Files
SODEW/sodew-bash-main/libs/commands/openlitespeed.sh
T
2026-08-18 09:40:08 +02:00

483 lines
16 KiB
Bash

openlitespeedLabel="[OpenLiteSpeed]"
# Renders the OpenLiteSpeed Kubernetes YAML manifest via Helm.
function cmdOpenlitespeedYamlRender() {
local templateFile="templates/$olsKube.yaml"
printSection "Render YAML file | Helm"
printDotText "Template" "$appAssetsPath/k3s/$templateFile"
[[ -f "$appAssetsPath/k3s/$templateFile" ]] || {
printDanger "Template file not found"
return 1
}
local profileCpuFile="$appAssetsPath/k3s/profiles/cpu-$kubeCpuProfile.yaml"
printDotText "CPU profile" "$profileCpuFile"
[[ -f "$profileCpuFile" ]] || {
printDanger "CPU profile file not found"
return 1
}
local profileMemoryFile="$appAssetsPath/k3s/profiles/memory-$kubeMemoryProfile.yaml"
printDotText "Memory profile" "$profileMemoryFile"
[[ -f "$profileMemoryFile" ]] || {
printDanger "Memory profile file not found"
return 1
}
local adminWhiteList=() adminWhiteStr
for i in "${!olsAdminWhiteList[@]}"; do
adminWhiteList[$i]="\"${olsAdminWhiteList[$i]}\""
done
adminWhiteStr=$(IFS=','; printf '%s\n' "${adminWhiteList[*]}")
local varsFile
varsFile=$(mktemp "/tmp/$olsKube.vars.XXXXXX.yaml") || {
printDotText "render" "$labelFail"
printDanger "Create temp variables file"
return 1
}
printDotText "Variables" "$varsFile"
trap 'rm -f -- "$varsFile"' RETURN
cat > "$varsFile" <<EOF
openlitespeedHelm: true
namespace: $k3sNamespace
openlitespeed: $olsKube
olsPodVhostsPath: $olsPodVhostsPath
olsPodPrivatePath: $olsPodPrivatePath
olsPodPublicPath: $olsPodPublicPath
olsVhostsPath: $olsVhostsPath
olsPrivatePath: $olsPrivatePath
olsPublicPath: $olsPublicPath
olsConfigPath: $olsConfigPath
olsPhpIniPath: $olsPhpIniPath
olsLogsPath: $olsLogsPath
olsAdminPath: $olsAdminPath
olsAdminWhiteList: $adminWhiteStr
EOF
printDotText "Result" "$olsYaml"
mkdir -p -- "$(dirname -- "$olsYaml")" || return 1
fileBackup "$olsYaml"
helm template stack "$appAssetsPath/k3s" -f "$varsFile" -f "$profileCpuFile" -f "$profileMemoryFile" --show-only "$templateFile" > "$olsYaml" || {
printDotText "render" "$labelFail"
printDanger "Render failed"
return 1
}
printDotText "render" "$labelDone"
}
# Initializes OpenLiteSpeed after Kubernetes deployment: patches Traefik, sets admin credentials, PHP config, rules, and restarts.
function cmdOpenlitespeedInit() {
printSection "Initialization..."
local ug
ug="$(stat -c "%u:%g" "$olsConfigFile")"
# Patch svc traefik
runSilent "$k3sCmd" kubectl -n kube-system patch svc traefik -p '{"spec": {"externalTrafficPolicy": "Local"}}' || {
printDotText "Patch svc traefik" "$labelFail"
return 1
}
printDotText "Patch svc traefik" "$labelDone"
# Updating Administrator Password
runSilent cmdOpenlitespeedAdminPassUpdate "$olsAdminPass" || {
printDotText "Updating admin password" "$labelFail"
return 1
}
printDotText "Updating admin password" "$labelDone"
# Adding redirect rules
mkdir -p "$olsConfigPath/rules"
cp -n "$appAssetsPath"/openlitespeed/rules/* "$olsConfigPath/rules/"
chown -R "$ug" "$olsConfigPath/rules"
chmod 750 -R "$olsConfigPath/rules"
printDotText "Adding redirect rules" "$labelDone"
# Adding PHP configs
local profileFile="$appAssetsPath/openlitespeed/profiles/memory-$kubeMemoryProfile.config"
local children max_memory_limit memory_limit max_execution_time post_max_size upload_max_filesize
children=$(configGet "$profileFile" "children")
max_memory_limit=$(configGet "$profileFile" "max_memory_limit")
memory_limit=$(configGet "$profileFile" "memory_limit")
max_execution_time=$(configGet "$profileFile" "max_execution_time")
post_max_size=$(configGet "$profileFile" "post_max_size")
upload_max_filesize=$(configGet "$profileFile" "upload_max_filesize")
local phpIniFile="$olsPhpIniPath/00-ols-master.ini"
fileBackup "$phpIniFile"
cp -f -- "$appAssetsPath/openlitespeed/php/00-ols-master.ini" "$phpIniFile"
sed -i \
-e "s|{{children}}|$children|g" \
-e "s|{{max_memory_limit}}|$max_memory_limit|g" \
-e "s|{{memory_limit}}|$memory_limit|g" \
-e "s|{{max_execution_time}}|$max_execution_time|g" \
-e "s|{{post_max_size}}|$post_max_size|g" \
-e "s|{{upload_max_filesize}}|$upload_max_filesize|g" \
-- "$phpIniFile"
find "$olsPhpIniPath" -type f -exec chmod 644 {} +
printDotText "Adding PHP configs" "$labelDone"
# Path OLS Admin config
runSilent openlitespeedAdminAllowList || {
printDotText "Path OLS Admin config" "$labelFail"
return 1
}
printDotText "Path OLS Admin config" "$labelDone"
# Path OLS config
openlitespeedConfigRebuild || {
printDotText "Path OLS config" "$labelFail"
return 1
}
printDotText "Path OLS config" "$labelDone"
cmdOpenlitespeedRestart
cmdOpenlitespeedPhpKill all
}
# Updates OpenLiteSpeed Kubernetes resources (limits, replicas, etc.) without re-initialization.
function cmdOpenlitespeedUpdate() {
cmdOpenlitespeedYamlRender || return 1
cmdK3sYamlApplyEx "$olsYaml" || return 1
}
# Installs OpenLiteSpeed into Kubernetes and runs initialization.
function cmdOpenlitespeedInstall() {
cmdOpenlitespeedYamlRender || return 1
cmdK3sYamlApplyEx "$olsYaml" || return 1
cmdOpenlitespeedInit
}
# Uninstalls OpenLiteSpeed Kubernetes resources.
function cmdOpenlitespeedUninstall() {
"$k3sCmd" kubectl delete -f "$olsYaml"
}
# Updates OpenLiteSpeed WebAdmin credentials.
# $1 (password): WebAdmin password.
# [$2] (user): WebAdmin username (default: admin).
function cmdOpenlitespeedAdminPassUpdate() {
local password="$1"
[[ -n "$password" ]] || { printDanger "Password not specified"; return 1; }
local user="${2:-admin}"
local encrypt output error
run encrypt error openlitespeedExec /usr/local/lsws/admin/fcgi-bin/admin_php -q /usr/local/lsws/admin/misc/htpasswd.php "$password" || {
printDotText "Get encrypt" "$labelFail"
printDanger "$error"
return 1
}
printDotText "Get encrypt" "$labelDone"
run output error openlitespeedExec bash -c "echo '$user:$encrypt' > /usr/local/lsws/admin/conf/htpasswd" || {
printDotText "Save data" "$labelFail"
printDanger "$error"
return 1
}
printDotText "Save data" "$labelDone"
# if admin... save to <hostname>.openlitespeed
}
# Restarts OpenLiteSpeed on all OLS pods.
function cmdOpenlitespeedRestart() {
local podList error
run podList error k3sPodListStatus "$olsKube" || { printDanger "Get pods: $error"; return 1; }
[[ -n "$podList" ]] || { printDanger "Pods not found"; return 1; }
local pod ready phase reason output
while IFS='|' read -r pod ready phase reason; do
printSection "$pod"
if [[ "$ready" != "1" ]]; then
printDotText "Status" "$fontGray$reason $fontRed$phase$fontReset"
else
printDotText "Status" "$fontGreen$phase$fontReset"
if ! run output error openlitespeedPodExec "$pod" /usr/local/lsws/bin/lswsctrl restart; then
printDotText "Restart" "$labelUnknown"
printDanger "$error"
elif [[ "$output" =~ "[OK]" ]]; then
printDotText "Restart" "$fontGreen$output$fontReset"
else
printDotText "Restart" "$fontRed$output$fontReset"
fi
fi
done < <(awk 'NF' <<< "$podList")
}
# Restarts PHP workers on all OLS pods.
function cmdOpenlitespeedPhpKill() {
local target="$1"
[[ -n "$target" ]] || { printRow; printDanger "Target not specified"; return 1; }
local podList error
run podList error k3sPodListStatus "$olsKube" || { printDanger "Get pods: $error"; return 1; }
[[ -n "$podList" ]] || { printDanger "Pods not found"; return 1; }
local uid=""
if [[ "$target" != "all" ]]; then
local vhostList
run vhostList error openlitespeedConfigVhostList || { printRow; printDanger "Cannot get vhost list: $error"; return 1; }
listContains "$target" "$vhostList" || { printRow; printDanger "Unknown domain: $target"; return 1; }
uid=$(domainToUid "$target")
[[ -n "$uid" ]] || { printDanger "Cannot resolve UID for: $target"; return 1; }
fi
local pod ready phase reason output
while IFS='|' read -r pod ready phase reason; do
printSection "$pod"
if [[ "$ready" != "1" ]]; then
printDotText "Status" "$fontGray$reason $fontRed$phase$fontReset"
else
printDotText "Status" "$fontGreen$phase$fontReset"
if [[ -n "$uid" ]]; then
runSilent openlitespeedPodExec "$pod" pkill -u "$uid" -x lsphp
else
runSilent openlitespeedPodExec "$pod" pkill -x lsphp
fi
printDotText "kill$fontBlue lsphp$fontReset processes for $target" "$labelDone"
fi
done < <(awk 'NF' <<< "$podList")
}
# Prints OpenLiteSpeed and PHP versions for each OLS pod.
function cmdOpenlitespeedInfo() {
local output error podList ver pid
if ! run podList error k3sPodListStatus "$olsKube"; then
printDanger "Get pods: $error"
elif [[ -z "$podList" ]]; then
printDanger "Pods not found"
else
local ready reason
while IFS='|' read -r pod ready phase reason; do
printSection "$pod"
if [[ "$ready" != "1" ]]; then
printDotText "Status" "$fontGray$reason $fontRed$phase$fontReset"
else
printDotText "Status" "$fontGreen$phase$fontReset"
if ! run output error openlitespeedPodExec "$pod" /usr/local/lsws/bin/lswsctrl status; then
printDotText "OpenLiteSpeed status" "$labelUnknown"
printDanger "$error"
elif [[ "$output" =~ "running" ]]; then
printDotText "OpenLiteSpeed status" "$fontGreen$output$fontReset"
else
printDotText "OpenLiteSpeed status" "$fontRed$output$fontReset"
fi
if run output error openlitespeedPodExec "$pod" /usr/local/lsws/bin/lshttpd -v; then
ver=$(awk 'NR==1{print $1, $2}' <<< "$output")
printDotText "OpenLiteSpeed version" "$ver"
else
printDotText "OpenLiteSpeed version" "$labelUnknown"
printDanger "$error"
fi
if run output error openlitespeedPodExec "$pod" php -r 'echo PHP_VERSION, "\n";'; then
printDotText "PHP version" "$output"
else
printDotText "PHP version" "$labelUnknown"
printDanger "$error"
fi
fi
done < <(awk 'NF' <<< "$podList")
fi
printSection "Hosts"
local vhostList vhostDown
if run output error openlitespeedConfigVhostList; then
mapfile -t vhostList < <(awk 'NF' <<< "$output")
printDotText "all" "${#vhostList[@]}"
else
printDotText "all" "$labelUnknown"
printDanger "$error"
fi
if run output error openlitespeedConfigVhostList "down"; then
mapfile -t vhostDownList < <(awk 'NF' <<< "$output")
printDotText "down" "${#vhostDownList[@]}"
else
printDotText "down" "$labelUnknown"
printDanger "$error"
fi
local count="$(find "$olsVhostsPath" -mindepth 1 -maxdepth 1 -type d | wc -l)"
printDotText "directories" "$fontGray$olsVhostsPath$fontReset $count"
}
# Marks a virtual host as suspended.
# $1 (domain): site domain name.
function cmdOpenlitespeedVhostDown() {
printRow
local error
if ! runError error openlitespeedVhostConfigDown "$@"; then
printDotText "VHost down" "$labelFail"
printDanger "$error"
else
printDotText "VHost down" "$labelPass"
cmdOpenlitespeedRestart
fi
}
# Marks a virtual host as active.
# $1 (domain): site domain name.
function cmdOpenlitespeedVhostUp() {
printRow
local error
if ! runError error openlitespeedVhostConfigUp "$@"; then
printDotText "VHost up" "$labelFail"
printDanger "$error"
else
printDotText "VHost up" "$labelPass"
cmdOpenlitespeedRestart
fi
}
# Lists virtual hosts with optional status filtering.
# [$1] (type): all (default) | up | down.
function cmdOpenlitespeedSiteList() {
printRow
local output error type="${1:-all}"
if ! run output error openlitespeedConfigVhostList "$type"; then
printDanger "$error"
else
printText "$output"
fi
}
# Updates the Traefik middleware allowlist for OpenLiteSpeed WebAdmin.
function cmdOpenlitespeedAdminWhiteList() {
printRow
local output error
run output error openlitespeedAdminWhiteList || { printDotText "Update" "$labelFail"; printDanger "$error"; return 1; }
printDotText "White list" "$output"
printDotText "Update" "$labelDone"
}
# Updates OpenLiteSpeed WebAdmin access control from current Traefik pod IPs.
function cmdOpenlitespeedAdminAllowList() {
printRow
local output error
run output error openlitespeedAdminAllowList || { printDotText "Update" "$labelFail"; printDanger "$error"; return 1; }
printDotText "Allow list: ${output:-$labelNull}"
printDotText "Update" "$labelDone"
cmdOpenlitespeedRestart
}
# Sets aliases for an OpenLiteSpeed virtual host.
# $1 (domain): primary site domain name.
# $@ (...): alias domain names.
function cmdOpenlitespeedVhostAliasSet() {
local domain
domain=$(domainPrepare "$1")
printRow
domainCheck "$domain" || return 1
local vhostList aliasList output error
if ! run vhostList error openlitespeedConfigVhostList; then
appError "Error retrieving vhost list: $error"
return 1
elif ! listContains "$domain" "$vhostList"; then
appError "Domain not exists in OpenLiteSpeed config: $domain"
return 1
fi
run output error openlitespeedVhostSet "$@" || {
printDotText "Set" "$labelFail"
printDanger "$error"
return 1
}
printDotText "Alias" "${output:-$labelNull}"
printDotText "Set" "$labelDone"
cmdOpenlitespeedRestart
}
# Lists aliases for a domain or all domains.
# [$1] (target): domain name, or "all" to list all.
function cmdOpenlitespeedAliasList() {
printRow
local output error domain target="$1"
if [[ "$target" == all ]]; then
if ! run output error openlitespeedConfigAliasList; then
printDanger "$error"
elif [[ -z "$output" ]]; then
printText "$labelNull"
else
printText "$output"
fi
else
domain=$(domainPrepare "$target")
if ! run output error openlitespeedConfigVhostAliasList "$domain"; then
printDanger "$error"
elif [[ -z "$output" ]]; then
printText "$labelNull"
else
printText "$output"
fi
fi
}
# Tests the OpenLiteSpeed configuration inside the container.
function cmdOpenlitespeedConfigCheck() {
printRow
local output error
run output error openlitespeedExec sh -lc "/usr/local/lsws/bin/openlitespeed -t 2>/dev/null || true"
if grep -qi 'configuration failed!' <<< "$output"; then
printDotText "Check config" "$labelFail"
printDanger "$output"
else
printDotText "Check config" "$labelPass"
fi
}
function cmdOpenlitespeedVhostRebuild() {
local target="$1"
local vhostList error
printRow
if [[ -z "$target" ]]; then
printDanger "Target not specified";
elif ! run vhostList error openlitespeedConfigVhostList; then
printDanger "Cannot get vhost list: $error";
elif [[ "$target" == "all" ]]; then
local domain
for domain in $vhostList; do
if ! runError error openlitespeedVhostRebuild "$domain"; then
printDotText "$domain" "$labelFail"
printDanger "$error"
else
printDotText "$domain" "$labelDone"
fi
done
elif ! listContains "$target" "$vhostList"; then
printDanger "Unknown domain: $target";
elif ! runError error openlitespeedVhostRebuild "$target"; then
printDotText "$target" "$labelFail"
printDanger "$error"
else
printDotText "$target" "$labelDone"
fi
}