Files
SODEW/sodew-bash-main/libs/commands/openlitespeed.sh
T
2026-08-12 10:53:04 +02:00

507 lines
18 KiB
Bash

openlitespeedLabel="[OpenLiteSpeed]"
# Renders the OpenLiteSpeed Kubernetes YAML manifest via Helm.
function cmdOpenlitespeedYamlRender() {
local templateFile="templates/$openlitespeedKube.yaml"
printSection "Render YAML file | Helm"
printDotText "Template" "$appAssetsPath/k3s/$templateFile"
[[ -f "$appAssetsPath/k3s/$templateFile" ]] || {
printDanger "Template file not found"
return 1
}
local profileCpuFile="$appAssetsPath/k3s/profiles/cpu-$kubeCpuProfile.yaml"
printDotText "CPU profile" "$profileCpuFile"
[[ -f "$profileCpuFile" ]] || {
printDanger "CPU profile file not found"
return 1
}
local profileMemoryFile="$appAssetsPath/k3s/profiles/memory-$kubeMemoryProfile.yaml"
printDotText "Memory profile" "$profileMemoryFile"
[[ -f "$profileMemoryFile" ]] || {
printDanger "Memory profile file not found"
return 1
}
local adminWhiteList=() adminWhiteStr
for i in "${!openlitespeedAdminWhiteList[@]}"; do
adminWhiteList[$i]="\"${openlitespeedAdminWhiteList[$i]}\""
done
adminWhiteStr=$(IFS=','; printf '%s\n' "${adminWhiteList[*]}")
local varsFile
varsFile=$(mktemp "/tmp/$openlitespeedKube.vars.XXXXXX.yaml") || {
printDotText "render" "$labelFail"
printDanger "Create temp variables file"
return 1
}
printDotText "Variables" "$varsFile"
trap 'rm -f -- "$varsFile"' RETURN
cat > "$varsFile" <<EOF
openlitespeedHelm: true
namespace: $k3sNamespace
openlitespeed: $openlitespeedKube
openlitespeedConfigPath: $openlitespeedConfigPath
openlitespeedPhpIniPath: $openlitespeedPhpIniPath
openlitespeedLogsPath: $openlitespeedLogsPath
openlitespeedVhostDataPath: $openlitespeedVhostDataPath
openlitespeedVhostSharedPath: $openlitespeedVhostSharedPath
openlitespeedAdminPath: $openlitespeedAdminPath
openlitespeedAdminWhiteList: $adminWhiteStr
vhostsPath: $vhostsPath
EOF
printDotText "Result" "$openlitespeedYaml"
mkdir -p -- "$(dirname -- "$openlitespeedYaml")" || return 1
fileBackup "$openlitespeedYaml"
helm template stack "$appAssetsPath/k3s" -f "$varsFile" -f "$profileCpuFile" -f "$profileMemoryFile" --show-only "$templateFile" > "$openlitespeedYaml" || {
printDotText "render" "$labelFail"
printDanger "Render failed"
return 1
}
printDotText "render" "$labelDone"
}
# Initializes OpenLiteSpeed after Kubernetes deployment: patches Traefik, sets admin credentials, PHP config, rules, and restarts.
function cmdOpenlitespeedInit() {
printInfo "$openlitespeedLabel Initialization..."
local profileFile="$appAssetsPath/openlitespeed/profiles/memory-$kubeMemoryProfile.config"
local children max_memory_limit memory_limit max_execution_time post_max_size upload_max_filesize
children=$(configGet "$profileFile" "children")
max_memory_limit=$(configGet "$profileFile" "max_memory_limit")
memory_limit=$(configGet "$profileFile" "memory_limit")
max_execution_time=$(configGet "$profileFile" "max_execution_time")
post_max_size=$(configGet "$profileFile" "post_max_size")
upload_max_filesize=$(configGet "$profileFile" "upload_max_filesize")
"$k3sCmd" kubectl -n kube-system patch svc traefik -p '{"spec": {"externalTrafficPolicy": "Local"}}'
cmdOpenlitespeedWaitReady || return 1
cmdOpenlitespeedAdminPassUpdate "$openlitespeedAdminPass" || return 1
local ug output error
run ug error stat -c "%u:%g" "$openlitespeedConfigFile" || printDanger "$openlitespeedLabel Stat: $error"
printInfo "$openlitespeedLabel Adding PHP configs..."
local phpIniFile="$openlitespeedPhpIniPath/00-ols-master.ini"
fileBackup "$phpIniFile"
cp -f -- "$appAssetsPath/openlitespeed/php/00-ols-master.ini" "$phpIniFile"
sed -i \
-e "s|{{children}}|$children|g" \
-e "s|{{max_memory_limit}}|$max_memory_limit|g" \
-e "s|{{memory_limit}}|$memory_limit|g" \
-e "s|{{max_execution_time}}|$max_execution_time|g" \
-e "s|{{post_max_size}}|$post_max_size|g" \
-e "s|{{upload_max_filesize}}|$upload_max_filesize|g" \
-- "$phpIniFile"
find "$openlitespeedPhpIniPath" -type f -exec chmod 644 {} +
printInfo "$openlitespeedLabel Adding redirect rules..."
mkdir -p "$openlitespeedConfigPath/rules"
cp -n "$appAssetsPath"/openlitespeed/rules/* "$openlitespeedConfigPath/rules/"
chown -R "$ug" "$openlitespeedConfigPath/rules"
chmod 750 -R "$openlitespeedConfigPath/rules"
printInfo "$openlitespeedLabel Path OLS config..."
fileBackup "$openlitespeedConfigFile"
openlitespeedConfigEditSet '' useIpInProxyHeader 2 || return 1
openlitespeedConfigEditSet 'fileAccessControl' checkSymbolLink 1 || return 1
openlitespeedConfigEditSet 'accessControl' allow '10.42.0.0/16T, 10.43.0.0/16T' || return 1
openlitespeedConfigEditDel 'ext[Pp]rocessor\h+lsphp' env 'PHPRC=*' || return 1
openlitespeedConfigEditSet 'ext[Pp]rocessor\h+lsphp' backlog 100 || return 1
openlitespeedConfigEditSet 'ext[Pp]rocessor\h+lsphp' procSoftLimit 700 || return 1
openlitespeedConfigEditSet 'ext[Pp]rocessor\h+lsphp' procHardLimit 800 || return 1
openlitespeedConfigEditSet 'ext[Pp]rocessor\h+lsphp' maxConns "$children" || return 1
openlitespeedConfigEditSetMasked 'ext[Pp]rocessor\h+lsphp' env 'PHP_INI_SCAN_DIR=*' 'PHP_INI_SCAN_DIR=:/etc/ols-php-ini' || return 1
openlitespeedConfigEditSetMasked 'ext[Pp]rocessor\h+lsphp' env 'PHP_LSAPI_CHILDREN=*' "PHP_LSAPI_CHILDREN=$children" || return 1
openlitespeedConfigEditSetMasked 'ext[Pp]rocessor\h+lsphp' env 'LSAPI_AVOID_FORK=*' 'LSAPI_AVOID_FORK=0' || return 1
openlitespeedConfigEditSetMasked 'ext[Pp]rocessor\h+lsphp' env 'LSAPI_MAX_IDLE=*' 'LSAPI_MAX_IDLE=120' || return 1
openlitespeedConfigEditSetMasked 'ext[Pp]rocessor\h+lsphp' env 'LSAPI_MAX_IDLE_CHILDREN=*' 'LSAPI_MAX_IDLE_CHILDREN=1' || return 1
openlitespeedConfigEditSetMasked 'ext[Pp]rocessor\h+lsphp' env 'LSAPI_PGRP_MAX_IDLE=*' 'LSAPI_PGRP_MAX_IDLE=300' || return 1
openlitespeedConfigEditSetMasked 'ext[Pp]rocessor\h+lsphp' env 'LSAPI_MAX_PROCESS_TIME=*' 'LSAPI_MAX_PROCESS_TIME=300' || return 1
openlitespeedConfigEditSetMasked 'ext[Pp]rocessor\h+lsphp' env 'LSAPI_SLOW_REQ_MSECS=*' 'LSAPI_SLOW_REQ_MSECS=5000' || return 1
printInfo "$openlitespeedLabel Path OLS Admin config..."
openlitespeedAdminAllowList || return 1
cmdOpenlitespeedRestart
cmdOpenlitespeedPhpRestart
printSuccess "$openlitespeedLabel Initialization completed"
}
# Updates OpenLiteSpeed Kubernetes resources (limits, replicas, etc.) without re-initialization.
function cmdOpenlitespeedUpdate() {
cmdOpenlitespeedYamlRender || return 1
cmdK3sYamlApplyEx "$openlitespeedYaml" || return 1
}
# Installs OpenLiteSpeed into Kubernetes and runs initialization.
function cmdOpenlitespeedInstall() {
cmdOpenlitespeedYamlRender || return 1
cmdK3sYamlApplyEx "$openlitespeedYaml" || return 1
cmdOpenlitespeedInit
}
# Uninstalls OpenLiteSpeed Kubernetes resources.
function cmdOpenlitespeedUninstall() {
"$k3sCmd" kubectl delete -f "$openlitespeedYaml"
}
# Waits until OpenLiteSpeed WebAdmin PHP is ready.
function cmdOpenlitespeedWaitReady() {
local tries=${k3sReadyRetries:-10}
local sleepSec=${k3sReadySleep:-2}
local i output error
for ((i=1; i<=tries; i++)); do
run output error openlitespeedExec /usr/local/lsws/admin/fcgi-bin/admin_php -v && return 0
printWarning "$openlitespeedLabel Waiting..."
sleep "$sleepSec"
done
printDanger "$openlitespeedLabel Not ready after ${tries} tries"
return 1
}
# Updates OpenLiteSpeed WebAdmin credentials.
# $1 (password): WebAdmin password.
# [$2] (user): WebAdmin username (default: admin).
function cmdOpenlitespeedAdminPassUpdate() {
local password="$1"
[[ -n "$password" ]] || { printDanger "$openlitespeedLabel Password not specified"; return 1; }
local user="${2:-admin}"
local encrypt output error
run encrypt error openlitespeedExec /usr/local/lsws/admin/fcgi-bin/admin_php -q /usr/local/lsws/admin/misc/htpasswd.php "$password" || {
printDanger "$openlitespeedLabel Create pass | $error"
return 1
}
run output error openlitespeedExec bash -c "echo '$user:$encrypt' > /usr/local/lsws/admin/conf/htpasswd" || {
printDanger "$openlitespeedLabel Encrypt pass | $error"
return 1
}
printSuccess "$openlitespeedLabel Authorization parameters updated"
}
# Restarts OpenLiteSpeed on all OLS pods.
function cmdOpenlitespeedRestart() {
local output error podList
if ! run podList error k3sPodListStatus "$openlitespeedKube"; then
printDanger "Get pods: $error"
elif [[ -z "$podList" ]]; then
printDanger "Pods not found"
else
while IFS='|' read -r pod phase; do
printSection "$pod"
if [[ "$phase" != "Running" ]]; then
printDotText "Phase" "$fontRed$phase$fontReset"
else
printDotText "Phase" "$fontGreen$phase$fontReset"
if ! run output error openlitespeedPodExec "$pod" /usr/local/lsws/bin/lswsctrl restart; then
printDotText "Restart" "$labelUnknown"
printDanger "$error"
elif [[ "$output" =~ "[OK]" ]]; then
printDotText "Restart" "$fontGreen$output$fontReset"
else
printDotText "Restart" "$fontRed$output$fontReset"
fi
# k3sRun wait --for=condition=Ready "pod/$pod" --timeout=10s >/dev/null 2>&1 || true
fi
done < <(awk 'NF' <<< "$podList")
fi
}
# Restarts PHP workers on all OLS pods.
function cmdOpenlitespeedPhpRestart() {
local output error podList
if ! run podList error k3sPodListStatus "$openlitespeedKube"; then
printDanger "Get pods: $error"
elif [[ -z "$podList" ]]; then
printDanger "Pods not found"
else
while IFS='|' read -r pod phase; do
printSection "$pod"
if [[ "$phase" != "Running" ]]; then
printDotText "Phase" "$fontRed$phase$fontReset"
else
printDotText "Phase" "$fontGreen$phase$fontReset"
run output error openlitespeedPodExec "$pod" killall -USR1 lsphp || true
printDotText "PHP" "process restart"
fi
done < <(awk 'NF' <<< "$podList")
fi
}
# Restarts PHP (kill) workers on all OLS pods.
function cmdOpenlitespeedPhpKill() {
local output error podList
if ! run podList error k3sPodListStatus "$openlitespeedKube"; then
printDanger "Get pods: $error"
elif [[ -z "$podList" ]]; then
printDanger "Pods not found"
else
while IFS='|' read -r pod phase; do
printSection "$pod"
if [[ "$phase" != "Running" ]]; then
printDotText "Phase" "$fontRed$phase$fontReset"
else
printDotText "Phase" "$fontGreen$phase$fontReset"
run output error openlitespeedPodExec "$pod" pkill -9 -f lsphp || true
printDotText "PHP" "process kill"
fi
done < <(awk 'NF' <<< "$podList")
fi
}
# Prints OpenLiteSpeed and PHP versions for each OLS pod.
function cmdOpenlitespeedInfo() {
local output error podList ver pid
if ! run podList error k3sPodListStatus "$openlitespeedKube"; then
printDanger "Get pods: $error"
elif [[ -z "$podList" ]]; then
printDanger "Pods not found"
else
while IFS='|' read -r pod phase; do
printSection "$pod"
if [[ "$phase" != "Running" ]]; then
printDotText "Phase" "$fontRed$phase$fontReset"
else
printDotText "Phase" "$fontGreen$phase$fontReset"
if ! run output error openlitespeedPodExec "$pod" /usr/local/lsws/bin/lswsctrl status; then
printDotText "Status" "$labelUnknown"
printDanger "$error"
elif [[ "$output" =~ "running" ]]; then
printDotText "OpenLiteSpeed status" "$fontGreen$output$fontReset"
else
printDotText "OpenLiteSpeed status" "$fontRed$output$fontReset"
fi
if run output error openlitespeedPodExec "$pod" /usr/local/lsws/bin/lshttpd -v; then
ver=$(awk 'NR==1{print $1, $2}' <<< "$output")
printDotText "OpenLiteSpeed version" "$ver"
else
printDotText "OpenLiteSpeed version" "$labelUnknown"
printDanger "$error"
fi
if run output error openlitespeedPodExec "$pod" php -r 'echo PHP_VERSION, "\n";'; then
printDotText "PHP version" "$output"
else
printDotText "PHP version" "$labelUnknown"
printDanger "$error"
fi
fi
done < <(awk 'NF' <<< "$podList")
fi
printSection "Hosts"
local vhostList vhostDown
if run output error openlitespeedVhostList; then
mapfile -t vhostList < <(awk 'NF' <<< "$output")
printDotText "all" "${#vhostList[@]}"
else
printDotText "all" "$labelUnknown"
printDanger "$error"
fi
if run output error openlitespeedVhostList "down"; then
mapfile -t vhostDownList < <(awk 'NF' <<< "$output")
printDotText "down" "${#vhostDownList[@]}"
else
printDotText "down" "$labelUnknown"
printDanger "$error"
fi
local count="$(find "$vhostsPath" -mindepth 1 -maxdepth 1 -type d | wc -l)"
printDotText "directories" "$fontGray$vhostsPath$fontReset $count"
}
# Marks a virtual host as suspended.
# $1 (domain): site domain name.
function cmdOpenlitespeedVHostDown() {
local error
printRow
if ! runError error openlitespeedVHostDown "$@"; then
printDotText "VHost down" "$labelFail"
printDanger "$error"
else
printDotText "VHost down" "$labelPass"
cmdOpenlitespeedRestart
fi
}
# Marks a virtual host as active.
# $1 (domain): site domain name.
function cmdOpenlitespeedVHostUp() {
local error
printRow
if ! runError error openlitespeedVHostUp "$@"; then
printDotText "VHost up" "$labelFail"
printDanger "$error"
else
printDotText "VHost up" "$labelPass"
cmdOpenlitespeedRestart
fi
}
# Lists virtual hosts with optional status filtering.
# [$1] (type): all (default) | up | down.
function cmdOpenlitespeedSiteList() {
local output error type="${1:-all}"
printRow
if ! run output error openlitespeedVhostList "$type"; then
printDanger "$error"
else
printText "$output"
fi
}
# Updates the Traefik middleware allowlist for OpenLiteSpeed WebAdmin.
function cmdOpenlitespeedAdminWhiteList() {
local output error
printRow
if ! run output error openlitespeedAdminWhiteList; then
printDotText "Update" "$labelFail"
printDanger "$error"
else
printDotText "White list" "$output"
printDotText "Update" "$labelDone"
fi
}
# Sets aliases for an OpenLiteSpeed virtual host.
# $1 (domain): primary site domain name.
# $@ (...): alias domain names.
function cmdOpenlitespeedAliasSet() {
local output error
printRow
if ! run output error openlitespeedAliasSet "$@"; then
printDanger "$error"
elif [[ -z "$output" ]]; then
printText "$labelNull"
cmdOpenlitespeedRestart
else
printText "$output"
cmdOpenlitespeedRestart
fi
}
# Updates OpenLiteSpeed WebAdmin access control from current Traefik pod IPs.
function cmdOpenlitespeedAdminAllowList() {
local output error
printRow
if ! run output error openlitespeedAdminAllowList; then
printDotText "Update" "$labelFail"
printDanger "$error"
elif [[ -z "$output" ]]; then
printDotText "Allow list" "$labelNull"
printDotText "Update" "$labelDone"
cmdOpenlitespeedRestart
else
printDotText "Allow list" "$output"
printDotText "Update" "$labelDone"
cmdOpenlitespeedRestart
fi
}
# Lists aliases for a domain or all domains.
# [$1] (target): domain name, or "all" to list all.
function cmdOpenlitespeedAliasList() {
local output error domain target="$1"
printRow
if [[ "$target" == all ]]; then
if ! run output error openlitespeedAliasList; then
printDanger "$error"
elif [[ -z "$output" ]]; then
printText "$labelNull"
else
printText "$output"
fi
else
domain=$(domainPrepare "$target")
if ! run output error openlitespeedVhostAlias "$domain"; then
printDanger "$error"
elif [[ -z "$output" ]]; then
printText "$labelNull"
else
printText "$output"
fi
fi
}
# Tests the OpenLiteSpeed configuration inside the container.
function cmdOpenlitespeedConfigCheck() {
local output error
printRow
run output error openlitespeedExec sh -lc "/usr/local/lsws/bin/openlitespeed -t 2>/dev/null || true"
if grep -qi 'configuration failed!' <<< "$output"; then
printDotText "Check config" "$labelFail"
printDanger "$output"
else
printDotText "Check config" "$labelPass"
fi
}
function cmdOpenlitespeedVhostRebuild() {
local target="$1"
local vhostList error
printRow
if [[ -z "$target" ]]; then
printDanger "Target not specified";
elif ! run vhostList error openlitespeedVhostList; then
printDanger "Cannot get vhost list: $error";
elif [[ "$target" == "all" ]]; then
local domain
for domain in $vhostList; do
if ! runError error openlitespeedVhostRebuild "$domain"; then
printDotText "$domain" "$labelFail"
printDanger "$error"
else
printDotText "$domain" "$labelDone"
fi
done
elif ! listContains "$target" "$vhostList"; then
printDanger "Unknown domain: $target";
elif ! runError error openlitespeedVhostRebuild "$target"; then
printDotText "$target" "$labelFail"
printDanger "$error"
else
printDotText "$target" "$labelDone"
fi
}