483 lines
16 KiB
Bash
483 lines
16 KiB
Bash
openlitespeedLabel="[OpenLiteSpeed]"
|
|
|
|
# Renders the OpenLiteSpeed Kubernetes YAML manifest via Helm.
|
|
function cmdOpenlitespeedYamlRender() {
|
|
local templateFile="templates/$olsKube.yaml"
|
|
|
|
printSection "Render YAML file | Helm"
|
|
printDotText "Template" "$appAssetsPath/k3s/$templateFile"
|
|
[[ -f "$appAssetsPath/k3s/$templateFile" ]] || {
|
|
printDanger "Template file not found"
|
|
return 1
|
|
}
|
|
|
|
local profileCpuFile="$appAssetsPath/k3s/profiles/cpu-$kubeCpuProfile.yaml"
|
|
printDotText "CPU profile" "$profileCpuFile"
|
|
[[ -f "$profileCpuFile" ]] || {
|
|
printDanger "CPU profile file not found"
|
|
return 1
|
|
}
|
|
|
|
local profileMemoryFile="$appAssetsPath/k3s/profiles/memory-$kubeMemoryProfile.yaml"
|
|
printDotText "Memory profile" "$profileMemoryFile"
|
|
[[ -f "$profileMemoryFile" ]] || {
|
|
printDanger "Memory profile file not found"
|
|
return 1
|
|
}
|
|
|
|
local adminWhiteList=() adminWhiteStr
|
|
for i in "${!olsAdminWhiteList[@]}"; do
|
|
adminWhiteList[$i]="\"${olsAdminWhiteList[$i]}\""
|
|
done
|
|
adminWhiteStr=$(IFS=','; printf '%s\n' "${adminWhiteList[*]}")
|
|
|
|
local varsFile
|
|
varsFile=$(mktemp "/tmp/$olsKube.vars.XXXXXX.yaml") || {
|
|
printDotText "render" "$labelFail"
|
|
printDanger "Create temp variables file"
|
|
return 1
|
|
}
|
|
printDotText "Variables" "$varsFile"
|
|
trap 'rm -f -- "$varsFile"' RETURN
|
|
cat > "$varsFile" <<EOF
|
|
openlitespeedHelm: true
|
|
namespace: $k3sNamespace
|
|
openlitespeed: $olsKube
|
|
olsPodVhostsPath: $olsPodVhostsPath
|
|
olsPodPrivatePath: $olsPodPrivatePath
|
|
olsPodPublicPath: $olsPodPublicPath
|
|
olsVhostsPath: $olsVhostsPath
|
|
olsPrivatePath: $olsPrivatePath
|
|
olsPublicPath: $olsPublicPath
|
|
olsConfigPath: $olsConfigPath
|
|
olsPhpIniPath: $olsPhpIniPath
|
|
olsLogsPath: $olsLogsPath
|
|
olsAdminPath: $olsAdminPath
|
|
olsAdminWhiteList: $adminWhiteStr
|
|
EOF
|
|
|
|
printDotText "Result" "$olsYaml"
|
|
mkdir -p -- "$(dirname -- "$olsYaml")" || return 1
|
|
fileBackup "$olsYaml"
|
|
helm template stack "$appAssetsPath/k3s" -f "$varsFile" -f "$profileCpuFile" -f "$profileMemoryFile" --show-only "$templateFile" > "$olsYaml" || {
|
|
printDotText "render" "$labelFail"
|
|
printDanger "Render failed"
|
|
return 1
|
|
}
|
|
|
|
printDotText "render" "$labelDone"
|
|
}
|
|
|
|
# Initializes OpenLiteSpeed after Kubernetes deployment: patches Traefik, sets admin credentials, PHP config, rules, and restarts.
|
|
function cmdOpenlitespeedInit() {
|
|
printSection "Initialization..."
|
|
|
|
local ug
|
|
ug="$(stat -c "%u:%g" "$olsConfigFile")"
|
|
|
|
# Patch svc traefik
|
|
runSilent "$k3sCmd" kubectl -n kube-system patch svc traefik -p '{"spec": {"externalTrafficPolicy": "Local"}}' || {
|
|
printDotText "Patch svc traefik" "$labelFail"
|
|
return 1
|
|
}
|
|
printDotText "Patch svc traefik" "$labelDone"
|
|
|
|
# Updating Administrator Password
|
|
runSilent cmdOpenlitespeedAdminPassUpdate "$olsAdminPass" || {
|
|
printDotText "Updating admin password" "$labelFail"
|
|
return 1
|
|
}
|
|
printDotText "Updating admin password" "$labelDone"
|
|
|
|
# Adding redirect rules
|
|
mkdir -p "$olsConfigPath/rules"
|
|
cp -n "$appAssetsPath"/openlitespeed/rules/* "$olsConfigPath/rules/"
|
|
chown -R "$ug" "$olsConfigPath/rules"
|
|
chmod 750 -R "$olsConfigPath/rules"
|
|
printDotText "Adding redirect rules" "$labelDone"
|
|
|
|
# Adding PHP configs
|
|
local profileFile="$appAssetsPath/openlitespeed/profiles/memory-$kubeMemoryProfile.config"
|
|
local children max_memory_limit memory_limit max_execution_time post_max_size upload_max_filesize
|
|
children=$(configGet "$profileFile" "children")
|
|
max_memory_limit=$(configGet "$profileFile" "max_memory_limit")
|
|
memory_limit=$(configGet "$profileFile" "memory_limit")
|
|
max_execution_time=$(configGet "$profileFile" "max_execution_time")
|
|
post_max_size=$(configGet "$profileFile" "post_max_size")
|
|
upload_max_filesize=$(configGet "$profileFile" "upload_max_filesize")
|
|
|
|
local phpIniFile="$olsPhpIniPath/00-ols-master.ini"
|
|
fileBackup "$phpIniFile"
|
|
cp -f -- "$appAssetsPath/openlitespeed/php/00-ols-master.ini" "$phpIniFile"
|
|
sed -i \
|
|
-e "s|{{children}}|$children|g" \
|
|
-e "s|{{max_memory_limit}}|$max_memory_limit|g" \
|
|
-e "s|{{memory_limit}}|$memory_limit|g" \
|
|
-e "s|{{max_execution_time}}|$max_execution_time|g" \
|
|
-e "s|{{post_max_size}}|$post_max_size|g" \
|
|
-e "s|{{upload_max_filesize}}|$upload_max_filesize|g" \
|
|
-- "$phpIniFile"
|
|
find "$olsPhpIniPath" -type f -exec chmod 644 {} +
|
|
printDotText "Adding PHP configs" "$labelDone"
|
|
|
|
# Path OLS Admin config
|
|
runSilent openlitespeedAdminAllowList || {
|
|
printDotText "Path OLS Admin config" "$labelFail"
|
|
return 1
|
|
}
|
|
printDotText "Path OLS Admin config" "$labelDone"
|
|
|
|
# Path OLS config
|
|
openlitespeedConfigRebuild || {
|
|
printDotText "Path OLS config" "$labelFail"
|
|
return 1
|
|
}
|
|
printDotText "Path OLS config" "$labelDone"
|
|
|
|
cmdOpenlitespeedRestart
|
|
cmdOpenlitespeedPhpKill all
|
|
}
|
|
|
|
# Updates OpenLiteSpeed Kubernetes resources (limits, replicas, etc.) without re-initialization.
|
|
function cmdOpenlitespeedUpdate() {
|
|
cmdOpenlitespeedYamlRender || return 1
|
|
cmdK3sYamlApplyEx "$olsYaml" || return 1
|
|
}
|
|
|
|
# Installs OpenLiteSpeed into Kubernetes and runs initialization.
|
|
function cmdOpenlitespeedInstall() {
|
|
cmdOpenlitespeedYamlRender || return 1
|
|
cmdK3sYamlApplyEx "$olsYaml" || return 1
|
|
cmdOpenlitespeedInit
|
|
}
|
|
|
|
# Uninstalls OpenLiteSpeed Kubernetes resources.
|
|
function cmdOpenlitespeedUninstall() {
|
|
"$k3sCmd" kubectl delete -f "$olsYaml"
|
|
}
|
|
|
|
# Updates OpenLiteSpeed WebAdmin credentials.
|
|
# $1 (password): WebAdmin password.
|
|
# [$2] (user): WebAdmin username (default: admin).
|
|
function cmdOpenlitespeedAdminPassUpdate() {
|
|
local password="$1"
|
|
[[ -n "$password" ]] || { printDanger "Password not specified"; return 1; }
|
|
|
|
local user="${2:-admin}"
|
|
local encrypt output error
|
|
|
|
run encrypt error openlitespeedExec /usr/local/lsws/admin/fcgi-bin/admin_php -q /usr/local/lsws/admin/misc/htpasswd.php "$password" || {
|
|
printDotText "Get encrypt" "$labelFail"
|
|
printDanger "$error"
|
|
return 1
|
|
}
|
|
printDotText "Get encrypt" "$labelDone"
|
|
|
|
run output error openlitespeedExec bash -c "echo '$user:$encrypt' > /usr/local/lsws/admin/conf/htpasswd" || {
|
|
printDotText "Save data" "$labelFail"
|
|
printDanger "$error"
|
|
return 1
|
|
}
|
|
printDotText "Save data" "$labelDone"
|
|
|
|
# if admin... save to <hostname>.openlitespeed
|
|
}
|
|
|
|
# Restarts OpenLiteSpeed on all OLS pods.
|
|
function cmdOpenlitespeedRestart() {
|
|
local podList error
|
|
run podList error k3sPodListStatus "$olsKube" || { printDanger "Get pods: $error"; return 1; }
|
|
[[ -n "$podList" ]] || { printDanger "Pods not found"; return 1; }
|
|
|
|
local pod ready phase reason output
|
|
while IFS='|' read -r pod ready phase reason; do
|
|
printSection "$pod"
|
|
|
|
if [[ "$ready" != "1" ]]; then
|
|
printDotText "Status" "$fontGray$reason $fontRed$phase$fontReset"
|
|
else
|
|
printDotText "Status" "$fontGreen$phase$fontReset"
|
|
|
|
if ! run output error openlitespeedPodExec "$pod" /usr/local/lsws/bin/lswsctrl restart; then
|
|
printDotText "Restart" "$labelUnknown"
|
|
printDanger "$error"
|
|
elif [[ "$output" =~ "[OK]" ]]; then
|
|
printDotText "Restart" "$fontGreen$output$fontReset"
|
|
else
|
|
printDotText "Restart" "$fontRed$output$fontReset"
|
|
fi
|
|
fi
|
|
done < <(awk 'NF' <<< "$podList")
|
|
}
|
|
|
|
# Restarts PHP workers on all OLS pods.
|
|
function cmdOpenlitespeedPhpKill() {
|
|
local target="$1"
|
|
[[ -n "$target" ]] || { printRow; printDanger "Target not specified"; return 1; }
|
|
|
|
local podList error
|
|
run podList error k3sPodListStatus "$olsKube" || { printDanger "Get pods: $error"; return 1; }
|
|
[[ -n "$podList" ]] || { printDanger "Pods not found"; return 1; }
|
|
|
|
local uid=""
|
|
if [[ "$target" != "all" ]]; then
|
|
local vhostList
|
|
run vhostList error openlitespeedConfigVhostList || { printRow; printDanger "Cannot get vhost list: $error"; return 1; }
|
|
listContains "$target" "$vhostList" || { printRow; printDanger "Unknown domain: $target"; return 1; }
|
|
uid=$(domainToUid "$target")
|
|
[[ -n "$uid" ]] || { printDanger "Cannot resolve UID for: $target"; return 1; }
|
|
fi
|
|
|
|
local pod ready phase reason output
|
|
while IFS='|' read -r pod ready phase reason; do
|
|
printSection "$pod"
|
|
|
|
if [[ "$ready" != "1" ]]; then
|
|
printDotText "Status" "$fontGray$reason $fontRed$phase$fontReset"
|
|
else
|
|
printDotText "Status" "$fontGreen$phase$fontReset"
|
|
|
|
if [[ -n "$uid" ]]; then
|
|
runSilent openlitespeedPodExec "$pod" pkill -u "$uid" -x lsphp
|
|
else
|
|
runSilent openlitespeedPodExec "$pod" pkill -x lsphp
|
|
fi
|
|
printDotText "kill$fontBlue lsphp$fontReset processes for $target" "$labelDone"
|
|
fi
|
|
done < <(awk 'NF' <<< "$podList")
|
|
}
|
|
|
|
# Prints OpenLiteSpeed and PHP versions for each OLS pod.
|
|
function cmdOpenlitespeedInfo() {
|
|
local output error podList ver pid
|
|
|
|
if ! run podList error k3sPodListStatus "$olsKube"; then
|
|
printDanger "Get pods: $error"
|
|
elif [[ -z "$podList" ]]; then
|
|
printDanger "Pods not found"
|
|
else
|
|
local ready reason
|
|
while IFS='|' read -r pod ready phase reason; do
|
|
printSection "$pod"
|
|
|
|
if [[ "$ready" != "1" ]]; then
|
|
printDotText "Status" "$fontGray$reason $fontRed$phase$fontReset"
|
|
else
|
|
printDotText "Status" "$fontGreen$phase$fontReset"
|
|
|
|
if ! run output error openlitespeedPodExec "$pod" /usr/local/lsws/bin/lswsctrl status; then
|
|
printDotText "OpenLiteSpeed status" "$labelUnknown"
|
|
printDanger "$error"
|
|
elif [[ "$output" =~ "running" ]]; then
|
|
printDotText "OpenLiteSpeed status" "$fontGreen$output$fontReset"
|
|
else
|
|
printDotText "OpenLiteSpeed status" "$fontRed$output$fontReset"
|
|
fi
|
|
|
|
if run output error openlitespeedPodExec "$pod" /usr/local/lsws/bin/lshttpd -v; then
|
|
ver=$(awk 'NR==1{print $1, $2}' <<< "$output")
|
|
printDotText "OpenLiteSpeed version" "$ver"
|
|
else
|
|
printDotText "OpenLiteSpeed version" "$labelUnknown"
|
|
printDanger "$error"
|
|
fi
|
|
|
|
if run output error openlitespeedPodExec "$pod" php -r 'echo PHP_VERSION, "\n";'; then
|
|
printDotText "PHP version" "$output"
|
|
else
|
|
printDotText "PHP version" "$labelUnknown"
|
|
printDanger "$error"
|
|
fi
|
|
fi
|
|
done < <(awk 'NF' <<< "$podList")
|
|
fi
|
|
|
|
printSection "Hosts"
|
|
local vhostList vhostDown
|
|
if run output error openlitespeedConfigVhostList; then
|
|
mapfile -t vhostList < <(awk 'NF' <<< "$output")
|
|
printDotText "all" "${#vhostList[@]}"
|
|
else
|
|
printDotText "all" "$labelUnknown"
|
|
printDanger "$error"
|
|
fi
|
|
|
|
if run output error openlitespeedConfigVhostList "down"; then
|
|
mapfile -t vhostDownList < <(awk 'NF' <<< "$output")
|
|
printDotText "down" "${#vhostDownList[@]}"
|
|
else
|
|
printDotText "down" "$labelUnknown"
|
|
printDanger "$error"
|
|
fi
|
|
|
|
local count="$(find "$olsVhostsPath" -mindepth 1 -maxdepth 1 -type d | wc -l)"
|
|
printDotText "directories" "$fontGray$olsVhostsPath$fontReset $count"
|
|
}
|
|
|
|
# Marks a virtual host as suspended.
|
|
# $1 (domain): site domain name.
|
|
function cmdOpenlitespeedVhostDown() {
|
|
printRow
|
|
|
|
local error
|
|
if ! runError error openlitespeedVhostConfigDown "$@"; then
|
|
printDotText "VHost down" "$labelFail"
|
|
printDanger "$error"
|
|
else
|
|
printDotText "VHost down" "$labelPass"
|
|
cmdOpenlitespeedRestart
|
|
fi
|
|
}
|
|
|
|
# Marks a virtual host as active.
|
|
# $1 (domain): site domain name.
|
|
function cmdOpenlitespeedVhostUp() {
|
|
printRow
|
|
|
|
local error
|
|
if ! runError error openlitespeedVhostConfigUp "$@"; then
|
|
printDotText "VHost up" "$labelFail"
|
|
printDanger "$error"
|
|
else
|
|
printDotText "VHost up" "$labelPass"
|
|
cmdOpenlitespeedRestart
|
|
fi
|
|
}
|
|
|
|
# Lists virtual hosts with optional status filtering.
|
|
# [$1] (type): all (default) | up | down.
|
|
function cmdOpenlitespeedSiteList() {
|
|
printRow
|
|
|
|
local output error type="${1:-all}"
|
|
if ! run output error openlitespeedConfigVhostList "$type"; then
|
|
printDanger "$error"
|
|
else
|
|
printText "$output"
|
|
fi
|
|
}
|
|
|
|
# Updates the Traefik middleware allowlist for OpenLiteSpeed WebAdmin.
|
|
function cmdOpenlitespeedAdminWhiteList() {
|
|
printRow
|
|
|
|
local output error
|
|
run output error openlitespeedAdminWhiteList || { printDotText "Update" "$labelFail"; printDanger "$error"; return 1; }
|
|
|
|
printDotText "White list" "$output"
|
|
printDotText "Update" "$labelDone"
|
|
}
|
|
|
|
# Updates OpenLiteSpeed WebAdmin access control from current Traefik pod IPs.
|
|
function cmdOpenlitespeedAdminAllowList() {
|
|
printRow
|
|
|
|
local output error
|
|
run output error openlitespeedAdminAllowList || { printDotText "Update" "$labelFail"; printDanger "$error"; return 1; }
|
|
|
|
printDotText "Allow list: ${output:-$labelNull}"
|
|
printDotText "Update" "$labelDone"
|
|
cmdOpenlitespeedRestart
|
|
}
|
|
|
|
# Sets aliases for an OpenLiteSpeed virtual host.
|
|
# $1 (domain): primary site domain name.
|
|
# $@ (...): alias domain names.
|
|
function cmdOpenlitespeedVhostAliasSet() {
|
|
local domain
|
|
domain=$(domainPrepare "$1")
|
|
|
|
printRow
|
|
|
|
domainCheck "$domain" || return 1
|
|
|
|
local vhostList aliasList output error
|
|
if ! run vhostList error openlitespeedConfigVhostList; then
|
|
appError "Error retrieving vhost list: $error"
|
|
return 1
|
|
elif ! listContains "$domain" "$vhostList"; then
|
|
appError "Domain not exists in OpenLiteSpeed config: $domain"
|
|
return 1
|
|
fi
|
|
|
|
run output error openlitespeedVhostSet "$@" || {
|
|
printDotText "Set" "$labelFail"
|
|
printDanger "$error"
|
|
return 1
|
|
}
|
|
|
|
printDotText "Alias" "${output:-$labelNull}"
|
|
printDotText "Set" "$labelDone"
|
|
cmdOpenlitespeedRestart
|
|
}
|
|
|
|
# Lists aliases for a domain or all domains.
|
|
# [$1] (target): domain name, or "all" to list all.
|
|
function cmdOpenlitespeedAliasList() {
|
|
printRow
|
|
|
|
local output error domain target="$1"
|
|
if [[ "$target" == all ]]; then
|
|
if ! run output error openlitespeedConfigAliasList; then
|
|
printDanger "$error"
|
|
elif [[ -z "$output" ]]; then
|
|
printText "$labelNull"
|
|
else
|
|
printText "$output"
|
|
fi
|
|
else
|
|
domain=$(domainPrepare "$target")
|
|
if ! run output error openlitespeedConfigVhostAliasList "$domain"; then
|
|
printDanger "$error"
|
|
elif [[ -z "$output" ]]; then
|
|
printText "$labelNull"
|
|
else
|
|
printText "$output"
|
|
fi
|
|
fi
|
|
}
|
|
|
|
# Tests the OpenLiteSpeed configuration inside the container.
|
|
function cmdOpenlitespeedConfigCheck() {
|
|
printRow
|
|
|
|
local output error
|
|
run output error openlitespeedExec sh -lc "/usr/local/lsws/bin/openlitespeed -t 2>/dev/null || true"
|
|
if grep -qi 'configuration failed!' <<< "$output"; then
|
|
printDotText "Check config" "$labelFail"
|
|
printDanger "$output"
|
|
else
|
|
printDotText "Check config" "$labelPass"
|
|
fi
|
|
}
|
|
|
|
function cmdOpenlitespeedVhostRebuild() {
|
|
local target="$1"
|
|
local vhostList error
|
|
|
|
printRow
|
|
|
|
if [[ -z "$target" ]]; then
|
|
printDanger "Target not specified";
|
|
elif ! run vhostList error openlitespeedConfigVhostList; then
|
|
printDanger "Cannot get vhost list: $error";
|
|
elif [[ "$target" == "all" ]]; then
|
|
local domain
|
|
for domain in $vhostList; do
|
|
if ! runError error openlitespeedVhostRebuild "$domain"; then
|
|
printDotText "$domain" "$labelFail"
|
|
printDanger "$error"
|
|
else
|
|
printDotText "$domain" "$labelDone"
|
|
fi
|
|
done
|
|
elif ! listContains "$target" "$vhostList"; then
|
|
printDanger "Unknown domain: $target";
|
|
elif ! runError error openlitespeedVhostRebuild "$target"; then
|
|
printDotText "$target" "$labelFail"
|
|
printDanger "$error"
|
|
else
|
|
printDotText "$target" "$labelDone"
|
|
fi
|
|
}
|