openlitespeedLabel="[OpenLiteSpeed]" # Renders the OpenLiteSpeed Kubernetes YAML manifest via Helm. function cmdOpenlitespeedYamlRender() { local templateFile="templates/$openlitespeedKube.yaml" printSection "Render YAML file | Helm" printDotText "Template" "$appAssetsPath/k3s/$templateFile" [[ -f "$appAssetsPath/k3s/$templateFile" ]] || { printDanger "Template file not found" return 1 } local profileCpuFile="$appAssetsPath/k3s/profiles/cpu-$kubeCpuProfile.yaml" printDotText "CPU profile" "$profileCpuFile" [[ -f "$profileCpuFile" ]] || { printDanger "CPU profile file not found" return 1 } local profileMemoryFile="$appAssetsPath/k3s/profiles/memory-$kubeMemoryProfile.yaml" printDotText "Memory profile" "$profileMemoryFile" [[ -f "$profileMemoryFile" ]] || { printDanger "Memory profile file not found" return 1 } local adminWhiteList=() adminWhiteStr for i in "${!openlitespeedAdminWhiteList[@]}"; do adminWhiteList[$i]="\"${openlitespeedAdminWhiteList[$i]}\"" done adminWhiteStr=$(IFS=','; printf '%s\n' "${adminWhiteList[*]}") local varsFile varsFile=$(mktemp "/tmp/$openlitespeedKube.vars.XXXXXX.yaml") || { printDotText "render" "$labelFail" printDanger "Create temp variables file" return 1 } printDotText "Variables" "$varsFile" trap 'rm -f -- "$varsFile"' RETURN cat > "$varsFile" < "$openlitespeedYaml" || { printDotText "render" "$labelFail" printDanger "Render failed" return 1 } printDotText "render" "$labelDone" } # Initializes OpenLiteSpeed after Kubernetes deployment: patches Traefik, sets admin credentials, PHP config, rules, and restarts. function cmdOpenlitespeedInit() { printInfo "$openlitespeedLabel Initialization..." local profileFile="$appAssetsPath/openlitespeed/profiles/memory-$kubeMemoryProfile.config" local children max_memory_limit memory_limit max_execution_time post_max_size upload_max_filesize children=$(configGet "$profileFile" "children") max_memory_limit=$(configGet "$profileFile" "max_memory_limit") memory_limit=$(configGet "$profileFile" "memory_limit") max_execution_time=$(configGet "$profileFile" "max_execution_time") post_max_size=$(configGet "$profileFile" "post_max_size") upload_max_filesize=$(configGet "$profileFile" "upload_max_filesize") "$k3sCmd" kubectl -n kube-system patch svc traefik -p '{"spec": {"externalTrafficPolicy": "Local"}}' cmdOpenlitespeedWaitReady || return 1 cmdOpenlitespeedAdminPassUpdate "$openlitespeedAdminPass" || return 1 local ug output error run ug error stat -c "%u:%g" "$openlitespeedConfigFile" || printDanger "$openlitespeedLabel Stat: $error" printInfo "$openlitespeedLabel Adding PHP configs..." local phpIniFile="$openlitespeedPhpIniPath/00-ols-master.ini" fileBackup "$phpIniFile" cp -f -- "$appAssetsPath/openlitespeed/php/00-ols-master.ini" "$phpIniFile" sed -i \ -e "s|{{children}}|$children|g" \ -e "s|{{max_memory_limit}}|$max_memory_limit|g" \ -e "s|{{memory_limit}}|$memory_limit|g" \ -e "s|{{max_execution_time}}|$max_execution_time|g" \ -e "s|{{post_max_size}}|$post_max_size|g" \ -e "s|{{upload_max_filesize}}|$upload_max_filesize|g" \ -- "$phpIniFile" find "$openlitespeedPhpIniPath" -type f -exec chmod 644 {} + printInfo "$openlitespeedLabel Adding redirect rules..." mkdir -p "$openlitespeedConfigPath/rules" cp -n "$appAssetsPath"/openlitespeed/rules/* "$openlitespeedConfigPath/rules/" chown -R "$ug" "$openlitespeedConfigPath/rules" chmod 750 -R "$openlitespeedConfigPath/rules" printInfo "$openlitespeedLabel Path OLS config..." fileBackup "$openlitespeedConfigFile" openlitespeedConfigEditSet '' useIpInProxyHeader 2 || return 1 openlitespeedConfigEditSet 'fileAccessControl' checkSymbolLink 1 || return 1 openlitespeedConfigEditSet 'accessControl' allow '10.42.0.0/16T, 10.43.0.0/16T' || return 1 openlitespeedConfigEditDel 'ext[Pp]rocessor\h+lsphp' env 'PHPRC=*' || return 1 openlitespeedConfigEditSet 'ext[Pp]rocessor\h+lsphp' backlog 100 || return 1 openlitespeedConfigEditSet 'ext[Pp]rocessor\h+lsphp' procSoftLimit 700 || return 1 openlitespeedConfigEditSet 'ext[Pp]rocessor\h+lsphp' procHardLimit 800 || return 1 openlitespeedConfigEditSet 'ext[Pp]rocessor\h+lsphp' maxConns "$children" || return 1 openlitespeedConfigEditSetMasked 'ext[Pp]rocessor\h+lsphp' env 'PHP_INI_SCAN_DIR=*' 'PHP_INI_SCAN_DIR=:/etc/ols-php-ini' || return 1 openlitespeedConfigEditSetMasked 'ext[Pp]rocessor\h+lsphp' env 'PHP_LSAPI_CHILDREN=*' "PHP_LSAPI_CHILDREN=$children" || return 1 openlitespeedConfigEditSetMasked 'ext[Pp]rocessor\h+lsphp' env 'LSAPI_AVOID_FORK=*' 'LSAPI_AVOID_FORK=0' || return 1 openlitespeedConfigEditSetMasked 'ext[Pp]rocessor\h+lsphp' env 'LSAPI_MAX_IDLE=*' 'LSAPI_MAX_IDLE=120' || return 1 openlitespeedConfigEditSetMasked 'ext[Pp]rocessor\h+lsphp' env 'LSAPI_MAX_IDLE_CHILDREN=*' 'LSAPI_MAX_IDLE_CHILDREN=1' || return 1 openlitespeedConfigEditSetMasked 'ext[Pp]rocessor\h+lsphp' env 'LSAPI_PGRP_MAX_IDLE=*' 'LSAPI_PGRP_MAX_IDLE=300' || return 1 openlitespeedConfigEditSetMasked 'ext[Pp]rocessor\h+lsphp' env 'LSAPI_MAX_PROCESS_TIME=*' 'LSAPI_MAX_PROCESS_TIME=300' || return 1 openlitespeedConfigEditSetMasked 'ext[Pp]rocessor\h+lsphp' env 'LSAPI_SLOW_REQ_MSECS=*' 'LSAPI_SLOW_REQ_MSECS=5000' || return 1 printInfo "$openlitespeedLabel Path OLS Admin config..." openlitespeedAdminAllowList || return 1 cmdOpenlitespeedRestart cmdOpenlitespeedPhpRestart printSuccess "$openlitespeedLabel Initialization completed" } # Updates OpenLiteSpeed Kubernetes resources (limits, replicas, etc.) without re-initialization. function cmdOpenlitespeedUpdate() { cmdOpenlitespeedYamlRender || return 1 cmdK3sYamlApplyEx "$openlitespeedYaml" || return 1 } # Installs OpenLiteSpeed into Kubernetes and runs initialization. function cmdOpenlitespeedInstall() { cmdOpenlitespeedYamlRender || return 1 cmdK3sYamlApplyEx "$openlitespeedYaml" || return 1 cmdOpenlitespeedInit } # Uninstalls OpenLiteSpeed Kubernetes resources. function cmdOpenlitespeedUninstall() { "$k3sCmd" kubectl delete -f "$openlitespeedYaml" } # Waits until OpenLiteSpeed WebAdmin PHP is ready. function cmdOpenlitespeedWaitReady() { local tries=${k3sReadyRetries:-10} local sleepSec=${k3sReadySleep:-2} local i output error for ((i=1; i<=tries; i++)); do run output error openlitespeedExec /usr/local/lsws/admin/fcgi-bin/admin_php -v && return 0 printWarning "$openlitespeedLabel Waiting..." sleep "$sleepSec" done printDanger "$openlitespeedLabel Not ready after ${tries} tries" return 1 } # Updates OpenLiteSpeed WebAdmin credentials. # $1 (password): WebAdmin password. # [$2] (user): WebAdmin username (default: admin). function cmdOpenlitespeedAdminPassUpdate() { local password="$1" [[ -n "$password" ]] || { printDanger "$openlitespeedLabel Password not specified"; return 1; } local user="${2:-admin}" local encrypt output error run encrypt error openlitespeedExec /usr/local/lsws/admin/fcgi-bin/admin_php -q /usr/local/lsws/admin/misc/htpasswd.php "$password" || { printDanger "$openlitespeedLabel Create pass | $error" return 1 } run output error openlitespeedExec bash -c "echo '$user:$encrypt' > /usr/local/lsws/admin/conf/htpasswd" || { printDanger "$openlitespeedLabel Encrypt pass | $error" return 1 } printSuccess "$openlitespeedLabel Authorization parameters updated" } # Restarts OpenLiteSpeed on all OLS pods. function cmdOpenlitespeedRestart() { local output error podList if ! run podList error k3sPodListStatus "$openlitespeedKube"; then printDanger "Get pods: $error" elif [[ -z "$podList" ]]; then printDanger "Pods not found" else while IFS='|' read -r pod phase; do printSection "$pod" if [[ "$phase" != "Running" ]]; then printDotText "Phase" "$fontRed$phase$fontReset" else printDotText "Phase" "$fontGreen$phase$fontReset" if ! run output error openlitespeedPodExec "$pod" /usr/local/lsws/bin/lswsctrl restart; then printDotText "Restart" "$labelUnknown" printDanger "$error" elif [[ "$output" =~ "[OK]" ]]; then printDotText "Restart" "$fontGreen$output$fontReset" else printDotText "Restart" "$fontRed$output$fontReset" fi # k3sRun wait --for=condition=Ready "pod/$pod" --timeout=10s >/dev/null 2>&1 || true fi done < <(awk 'NF' <<< "$podList") fi printRow } # Restarts PHP workers on all OLS pods. function cmdOpenlitespeedPhpRestart() { local output error podList if ! run podList error k3sPodListStatus "$openlitespeedKube"; then printDanger "Get pods: $error" elif [[ -z "$podList" ]]; then printDanger "Pods not found" else while IFS='|' read -r pod phase; do printSection "$pod" if [[ "$phase" != "Running" ]]; then printDotText "Phase" "$fontRed$phase$fontReset" else printDotText "Phase" "$fontGreen$phase$fontReset" run output error openlitespeedPodExec "$pod" killall -USR1 lsphp || true printDotText "PHP" "process restart" fi done < <(awk 'NF' <<< "$podList") fi printRow } # Restarts PHP (kill) workers on all OLS pods. function cmdOpenlitespeedPhpKill() { local output error podList if ! run podList error k3sPodListStatus "$openlitespeedKube"; then printDanger "Get pods: $error" elif [[ -z "$podList" ]]; then printDanger "Pods not found" else while IFS='|' read -r pod phase; do printSection "$pod" if [[ "$phase" != "Running" ]]; then printDotText "Phase" "$fontRed$phase$fontReset" else printDotText "Phase" "$fontGreen$phase$fontReset" run output error openlitespeedPodExec "$pod" pkill -9 -f lsphp || true printDotText "PHP" "process kill" fi done < <(awk 'NF' <<< "$podList") fi printRow } # Prints OpenLiteSpeed and PHP versions for each OLS pod. function cmdOpenlitespeedInfo() { local output error podList ver pid if ! run podList error k3sPodListStatus "$openlitespeedKube"; then printDanger "Get pods: $error" elif [[ -z "$podList" ]]; then printDanger "Pods not found" else while IFS='|' read -r pod phase; do printSection "$pod" if [[ "$phase" != "Running" ]]; then printDotText "Phase" "$fontRed$phase$fontReset" else printDotText "Phase" "$fontGreen$phase$fontReset" if ! run output error openlitespeedPodExec "$pod" /usr/local/lsws/bin/lswsctrl status; then printDotText "Status" "$labelUnknown" printDanger "$error" elif [[ "$output" =~ "running" ]]; then printDotText "OpenLiteSpeed status" "$fontGreen$output$fontReset" else printDotText "OpenLiteSpeed status" "$fontRed$output$fontReset" fi if run output error openlitespeedPodExec "$pod" /usr/local/lsws/bin/lshttpd -v; then ver=$(awk 'NR==1{print $1, $2}' <<< "$output") printDotText "OpenLiteSpeed version" "$ver" else printDotText "OpenLiteSpeed version" "$labelUnknown" printDanger "$error" fi if run output error openlitespeedPodExec "$pod" php -r 'echo PHP_VERSION, "\n";'; then printDotText "PHP version" "$output" else printDotText "PHP version" "$labelUnknown" printDanger "$error" fi fi done < <(awk 'NF' <<< "$podList") fi printSection "Hosts" local vhostList vhostDown if run output error openlitespeedVhostList; then mapfile -t vhostList < <(awk 'NF' <<< "$output") printDotText "all" "${#vhostList[@]}" else printDotText "all" "$labelUnknown" printDanger "$error" fi if run output error openlitespeedVhostList "down"; then mapfile -t vhostDownList < <(awk 'NF' <<< "$output") printDotText "down" "${#vhostDownList[@]}" else printDotText "down" "$labelUnknown" printDanger "$error" fi local count="$(find "$vhostsPath" -mindepth 1 -maxdepth 1 -type d | wc -l)" printDotText "directories" "$fontGray$vhostsPath$fontReset $count" printRow } # Marks a virtual host as suspended. # $1 (domain): site domain name. function cmdOpenlitespeedVHostDown() { local error printRow if ! runError error openlitespeedVHostDown "$@"; then printDotText "VHost down" "$labelFail" printDanger "$error" printRow else printDotText "VHost down" "$labelPass" cmdOpenlitespeedRestart fi } # Marks a virtual host as active. # $1 (domain): site domain name. function cmdOpenlitespeedVHostUp() { local error printRow if ! runError error openlitespeedVHostUp "$@"; then printDotText "VHost up" "$labelFail" printDanger "$error" printRow else printDotText "VHost up" "$labelPass" cmdOpenlitespeedRestart fi } # Lists virtual hosts with optional status filtering. # [$1] (type): all (default) | up | down. function cmdOpenlitespeedSiteList() { local output error type="${1:-all}" printRow if ! run output error openlitespeedVhostList "$type"; then printDanger "$error" else printText "$output" fi printRow } # Updates the Traefik middleware allowlist for OpenLiteSpeed WebAdmin. function cmdOpenlitespeedAdminWhiteList() { local output error printRow if ! run output error openlitespeedAdminWhiteList; then printDotText "Update" "$labelFail" printDanger "$error" else printDotText "White list" "$output" printDotText "Update" "$labelDone" fi printRow } # Sets aliases for an OpenLiteSpeed virtual host. # $1 (domain): primary site domain name. # $@ (...): alias domain names. function cmdOpenlitespeedAliasSet() { local output error printRow if ! run output error openlitespeedAliasSet "$@"; then printDanger "$error" printRow elif [[ -z "$output" ]]; then printText "$labelNull" cmdOpenlitespeedRestart else printText "$output" cmdOpenlitespeedRestart fi } # Updates OpenLiteSpeed WebAdmin access control from current Traefik pod IPs. function cmdOpenlitespeedAdminAllowList() { local output error printRow if ! run output error openlitespeedAdminAllowList; then printDotText "Update" "$labelFail" printDanger "$error" printRow elif [[ -z "$output" ]]; then printDotText "Allow list" "$labelNull" printDotText "Update" "$labelDone" cmdOpenlitespeedRestart else printDotText "Allow list" "$output" printDotText "Update" "$labelDone" cmdOpenlitespeedRestart fi } # Lists aliases for a domain or all domains. # [$1] (target): domain name, or "all" to list all. function cmdOpenlitespeedAliasList() { local output error domain target="$1" printRow if [[ "$target" == all ]]; then if ! run output error openlitespeedAliasList; then printDanger "$error" elif [[ -z "$output" ]]; then printText "$labelNull" else printText "$output" fi else domain=$(domainPrepare "$target") if ! run output error openlitespeedVhostAlias "$domain"; then printDanger "$error" elif [[ -z "$output" ]]; then printText "$labelNull" else printText "$output" fi fi printRow } # Tests the OpenLiteSpeed configuration inside the container. function cmdOpenlitespeedConfigCheck() { local output error printRow run output error openlitespeedExec sh -lc "/usr/local/lsws/bin/openlitespeed -t 2>/dev/null || true" if grep -qi 'configuration failed!' <<< "$output"; then printDotText "Check config" "$labelFail" printDanger "$output" else printDotText "Check config" "$labelPass" fi printRow } function cmdOpenlitespeedVhostRebuild() { local target="$1" local vhostList error printRow if [[ -z "$target" ]]; then printDanger "Target not specified"; elif ! run vhostList error openlitespeedVhostList; then printDanger "Cannot get vhost list: $error"; elif [[ "$target" == "all" ]]; then local domain for domain in $vhostList; do if ! runError error openlitespeedVhostRebuild "$domain"; then printDotText "$domain" "$labelFail" printDanger "$error" else printDotText "$domain" "$labelDone" fi done elif ! listContains "$target" "$vhostList"; then printDanger "Unknown domain: $target"; elif ! runError error openlitespeedVhostRebuild "$target"; then printDotText "$target" "$labelFail" printDanger "$error" else printDotText "$target" "$labelDone" fi printRow }