openlitespeedLabel="[OpenLiteSpeed]" # Renders the OpenLiteSpeed Kubernetes YAML manifest via Helm. function cmdOpenlitespeedYamlRender() { printInfo "$openlitespeedLabel Render YAML | Helm" local templateFile="templates/$openlitespeedKube.yaml" [[ -f "$appAssetsPath/k3s/$templateFile" ]] || { printDanger "$openlitespeedLabel Template YAML : File not found | $appAssetsPath/k3s/$templateFile" return 1 } printInfo "$openlitespeedLabel Template YAML : $appAssetsPath/k3s/$templateFile" local profileCpuFile="$appAssetsPath/k3s/profiles/cpu-$kubeCpuProfile.yaml" [[ -f "$profileCpuFile" ]] || { printDanger "$openlitespeedLabel CPU profile : File not found | $profileCpuFile" return 1 } printInfo "$openlitespeedLabel CPU profile : $profileCpuFile" local profileMemoryFile="$appAssetsPath/k3s/profiles/memory-$kubeMemoryProfile.yaml" [[ -f "$profileMemoryFile" ]] || { printDanger "$openlitespeedLabel Memory profile : File not found | $profileMemoryFile" return 1 } printInfo "$openlitespeedLabel Memory profile : $profileMemoryFile" local adminWhiteList=() adminWhiteStr for i in "${!openlitespeedAdminWhiteList[@]}"; do adminWhiteList[$i]="\"${openlitespeedAdminWhiteList[$i]}\"" done adminWhiteStr=$(IFS=','; printf '%s\n' "${adminWhiteList[*]}") local varsFile varsFile=$(mktemp "/tmp/$openlitespeedKube.vars.XXXXXX.yaml") || return 1 printInfo "$openlitespeedLabel Variables : $varsFile" trap 'rm -f -- "$varsFile"' RETURN cat > "$varsFile" < "$openlitespeedYaml" || { printDanger "$openlitespeedLabel Render failed" return 1 } printSuccess "$openlitespeedLabel Render completed" } # Initializes OpenLiteSpeed after Kubernetes deployment: patches Traefik, sets admin credentials, PHP config, rules, and restarts. function cmdOpenlitespeedInit() { printInfo "$openlitespeedLabel Initialization..." local profileFile="$appAssetsPath/openlitespeed/profiles/memory-$kubeMemoryProfile.config" local children max_memory_limit memory_limit max_execution_time post_max_size upload_max_filesize children=$(configGet "$profileFile" "children") max_memory_limit=$(configGet "$profileFile" "max_memory_limit") memory_limit=$(configGet "$profileFile" "memory_limit") max_execution_time=$(configGet "$profileFile" "max_execution_time") post_max_size=$(configGet "$profileFile" "post_max_size") upload_max_filesize=$(configGet "$profileFile" "upload_max_filesize") "$k3sCmd" kubectl -n kube-system patch svc traefik -p '{"spec": {"externalTrafficPolicy": "Local"}}' cmdOpenlitespeedWaitReady || return 1 cmdOpenlitespeedAdminPassUpdate "$openlitespeedAdminPass" || return 1 local ug output error run ug error stat -c "%u:%g" "$openlitespeedConfigFile" || printDanger "$openlitespeedLabel Stat: $error" printInfo "$openlitespeedLabel Adding PHP configs..." local phpIniFile="$openlitespeedPhpIniPath/00-ols-master.ini" fileBackup "$phpIniFile" cp -f -- "$appAssetsPath/openlitespeed/php/00-ols-master.ini" "$phpIniFile" sed -i \ -e "s|{{children}}|$children|g" \ -e "s|{{max_memory_limit}}|$max_memory_limit|g" \ -e "s|{{memory_limit}}|$memory_limit|g" \ -e "s|{{max_execution_time}}|$max_execution_time|g" \ -e "s|{{post_max_size}}|$post_max_size|g" \ -e "s|{{upload_max_filesize}}|$upload_max_filesize|g" \ -- "$phpIniFile" find "$openlitespeedPhpIniPath" -type f -exec chmod 644 {} + printInfo "$openlitespeedLabel Adding redirect rules..." mkdir -p "$openlitespeedConfigPath/rules" cp -n "$appAssetsPath"/openlitespeed/rules/* "$openlitespeedConfigPath/rules/" chown -R "$ug" "$openlitespeedConfigPath/rules" chmod 750 -R "$openlitespeedConfigPath/rules" printInfo "$openlitespeedLabel Path OLS config..." fileBackup "$openlitespeedConfigFile" openlitespeedConfigEditSet '' useIpInProxyHeader 2 || return 1 openlitespeedConfigEditSet 'fileAccessControl' checkSymbolLink 1 || return 1 openlitespeedConfigEditSet 'accessControl' allow '10.42.0.0/16T, 10.43.0.0/16T' || return 1 openlitespeedConfigEditDel 'ext[Pp]rocessor\h+lsphp' env 'PHPRC=*' || return 1 openlitespeedConfigEditSet 'ext[Pp]rocessor\h+lsphp' backlog 100 || return 1 openlitespeedConfigEditSet 'ext[Pp]rocessor\h+lsphp' procSoftLimit 700 || return 1 openlitespeedConfigEditSet 'ext[Pp]rocessor\h+lsphp' procHardLimit 800 || return 1 openlitespeedConfigEditSet 'ext[Pp]rocessor\h+lsphp' maxConns "$children" || return 1 openlitespeedConfigEditSetMasked 'ext[Pp]rocessor\h+lsphp' env 'PHP_INI_SCAN_DIR=*' 'PHP_INI_SCAN_DIR=:/etc/ols-php-ini' || return 1 openlitespeedConfigEditSetMasked 'ext[Pp]rocessor\h+lsphp' env 'PHP_LSAPI_CHILDREN=*' "PHP_LSAPI_CHILDREN=$children" || return 1 openlitespeedConfigEditSetMasked 'ext[Pp]rocessor\h+lsphp' env 'LSAPI_AVOID_FORK=*' 'LSAPI_AVOID_FORK=0' || return 1 openlitespeedConfigEditSetMasked 'ext[Pp]rocessor\h+lsphp' env 'LSAPI_MAX_IDLE=*' 'LSAPI_MAX_IDLE=120' || return 1 openlitespeedConfigEditSetMasked 'ext[Pp]rocessor\h+lsphp' env 'LSAPI_MAX_IDLE_CHILDREN=*' 'LSAPI_MAX_IDLE_CHILDREN=1' || return 1 openlitespeedConfigEditSetMasked 'ext[Pp]rocessor\h+lsphp' env 'LSAPI_PGRP_MAX_IDLE=*' 'LSAPI_PGRP_MAX_IDLE=300' || return 1 openlitespeedConfigEditSetMasked 'ext[Pp]rocessor\h+lsphp' env 'LSAPI_MAX_PROCESS_TIME=*' 'LSAPI_MAX_PROCESS_TIME=300' || return 1 openlitespeedConfigEditSetMasked 'ext[Pp]rocessor\h+lsphp' env 'LSAPI_SLOW_REQ_MSECS=*' 'LSAPI_SLOW_REQ_MSECS=5000' || return 1 printInfo "$openlitespeedLabel Path OLS Admin config..." openlitespeedAdminAllowList || return 1 cmdOpenlitespeedRestart cmdOpenlitespeedPhpRestart printSuccess "$openlitespeedLabel Initialization completed" } # Installs OpenLiteSpeed into Kubernetes and runs initialization. function cmdOpenlitespeedInstall() { cmdOpenlitespeedYamlRender || return 1 cmdK3sYamlApplyEx "$openlitespeedYaml" || return 1 cmdOpenlitespeedInit } # Uninstalls OpenLiteSpeed Kubernetes resources. function cmdOpenlitespeedUninstall() { "$k3sCmd" kubectl delete -f "$openlitespeedYaml" } # Waits until OpenLiteSpeed WebAdmin PHP is ready. function cmdOpenlitespeedWaitReady() { local tries=${k3sReadyRetries:-10} local sleepSec=${k3sReadySleep:-2} local i output error for ((i=1; i<=tries; i++)); do run output error openlitespeedExec /usr/local/lsws/admin/fcgi-bin/admin_php -v && return 0 printWarning "$openlitespeedLabel Waiting..." sleep "$sleepSec" done printDanger "$openlitespeedLabel Not ready after ${tries} tries" return 1 } # Updates OpenLiteSpeed WebAdmin credentials. # $1 (password): WebAdmin password. # [$2] (user): WebAdmin username (default: admin). function cmdOpenlitespeedAdminPassUpdate() { local password="$1" [[ -n "$password" ]] || { printDanger "$openlitespeedLabel Password not specified"; return 1; } local user="${2:-admin}" local encrypt output error run encrypt error openlitespeedExec /usr/local/lsws/admin/fcgi-bin/admin_php -q /usr/local/lsws/admin/misc/htpasswd.php "$password" || { printDanger "$openlitespeedLabel Create pass | $error" return 1 } run output error openlitespeedExec bash -c "echo '$user:$encrypt' > /usr/local/lsws/admin/conf/htpasswd" || { printDanger "$openlitespeedLabel Encrypt pass | $error" return 1 } printSuccess "$openlitespeedLabel Authorization parameters updated" } # Restarts OpenLiteSpeed on all OLS pods. function cmdOpenlitespeedRestart() { local output error podList if ! run podList error k3sPodListStatus "$openlitespeedKube"; then printDanger "Get pods: $error" elif [[ -z "$podList" ]]; then printDanger "Pods not found" else while IFS='|' read -r pod phase; do printSection "$pod" if [[ "$phase" != "Running" ]]; then printDot 60 "Phase" "$fontRed$phase$fontReset" else printDot 60 "Phase" "$fontGreen$phase$fontReset" if ! run output error openlitespeedPodExec "$pod" /usr/local/lsws/bin/lswsctrl restart; then printDot 60 "Restart" "$labelUnknown" printDanger "$error" elif [[ "$output" =~ "[OK]" ]]; then printDot 60 "Restart" "$fontGreen$output$fontReset" else printDot 60 "Restart" "$fontRed$output$fontReset" fi # k3sRun wait --for=condition=Ready "pod/$pod" --timeout=10s >/dev/null 2>&1 || true fi done < <(awk 'NF' <<< "$podList") fi printRow } # Restarts PHP workers on all OLS pods. function cmdOpenlitespeedPhpRestart() { local output error podList if ! run podList error k3sPodListStatus "$openlitespeedKube"; then printDanger "Get pods: $error" elif [[ -z "$podList" ]]; then printDanger "Pods not found" else while IFS='|' read -r pod phase; do printSection "$pod" if [[ "$phase" != "Running" ]]; then printDot 60 "Phase" "$fontRed$phase$fontReset" else printDot 60 "Phase" "$fontGreen$phase$fontReset" # !!!!!!!!!!!!!!!!!!! # !!!!!!!!!!!!!!!!!!! # !!!!!!!!!!!!!!!!!!! # !!!!!!!!!!!!!!!!!!! # !!!!!!!!!!!!!!!!!!! # !!!!!!!!!!!!!!!!!!! run output error openlitespeedPodExec "$pod" pkill -9 -f lsphp || true # !!!!!!!!!!!!!!!!!!! # !!!!!!!!!!!!!!!!!!! # !!!!!!!!!!!!!!!!!!! # !!!!!!!!!!!!!!!!!!! # !!!!!!!!!!!!!!!!!!! # !!!!!!!!!!!!!!!!!!! # !!!!!!!!!!!!!!!!!!! # killall -USR1 lsphp printDot 60 "Restart" "process kill" fi done < <(awk 'NF' <<< "$podList") fi printRow } # Prints OpenLiteSpeed and PHP versions for each OLS pod. function cmdOpenlitespeedInfo() { local output error podList ver pid if ! run podList error k3sPodListStatus "$openlitespeedKube"; then printDanger "Get pods: $error" elif [[ -z "$podList" ]]; then printDanger "Pods not found" else while IFS='|' read -r pod phase; do printSection "$pod" if [[ "$phase" != "Running" ]]; then printDot 60 "Phase" "$fontRed$phase$fontReset" else printDot 60 "Phase" "$fontGreen$phase$fontReset" if ! run output error openlitespeedPodExec "$pod" /usr/local/lsws/bin/lswsctrl status; then printDot 60 "Status" "$labelUnknown" printDanger "$error" elif [[ "$output" =~ "running" ]]; then printDot 60 "OpenLiteSpeed status" "$fontGreen$output$fontReset" else printDot 60 "OpenLiteSpeed status" "$fontRed$output$fontReset" fi if run output error openlitespeedPodExec "$pod" /usr/local/lsws/bin/lshttpd -v; then ver=$(awk 'NR==1{print $1, $2}' <<< "$output") printDot 60 "OpenLiteSpeed version" "$ver" else printDot 60 "OpenLiteSpeed version" "$labelUnknown" printDanger "$error" fi if run output error openlitespeedPodExec "$pod" php -r 'echo PHP_VERSION, "\n";'; then printDot 60 "PHP version" "$output" else printDot 60 "PHP version" "$labelUnknown" printDanger "$error" fi fi done < <(awk 'NF' <<< "$podList") fi printRow } # Marks a virtual host as suspended. # $1 (domain): site domain name. function cmdOpenlitespeedVHostDown() { local error printRow if ! runError error openlitespeedVHostDown "$@"; then printDot 60 "VHost down" "$labelFail" printDanger "$error" printRow else printDot 60 "VHost down" "$labelPass" cmdOpenlitespeedRestart fi } # Marks a virtual host as active. # $1 (domain): site domain name. function cmdOpenlitespeedVHostUp() { local error printRow if ! runError error openlitespeedVHostUp "$@"; then printDot 60 "VHost up" "$labelFail" printDanger "$error" printRow else printDot 60 "VHost up" "$labelPass" cmdOpenlitespeedRestart fi } # Lists virtual hosts with optional status filtering. # [$1] (type): all (default) | up | down. function cmdOpenlitespeedSiteList() { local output error type="${1:-all}" printRow if ! run output error openlitespeedVhostList "$type"; then printDanger "$error" else printText "$output" fi printRow } # Updates the Traefik middleware allowlist for OpenLiteSpeed WebAdmin. function cmdOpenlitespeedAdminWhiteList() { local output error printRow if ! run output error openlitespeedAdminWhiteList; then printDot 60 "Update" "$labelFail" printDanger "$error" else printDot 60 "White list" "$output" printDot 60 "Update" "$labelDone" fi printRow } # Sets aliases for an OpenLiteSpeed virtual host. # $1 (domain): primary site domain name. # $@ (...): alias domain names. function cmdOpenlitespeedAliasSet() { local output error printRow if ! run output error openlitespeedAliasSet "$@"; then printDanger "$error" printRow elif [[ -z "$output" ]]; then printText "$labelNull" cmdOpenlitespeedRestart else printText "$output" cmdOpenlitespeedRestart fi } # Updates OpenLiteSpeed WebAdmin access control from current Traefik pod IPs. function cmdOpenlitespeedAdminAllowList() { local output error printRow if ! run output error openlitespeedAdminAllowList; then printDot 60 "Update" "$labelFail" printDanger "$error" printRow elif [[ -z "$output" ]]; then printDot 60 "Allow list" "$labelNull" printDot 60 "Update" "$labelDone" cmdOpenlitespeedRestart else printDot 60 "Allow list" "$output" printDot 60 "Update" "$labelDone" cmdOpenlitespeedRestart fi } # Lists aliases for a domain or all domains. # [$1] (target): domain name, or "all" to list all. function cmdOpenlitespeedAliasList() { local output error domain target="$1" printRow if [[ "$target" == all ]]; then if ! run output error openlitespeedAliasList; then printDanger "$error" elif [[ -z "$output" ]]; then printText "$labelNull" else printText "$output" fi else domain=$(domainPrepare "$target") if ! run output error openlitespeedVhostAlias "$domain"; then printDanger "$error" elif [[ -z "$output" ]]; then printText "$labelNull" else printText "$output" fi fi printRow } # Tests the OpenLiteSpeed configuration inside the container. function cmdOpenlitespeedConfigCheck() { local output error printRow run output error openlitespeedExec sh -lc "/usr/local/lsws/bin/openlitespeed -t 2>/dev/null || true" if grep -qi 'configuration failed!' <<< "$output"; then printDot 60 "Check config" "$labelFail" printDanger "$output" else printDot 60 "Check config" "$labelPass" fi printRow } function cmdOpenlitespeedVhostRebuild() { local domain vhostList error note domain=$(domainPrepare "$1") printRow if ! run vhostList error openlitespeedVhostList; then printDanger "Cannot get vhost list: $error" elif ! listContains "$domain" "$vhostList"; then printDot 60 "$domain" "$labelFail" printDanger "Domain is not exists in OpenLiteSpeed config" else openlitespeedVhostRebuild "$domain" printDot 60 "$domain" "$labelPass" fi printRow }