||||
printRow
|
||||
|
||||
local output error
|
||||
run output error openlitespeedAdminAllowList || { printDotText "Update" "$labelFail"; printDanger "$error"; return 1; }
|
||||
|
||||
printDotText "Allow list: ${output:-$labelNull}"
|
||||
printDotText "Update" "$labelDone"
|
||||
cmdOpenlitespeedRestart
|
||||
}
|
||||
|
||||
# Sets aliases for an OpenLiteSpeed virtual host.
|
||||
# $1 (domain): primary site domain name.
|
||||
# $@ (...): alias domain names.
|
||||
function cmdOpenlitespeedVhostAliasSet() {
|
||||
local domain
|
||||
domain=$(domainPrepare "$1")
|
||||
|
||||
printRow
|
||||
|
||||
domainCheck "$domain" || return 1
|
||||
|
||||
local vhostList aliasList output error
|
||||
if ! run vhostList error openlitespeedConfigVhostList; then
|
||||
appError "Error retrieving vhost list: $error"
|
||||
return 1
|
||||
elif ! listContains "$domain" "$vhostList"; then
|
||||
appError "Domain not exists in OpenLiteSpeed config: $domain"
|
||||
return 1
|
||||
fi
|
||||
|
||||
run output error openlitespeedVhostSet "$@" || {
|
||||
printDotText "Set" "$labelFail"
|
||||
printDanger "$error"
|
||||
return 1
|
||||
}
|
||||
|
||||
printDotText "Alias" "${output:-$labelNull}"
|
||||
printDotText "Set" "$labelDone"
|
||||
cmdOpenlitespeedRestart
|
||||
}
|
||||
|
||||
# Lists aliases for a domain or all domains.
|
||||
# [$1] (target): domain name, or "all" to list all.
|
||||
function cmdOpenlitespeedAliasList() {
|
||||
printRow
|
||||
|
||||
local output error domain target="$1"
|
||||
if [[ "$target" == all ]]; then
|
||||
if ! run output error openlitespeedConfigAliasList; then
|
||||
printDanger "$error"
|
||||
elif [[ -z "$output" ]]; then
|
||||
printText "$labelNull"
|
||||
else
|
||||
printText "$output"
|
||||
fi
|
||||
else
|
||||
domain=$(domainPrepare "$target")
|
||||
if ! run output error openlitespeedConfigVhostAliasList "$domain"; then
|
||||
printDanger "$error"
|
||||
elif [[ -z "$output" ]]; then
|
||||
printText "$labelNull"
|
||||
else
|
||||
printText "$output"
|
||||
fi
|
||||
fi
|
||||
}
|
||||
|
||||
# Tests the OpenLiteSpeed configuration inside the container.
|
||||
function cmdOpenlitespeedConfigCheck() {
|
||||
printRow
|
||||
|
||||
local output error
|
||||
run output error openlitespeedExec sh -lc "/usr/local/lsws/bin/openlitespeed -t 2>/dev/null || true"
|
||||
if grep -qi 'configuration failed!' <<< "$output"; then
|
||||
printDotText "Check config" "$labelFail"
|
||||
printDanger "$output"
|
||||
else
|
||||
printDotText "Check config" "$labelPass"
|
||||
fi
|
||||
}
|
||||
|
||||
function cmdOpenlitespeedVhostRebuild() {
|
||||
local target="$1"
|
||||
local vhostList error
|
||||
|
||||
printRow
|
||||
|
||||
if [[ -z "$target" ]]; then
|
||||
printDanger "Target not specified";
|
||||
elif ! run vhostList error openlitespeedConfigVhostList; then
|
||||
printDanger "Cannot get vhost list: $error";
|
||||
elif [[ "$target" == "all" ]]; then
|
||||
local domain
|
||||
for domain in $vhostList; do
|
||||
if ! runError error openlitespeedVhostRebuild "$domain"; then
|
||||
printDotText "$domain" "$labelFail"
|
||||
printDanger "$error"
|
||||
else
|
||||
printDotText "$domain" "$labelDone"
|
||||
fi
|
||||
done
|
||||
elif ! listContains "$target" "$vhostList"; then
|
||||
printDanger "Unknown domain: $target";
|
||||
elif ! runError error openlitespeedVhostRebuild "$target"; then
|
||||
printDotText "$target" "$labelFail"
|
||||
printDanger "$error"
|
||||
else
|
||||
printDotText "$target" "$labelDone"
|
||||
fi
|
||||
}
|
||||
Reference in New Issue
Block a user