feat: promote acme-dns renewal to production
This commit was merged in pull request #28.
This commit is contained in:
@@ -57,6 +57,12 @@ in
|
|||||||
|
|
||||||
environment.etc."acme-dns/lego.env".source = legoEnvironment;
|
environment.etc."acme-dns/lego.env".source = legoEnvironment;
|
||||||
|
|
||||||
|
# The staging order has completed successfully. This marker permits the
|
||||||
|
# production ACME post-run hook to hand a renewed certificate to Traefik.
|
||||||
|
systemd.tmpfiles.rules = [
|
||||||
|
"f /var/lib/ci-certs/acme-production-enabled 0600 root root -"
|
||||||
|
];
|
||||||
|
|
||||||
networking.firewall = {
|
networking.firewall = {
|
||||||
allowedTCPPorts = [ 53 ];
|
allowedTCPPorts = [ 53 ];
|
||||||
allowedUDPPorts = [ 53 ];
|
allowedUDPPorts = [ 53 ];
|
||||||
@@ -131,15 +137,15 @@ in
|
|||||||
certs."ci.commoninternet.net" = {
|
certs."ci.commoninternet.net" = {
|
||||||
domain = "ci.commoninternet.net";
|
domain = "ci.commoninternet.net";
|
||||||
extraDomainNames = [ "*.ci.commoninternet.net" ];
|
extraDomainNames = [ "*.ci.commoninternet.net" ];
|
||||||
# The pinned Lego provider spells this `acmedns`; keep the service on
|
# Staging issuance succeeded using the permanent, narrowly delegated
|
||||||
# staging until the operator has installed the permanent CNAME.
|
# CNAME. Production uses the same restricted acme-dns account.
|
||||||
dnsProvider = "acmedns";
|
dnsProvider = "acmedns";
|
||||||
environmentFile = "/etc/acme-dns/lego.env";
|
environmentFile = "/etc/acme-dns/lego.env";
|
||||||
dnsResolver = "1.1.1.1:53";
|
dnsResolver = "1.1.1.1:53";
|
||||||
server = "https://acme-staging-v02.api.letsencrypt.org/directory";
|
server = "https://acme-v02.api.letsencrypt.org/directory";
|
||||||
postRun = ''
|
postRun = ''
|
||||||
# Production cutover creates this marker in a separate reviewed
|
# The production marker is deployed only after staging proves the
|
||||||
# deployment. Staging issuance must never replace the live cert.
|
# permanent CNAME and restricted acme-dns account work end to end.
|
||||||
if [ -e /var/lib/ci-certs/acme-production-enabled ]; then
|
if [ -e /var/lib/ci-certs/acme-production-enabled ]; then
|
||||||
${pkgs.systemd}/bin/systemctl --no-block start cc-ci-acme-traefik-handoff.service
|
${pkgs.systemd}/bin/systemctl --no-block start cc-ci-acme-traefik-handoff.service
|
||||||
fi
|
fi
|
||||||
|
|||||||
Reference in New Issue
Block a user