#!/usr/bin/with-contenv bash
# shellcheck shell=bash

# Check if the cert is expired or expires within a day, if so, renew
if openssl x509 -in /config/keys/letsencrypt/fullchain.pem -noout -checkend 86400 >/dev/null; then
    echo "The cert does not expire within the next day. Letting the cron script handle the renewal attempts."
else
    echo "The cert is either expired or it expires within the next day. Attempting to renew. This could take up to 10 minutes."
    /app/le-renew.sh
    sleep 1
fi
