diff --git a/Dockerfile b/Dockerfile index ebb6cae..b829a5f 100755 --- a/Dockerfile +++ b/Dockerfile @@ -114,6 +114,7 @@ RUN \ certbot-dns-google \ certbot-dns-he \ certbot-dns-hetzner \ + certbot-dns-hetzner-cloud \ certbot-dns-infomaniak \ certbot-dns-inwx \ certbot-dns-ionos \ diff --git a/Dockerfile.aarch64 b/Dockerfile.aarch64 index 8198789..fdb4c9d 100755 --- a/Dockerfile.aarch64 +++ b/Dockerfile.aarch64 @@ -114,6 +114,7 @@ RUN \ certbot-dns-google \ certbot-dns-he \ certbot-dns-hetzner \ + certbot-dns-hetzner-cloud \ certbot-dns-infomaniak \ certbot-dns-inwx \ certbot-dns-ionos \ diff --git a/Jenkinsfile b/Jenkinsfile index 0e91b98..a8021da 100644 --- a/Jenkinsfile +++ b/Jenkinsfile @@ -76,6 +76,7 @@ pipeline { ''' script{ env.EXIT_STATUS = '' + env.CI_TEST_ATTEMPTED = '' env.LS_RELEASE = sh( script: '''docker run --rm quay.io/skopeo/stable:v1 inspect docker://ghcr.io/${LS_USER}/${CONTAINER_NAME}:latest 2>/dev/null | jq -r '.Labels.build_version' | awk '{print $3}' | grep '\\-ls' || : ''', returnStdout: true).trim() @@ -283,7 +284,7 @@ pipeline { -v ${WORKSPACE}:/mnt \ -e AWS_ACCESS_KEY_ID=\"${S3_KEY}\" \ -e AWS_SECRET_ACCESS_KEY=\"${S3_SECRET}\" \ - ghcr.io/linuxserver/baseimage-alpine:3 s6-envdir -fn -- /var/run/s6/container_environment /bin/bash -c "\ + ghcr.io/linuxserver/baseimage-alpine:3.23 s6-envdir -fn -- /var/run/s6/container_environment /bin/bash -c "\ apk add --no-cache python3 && \ python3 -m venv /lsiopy && \ pip install --no-cache-dir -U pip && \ @@ -871,6 +872,7 @@ pipeline { script{ env.CI_URL = 'https://ci-tests.linuxserver.io/' + env.IMAGE + '/' + env.META_TAG + '/index.html' env.CI_JSON_URL = 'https://ci-tests.linuxserver.io/' + env.IMAGE + '/' + env.META_TAG + '/report.json' + env.CI_TEST_ATTEMPTED = 'true' } sh '''#! /bin/bash set -e @@ -1073,98 +1075,13 @@ EOF ) ''' } } - // If this is a Pull request send the CI link as a comment on it - stage('Pull Request Comment') { - when { - not {environment name: 'CHANGE_ID', value: ''} - environment name: 'EXIT_STATUS', value: '' - } - steps { - sh '''#! /bin/bash - # Function to retrieve JSON data from URL - get_json() { - local url="$1" - local response=$(curl -s "$url") - if [ $? -ne 0 ]; then - echo "Failed to retrieve JSON data from $url" - return 1 - fi - local json=$(echo "$response" | jq .) - if [ $? -ne 0 ]; then - echo "Failed to parse JSON data from $url" - return 1 - fi - echo "$json" - } - - build_table() { - local data="$1" - - # Get the keys in the JSON data - local keys=$(echo "$data" | jq -r 'to_entries | map(.key) | .[]') - - # Check if keys are empty - if [ -z "$keys" ]; then - echo "JSON report data does not contain any keys or the report does not exist." - return 1 - fi - - # Build table header - local header="| Tag | Passed |\\n| --- | --- |\\n" - - # Loop through the JSON data to build the table rows - local rows="" - for build in $keys; do - local status=$(echo "$data" | jq -r ".[\\"$build\\"].test_success") - if [ "$status" = "true" ]; then - status="✅" - else - status="❌" - fi - local row="| "$build" | "$status" |\\n" - rows="${rows}${row}" - done - - local table="${header}${rows}" - local escaped_table=$(echo "$table" | sed 's/\"/\\\\"/g') - echo "$escaped_table" - } - - if [[ "${CI}" = "true" ]]; then - # Retrieve JSON data from URL - data=$(get_json "$CI_JSON_URL") - # Create table from JSON data - table=$(build_table "$data") - echo -e "$table" - - curl -X POST -H "Authorization: token $GITHUB_TOKEN" \ - -H "Accept: application/vnd.github.v3+json" \ - "https://api.github.com/repos/$LS_USER/$LS_REPO/issues/$PULL_REQUEST/comments" \ - -d "{\\"body\\": \\"I am a bot, here are the test results for this PR: \\n${CI_URL}\\n${SHELLCHECK_URL}\\n${table}\\"}" - else - curl -X POST -H "Authorization: token $GITHUB_TOKEN" \ - -H "Accept: application/vnd.github.v3+json" \ - "https://api.github.com/repos/$LS_USER/$LS_REPO/issues/$PULL_REQUEST/comments" \ - -d "{\\"body\\": \\"I am a bot, here is the pushed image/manifest for this PR: \\n\\n\\`${GITHUBIMAGE}:${META_TAG}\\`\\"}" - fi - ''' - - } - } } /* ###################### - Send status to Discord + Comment on PR and Send status to Discord ###################### */ post { always { - sh '''#!/bin/bash - rm -rf /config/.ssh/id_sign - rm -rf /config/.ssh/id_sign.pub - git config --global --unset gpg.format - git config --global --unset user.signingkey - git config --global --unset commit.gpgsign - ''' - script{ + script { env.JOB_DATE = sh( script: '''date '+%Y-%m-%dT%H:%M:%S%:z' ''', returnStdout: true).trim() @@ -1207,6 +1124,87 @@ EOF "username": "Jenkins"}' ${BUILDS_DISCORD} ''' } } + script { + if (env.GITHUBIMAGE =~ /lspipepr/){ + if (env.CI_TEST_ATTEMPTED == "true"){ + sh '''#! /bin/bash + # Function to retrieve JSON data from URL + get_json() { + local url="$1" + local response=$(curl -s "$url") + if [ $? -ne 0 ]; then + echo "Failed to retrieve JSON data from $url" + return 1 + fi + local json=$(echo "$response" | jq .) + if [ $? -ne 0 ]; then + echo "Failed to parse JSON data from $url" + return 1 + fi + echo "$json" + } + + build_table() { + local data="$1" + + # Get the keys in the JSON data + local keys=$(echo "$data" | jq -r 'to_entries | map(.key) | .[]') + + # Check if keys are empty + if [ -z "$keys" ]; then + echo "JSON report data does not contain any keys or the report does not exist." + return 1 + fi + + # Build table header + local header="| Tag | Passed |\\n| --- | --- |\\n" + + # Loop through the JSON data to build the table rows + local rows="" + for build in $keys; do + local status=$(echo "$data" | jq -r ".[\\"$build\\"].test_success") + if [ "$status" = "true" ]; then + status="✅" + else + status="❌" + fi + local row="| "$build" | "$status" |\\n" + rows="${rows}${row}" + done + + local table="${header}${rows}" + local escaped_table=$(echo "$table" | sed 's/\"/\\\\"/g') + echo "$escaped_table" + } + + if [[ "${CI}" = "true" ]]; then + # Retrieve JSON data from URL + data=$(get_json "$CI_JSON_URL") + # Create table from JSON data + table=$(build_table "$data") + echo -e "$table" + + curl -X POST -H "Authorization: token $GITHUB_TOKEN" \ + -H "Accept: application/vnd.github.v3+json" \ + "https://api.github.com/repos/$LS_USER/$LS_REPO/issues/$PULL_REQUEST/comments" \ + -d "{\\"body\\": \\"I am a bot, here are the test results for this PR: \\n${CI_URL}\\n${SHELLCHECK_URL}\\n${table}\\"}" + else + curl -X POST -H "Authorization: token $GITHUB_TOKEN" \ + -H "Accept: application/vnd.github.v3+json" \ + "https://api.github.com/repos/$LS_USER/$LS_REPO/issues/$PULL_REQUEST/comments" \ + -d "{\\"body\\": \\"I am a bot, here is the pushed image/manifest for this PR: \\n\\n\\`${GITHUBIMAGE}:${META_TAG}\\`\\"}" + fi + ''' + } + } + } + sh '''#!/bin/bash + rm -rf /config/.ssh/id_sign + rm -rf /config/.ssh/id_sign.pub + git config --global --unset gpg.format + git config --global --unset user.signingkey + git config --global --unset commit.gpgsign + ''' } cleanup { sh '''#! /bin/bash diff --git a/README.md b/README.md index 4486aa9..a4e8e71 100644 --- a/README.md +++ b/README.md @@ -170,7 +170,7 @@ This image can be run with a read-only container filesystem. For details please To help you get started creating a container from this image you can either use docker-compose or the docker cli. >[!NOTE] ->Unless a parameter is flaged as 'optional', it is *mandatory* and a value must be provided. +>Unless a parameter is flagged as 'optional', it is *mandatory* and a value must be provided. ### docker-compose (recommended, [click here for more info](https://docs.linuxserver.io/general/docker-compose)) @@ -254,7 +254,7 @@ Containers are configured using parameters passed at runtime (such as those abov | `-e VALIDATION=http` | Certbot validation method to use, options are `http` or `dns` (`dns` method also requires `DNSPLUGIN` variable set). | | `-e SUBDOMAINS=www,` | Subdomains you'd like the cert to cover (comma separated, no spaces) ie. `www,ftp,cloud`. For a wildcard cert, set this *exactly* to `wildcard` (wildcard cert is available via `dns` validation only) | | `-e CERTPROVIDER=` | Optionally define the cert provider. Set to `zerossl` for ZeroSSL certs (requires existing [ZeroSSL account](https://app.zerossl.com/signup) and the e-mail address entered in `EMAIL` env var). Otherwise defaults to Let's Encrypt. | -| `-e DNSPLUGIN=cloudflare` | Required if `VALIDATION` is set to `dns`. Options are `acmedns`, `aliyun`, `azure`, `bunny`, `cloudflare`, `cpanel`, `desec`, `digitalocean`, `directadmin`, `dnsimple`, `dnsmadeeasy`, `dnspod`, `do`, `domeneshop`, `dreamhost`, `duckdns`, `dynu`, `freedns`, `gandi`, `gehirn`, `glesys`, `godaddy`, `google`, `he`, `hetzner`, `infomaniak`, `inwx`, `ionos`, `linode`, `loopia`, `luadns`, `namecheap`, `netcup`, `njalla`, `nsone`, `ovh`, `porkbun`, `rfc2136`, `route53`, `sakuracloud`, `standalone`, `transip`, and `vultr`. Also need to enter the credentials into the corresponding ini (or json for some plugins) file under `/config/dns-conf`. | +| `-e DNSPLUGIN=cloudflare` | Required if `VALIDATION` is set to `dns`. Options are `acmedns`, `aliyun`, `azure`, `bunny`, `cloudflare`, `cpanel`, `desec`, `digitalocean`, `directadmin`, `dnsimple`, `dnsmadeeasy`, `dnspod`, `do`, `domeneshop`, `dreamhost`, `duckdns`, `dynu`, `freedns`, `gandi`, `gehirn`, `glesys`, `godaddy`, `google`, `he`, `hetzner`, `hetzner-cloud`, `infomaniak`, `inwx`, `ionos`, `linode`, `loopia`, `luadns`, `namecheap`, `netcup`, `njalla`, `nsone`, `ovh`, `porkbun`, `rfc2136`, `route53`, `sakuracloud`, `standalone`, `transip`, and `vultr`. Also need to enter the credentials into the corresponding ini (or json for some plugins) file under `/config/dns-conf`. | | `-e PROPAGATION=` | Optionally override (in seconds) the default propagation time for the dns plugins. | | `-e EMAIL=` | Optional e-mail address used for cert expiration notifications (Required for ZeroSSL). | | `-e ONLY_SUBDOMAINS=false` | If you wish to get certs only for certain subdomains, but not the main domain (main domain may be hosted on another machine and cannot be validated), set this to `true` | @@ -433,6 +433,8 @@ Once registered you can define the dockerfile to use with `-f Dockerfile.aarch64 ## Versions +* **23.01.26:** - Reorder init to fix proxy conf version checks. +* **21.12.25:** - Add support for hetzner-cloud dns validation. * **04.11.25:** - Switch default Gandi credentials from API Key to Token, allow DNS propagation time for Azure DNS plugin. * **18.07.25:** - Rebase to Alpine 3.22 with PHP 8.4. Add QUIC support. Drop PHP bindings for mcrypt as it is no longer maintained. * **05.05.25:** - Disable Certbot's built in log rotation. diff --git a/package_versions.txt b/package_versions.txt index e75b9e1..caf90dc 100755 --- a/package_versions.txt +++ b/package_versions.txt @@ -1,109 +1,110 @@ NAME VERSION TYPE Simple Launcher 1.1.0.14 binary (+5 duplicates) acl-libs 2.3.2-r1 apk -acme 5.2.2 python +acme 5.5.0 python alpine-baselayout 3.7.0-r0 apk alpine-baselayout-data 3.7.0-r0 apk alpine-keys 2.5-r0 apk -alpine-release 3.22.2-r0 apk +alpine-release 3.22.3-r0 apk aom-libs 3.12.1-r0 apk apache2-utils 2.4.66-r0 apk apk-tools 2.14.9-r3 apk apr 1.7.5-r0 apk apr-util 1.6.3-r1 apk argon2-libs 20190702-r5 apk -attrs 25.4.0 python +attrs 26.1.0 python autocommand 2.2.2 python azure-common 1.1.28 python -azure-core 1.37.0 python -azure-identity 1.25.1 python +azure-core 1.39.0 python +azure-identity 1.25.3 python azure-mgmt-core 1.6.0 python azure-mgmt-dns 9.0.0 python backports-tarfile 1.2.0 python bash 5.2.37-r0 apk beautifulsoup4 4.14.3 python -boto3 1.42.9 python -botocore 1.42.9 python +boto3 1.42.91 python +botocore 1.42.91 python brotli-libs 1.1.0-r2 apk bs4 0.0.2 python busybox 1.37.0-r20 apk busybox-binsh 1.37.0-r20 apk -c-ares 1.34.5-r0 apk +c-ares 1.34.6-r0 apk c-client 2007f-r15 apk ca-certificates 20250911-r0 apk ca-certificates-bundle 20250911-r0 apk -cachetools 6.2.3 python catatonit 0.2.1-r0 apk -certbot 5.2.2 python +certbot 5.5.0 python certbot-dns-acmedns 0.1.0 python certbot-dns-aliyun 2.0.0 python certbot-dns-azure 1.5.0 python certbot-dns-bunny 3.0.0 python -certbot-dns-cloudflare 5.2.2 python +certbot-dns-cloudflare 5.5.0 python certbot-dns-cpanel 0.4.0 python certbot-dns-desec 1.3.2 python -certbot-dns-digitalocean 5.2.2 python +certbot-dns-digitalocean 5.5.0 python certbot-dns-directadmin 1.0.15 python -certbot-dns-dnsimple 5.2.2 python -certbot-dns-dnsmadeeasy 5.2.2 python +certbot-dns-dnsimple 5.5.0 python +certbot-dns-dnsmadeeasy 5.5.0 python certbot-dns-dnspod 0.1.0 python certbot-dns-do 0.31.0 python certbot-dns-domeneshop 0.2.9 python certbot-dns-dreamhost 1.0 python -certbot-dns-duckdns 1.7.1 python +certbot-dns-duckdns 1.8.0 python certbot-dns-dynudns 0.0.6 python certbot-dns-freedns 0.2.0 python -certbot-dns-gehirn 5.2.2 python +certbot-dns-gehirn 5.5.0 python certbot-dns-glesys 2.1.0 python certbot-dns-godaddy 2.8.0 python -certbot-dns-google 5.2.2 python +certbot-dns-google 5.5.0 python certbot-dns-he 1.0.0 python -certbot-dns-hetzner 2.0.1 python +certbot-dns-hetzner 3.0.0 python +certbot-dns-hetzner-cloud 1.0.5 python certbot-dns-infomaniak 0.2.4 python certbot-dns-inwx 3.0.3 python certbot-dns-ionos 2024.11.9 python -certbot-dns-linode 5.2.2 python +certbot-dns-linode 5.5.0 python certbot-dns-loopia 1.0.1 python -certbot-dns-luadns 5.2.2 python +certbot-dns-luadns 5.5.0 python certbot-dns-namecheap 1.0.0 python -certbot-dns-netcup 2.0.0 python +certbot-dns-netcup 2.0.3 python certbot-dns-njalla 2.0.2 python -certbot-dns-nsone 5.2.2 python -certbot-dns-ovh 5.2.2 python +certbot-dns-nsone 5.5.0 python +certbot-dns-ovh 5.5.0 python certbot-dns-porkbun 0.11.0 python -certbot-dns-rfc2136 5.2.2 python -certbot-dns-route53 5.2.2 python -certbot-dns-sakuracloud 5.2.2 python +certbot-dns-rfc2136 5.5.0 python +certbot-dns-route53 5.5.0 python +certbot-dns-sakuracloud 5.5.0 python certbot-dns-standalone 1.2.1 python certbot-dns-transip 0.5.2 python certbot-dns-vultr 1.1.0 python certbot-plugin-gandi 1.5.0 python -certifi 2025.11.12 python +certifi 2026.2.25 python cffi 2.0.0 python -charset-normalizer 3.4.4 python +charset-normalizer 3.4.7 python cli UNKNOWN binary cli-32 UNKNOWN binary cli-64 UNKNOWN binary cli-arm64 UNKNOWN binary cloudflare 2.19.4 python -composer 2.9.2 binary -configargparse 1.7.1 python +composer 2.9.7 binary +configargparse 1.7.5 python configobj 5.0.9 python coreutils 9.7-r1 apk coreutils-env 9.7-r1 apk coreutils-fmt 9.7-r1 apk coreutils-sha512sum 9.7-r1 apk -cryptography 46.0.3 python +cryptography 46.0.7 python curl 8.14.1-r2 apk distro 1.9.0 python dns-lexicon 3.23.2 python +dns-lexicon-coop 3.24.2 python dnslib 0.9.26 python dnspython 2.8.0 python domeneshop 0.4.4 python fail2ban 1.1.0 python fail2ban 1.1.0-r3 apk fail2ban-pyc 1.1.0-r3 apk -filelock 3.20.0 python +filelock 3.28.0 python findutils 4.10.0-r0 apk fontconfig 2.15.0-r3 apk freetype 2.13.3-r0 apk @@ -113,45 +114,44 @@ git 2.49.1-r0 apk git-init-template 2.49.1-r0 apk git-perl 2.49.1-r0 apk gmp 6.3.0-r3 apk -gnupg 2.4.7-r0 apk -gnupg-dirmngr 2.4.7-r0 apk -gnupg-gpgconf 2.4.7-r0 apk -gnupg-keyboxd 2.4.7-r0 apk -gnupg-utils 2.4.7-r0 apk -gnupg-wks-client 2.4.7-r0 apk -gnutls 3.8.8-r0 apk -google-api-core 2.28.1 python -google-api-python-client 2.187.0 python -google-auth 2.43.0 python -google-auth-httplib2 0.2.1 python -googleapis-common-protos 1.72.0 python -gpg 2.4.7-r0 apk -gpg-agent 2.4.7-r0 apk -gpg-wks-server 2.4.7-r0 apk -gpgsm 2.4.7-r0 apk -gpgv 2.4.7-r0 apk +gnupg 2.4.9-r0 apk +gnupg-dirmngr 2.4.9-r0 apk +gnupg-gpgconf 2.4.9-r0 apk +gnupg-keyboxd 2.4.9-r0 apk +gnupg-utils 2.4.9-r0 apk +gnupg-wks-client 2.4.9-r0 apk +gnutls 3.8.12-r0 apk +google-api-core 2.30.3 python +google-api-python-client 2.194.0 python +google-auth 2.49.2 python +google-auth-httplib2 0.3.1 python +googleapis-common-protos 1.74.0 python +gpg 2.4.9-r0 apk +gpg-agent 2.4.9-r0 apk +gpg-wks-server 2.4.9-r0 apk +gpgsm 2.4.9-r0 apk +gpgv 2.4.9-r0 apk gui UNKNOWN binary gui-32 UNKNOWN binary gui-64 UNKNOWN binary gui-arm64 UNKNOWN binary -httplib2 0.31.0 python +hcloud 2.17.1 python +httplib2 0.31.2 python icu-data-en 76.1-r1 apk icu-libs 76.1-r1 apk idna 3.11 python -importlib-metadata 8.0.0 python -inflect 7.3.1 python +importlib-metadata 8.7.1 python inotify-tools 4.23.9.0-r0 apk inotify-tools-libs 4.23.9.0-r0 apk inwx-domrobot 3.2.0 python iptables 1.8.11-r1 apk iptables-legacy 1.8.11-r1 apk isodate 0.7.2 python -jaraco-collections 5.1.0 python -jaraco-context 5.3.0 python -jaraco-functools 4.0.1 python -jaraco-text 3.12.1 python +jaraco-context 6.1.0 python +jaraco-functools 4.4.0 python +jaraco-text 4.0.0 python jinja2 3.1.6 python -jmespath 1.0.1 python +jmespath 1.1.0 python josepy 2.2.0 python jq 1.8.1-r0 apk jsonlines 4.0.0 python @@ -162,12 +162,12 @@ libattr 2.5.2-r2 apk libavif 1.3.0-r0 apk libbsd 0.12.2-r0 apk libbz2 1.0.8-r6 apk -libcrypto3 3.5.4-r0 apk +libcrypto3 3.5.6-r0 apk libcurl 8.14.1-r2 apk libdav1d 1.5.1-r0 apk libedit 20250104.3.1-r1 apk libevent 2.1.12-r8 apk -libexpat 2.7.3-r0 apk +libexpat 2.7.5-r0 apk libffi 3.4.8-r0 apk libgcc 14.2.0-r6 apk libgcrypt 1.10.3-r1 apk @@ -188,18 +188,18 @@ libmnl 1.0.5-r2 apk libncursesw 6.5_p20250503-r0 apk libnftnl 1.2.9-r0 apk libpanelw 6.5_p20250503-r0 apk -libpng 1.6.53-r0 apk -libpq 17.7-r0 apk +libpng 1.6.57-r0 apk +libpq 17.9-r0 apk libproc2 4.0.4-r3 apk libpsl 0.21.5-r3 apk libsasl 2.1.28-r8 apk libseccomp 2.6.0-r0 apk libsharpyuv 1.5.0-r0 apk libsm 1.2.5-r0 apk -libsodium 1.0.20-r0 apk -libssl3 3.5.4-r0 apk +libsodium 1.0.20-r1 apk +libssl3 3.5.6-r0 apk libstdc++ 14.2.0-r6 apk -libtasn1 4.20.0-r0 apk +libtasn1 4.21.0-r0 apk libunistring 1.3-r0 apk libuuid 2.41-r9 apk libwebp 1.5.0-r0 apk @@ -218,155 +218,152 @@ libzip 1.11.4-r0 apk linux-pam 1.7.0-r4 apk logrotate 3.21.0-r1 apk loopialib 0.2.0 python -lxml 6.0.2 python +lxml 6.1.0 python lz4-libs 1.10.0-r0 apk markupsafe 3.0.3 python memcached 1.6.32-r0 apk mock 5.2.0 python -more-itertools 10.3.0 python +more-itertools 10.8.0 python mpdecimal 4.0.1-r0 apk -msal 1.34.0 python +msal 1.36.0 python msal-extensions 1.3.1 python -musl 1.2.5-r10 apk -musl-utils 1.2.5-r10 apk -my-test-package 1.0 python +musl 1.2.5-r12 apk +musl-utils 1.2.5-r12 apk nano 8.4-r0 apk ncurses-terminfo-base 6.5_p20250503-r0 apk netcat-openbsd 1.229.1-r0 apk -nettle 3.10.1-r0 apk +nettle 3.10.2-r0 apk nghttp2-libs 1.65.0-r0 apk -nginx 1.28.0-r3 apk -nginx-mod-devel-kit 1.28.0-r3 apk -nginx-mod-http-brotli 1.28.0-r3 apk -nginx-mod-http-dav-ext 1.28.0-r3 apk -nginx-mod-http-echo 1.28.0-r3 apk -nginx-mod-http-fancyindex 1.28.0-r3 apk -nginx-mod-http-geoip2 1.28.0-r3 apk -nginx-mod-http-headers-more 1.28.0-r3 apk -nginx-mod-http-image-filter 1.28.0-r3 apk -nginx-mod-http-perl 1.28.0-r3 apk -nginx-mod-http-redis2 1.28.0-r3 apk -nginx-mod-http-set-misc 1.28.0-r3 apk -nginx-mod-http-upload-progress 1.28.0-r3 apk -nginx-mod-http-xslt-filter 1.28.0-r3 apk -nginx-mod-mail 1.28.0-r3 apk -nginx-mod-rtmp 1.28.0-r3 apk -nginx-mod-stream 1.28.0-r3 apk -nginx-mod-stream-geoip2 1.28.0-r3 apk -nginx-vim 1.28.0-r3 apk +nginx 1.28.3-r0 apk +nginx-mod-devel-kit 1.28.3-r0 apk +nginx-mod-http-brotli 1.28.3-r0 apk +nginx-mod-http-dav-ext 1.28.3-r0 apk +nginx-mod-http-echo 1.28.3-r0 apk +nginx-mod-http-fancyindex 1.28.3-r0 apk +nginx-mod-http-geoip2 1.28.3-r0 apk +nginx-mod-http-headers-more 1.28.3-r0 apk +nginx-mod-http-image-filter 1.28.3-r0 apk +nginx-mod-http-perl 1.28.3-r0 apk +nginx-mod-http-redis2 1.28.3-r0 apk +nginx-mod-http-set-misc 1.28.3-r0 apk +nginx-mod-http-upload-progress 1.28.3-r0 apk +nginx-mod-http-xslt-filter 1.28.3-r0 apk +nginx-mod-mail 1.28.3-r0 apk +nginx-mod-rtmp 1.28.3-r0 apk +nginx-mod-stream 1.28.3-r0 apk +nginx-mod-stream-geoip2 1.28.3-r0 apk +nginx-vim 1.28.3-r0 apk npth 1.8-r0 apk oniguruma 6.9.10-r0 apk -openssl 3.5.4-r0 apk +openssl 3.5.6-r0 apk p11-kit 0.25.5-r2 apk -packaging 24.2 python +packaging 26.0 python +packaging 26.1 python parsedatetime 2.6 python pcre2 10.46-r0 apk -perl 5.40.3-r0 apk +perl 5.40.4-r0 apk perl-error 0.17030-r0 apk perl-git 2.49.1-r0 apk -php84 8.4.14-r0 apk -php84-bcmath 8.4.14-r0 apk -php84-bz2 8.4.14-r0 apk -php84-common 8.4.14-r0 apk -php84-ctype 8.4.14-r0 apk -php84-curl 8.4.14-r0 apk -php84-dom 8.4.14-r0 apk -php84-exif 8.4.14-r0 apk -php84-fileinfo 8.4.14-r0 apk -php84-fpm 8.4.14-r0 apk -php84-ftp 8.4.14-r0 apk -php84-gd 8.4.14-r0 apk -php84-gmp 8.4.14-r0 apk -php84-iconv 8.4.14-r0 apk -php84-intl 8.4.14-r0 apk -php84-ldap 8.4.14-r0 apk -php84-mbstring 8.4.14-r0 apk -php84-mysqli 8.4.14-r0 apk -php84-mysqlnd 8.4.14-r0 apk -php84-opcache 8.4.14-r0 apk -php84-openssl 8.4.14-r0 apk -php84-pdo 8.4.14-r0 apk -php84-pdo_mysql 8.4.14-r0 apk -php84-pdo_odbc 8.4.14-r0 apk -php84-pdo_pgsql 8.4.14-r0 apk -php84-pdo_sqlite 8.4.14-r0 apk -php84-pear 8.4.14-r0 apk +php84 8.4.16-r0 apk +php84-bcmath 8.4.16-r0 apk +php84-bz2 8.4.16-r0 apk +php84-common 8.4.16-r0 apk +php84-ctype 8.4.16-r0 apk +php84-curl 8.4.16-r0 apk +php84-dom 8.4.16-r0 apk +php84-exif 8.4.16-r0 apk +php84-fileinfo 8.4.16-r0 apk +php84-fpm 8.4.16-r0 apk +php84-ftp 8.4.16-r0 apk +php84-gd 8.4.16-r0 apk +php84-gmp 8.4.16-r0 apk +php84-iconv 8.4.16-r0 apk +php84-intl 8.4.16-r0 apk +php84-ldap 8.4.16-r0 apk +php84-mbstring 8.4.16-r0 apk +php84-mysqli 8.4.16-r0 apk +php84-mysqlnd 8.4.16-r0 apk +php84-opcache 8.4.16-r0 apk +php84-openssl 8.4.16-r0 apk +php84-pdo 8.4.16-r0 apk +php84-pdo_mysql 8.4.16-r0 apk +php84-pdo_odbc 8.4.16-r0 apk +php84-pdo_pgsql 8.4.16-r0 apk +php84-pdo_sqlite 8.4.16-r0 apk +php84-pear 8.4.16-r0 apk php84-pecl-apcu 5.1.27-r0 apk php84-pecl-igbinary 3.2.16-r1 apk php84-pecl-imap 1.0.3-r0 apk php84-pecl-memcached 3.3.0-r0 apk php84-pecl-msgpack 3.0.0-r0 apk php84-pecl-redis 6.3.0-r0 apk -php84-pgsql 8.4.14-r0 apk -php84-phar 8.4.14-r0 apk -php84-posix 8.4.14-r0 apk -php84-session 8.4.14-r0 apk -php84-simplexml 8.4.14-r0 apk -php84-soap 8.4.14-r0 apk -php84-sockets 8.4.14-r0 apk -php84-sodium 8.4.14-r0 apk -php84-sqlite3 8.4.14-r0 apk -php84-tokenizer 8.4.14-r0 apk -php84-xml 8.4.14-r0 apk -php84-xmlreader 8.4.14-r0 apk -php84-xmlwriter 8.4.14-r0 apk -php84-xsl 8.4.14-r0 apk -php84-zip 8.4.14-r0 apk +php84-pgsql 8.4.16-r0 apk +php84-phar 8.4.16-r0 apk +php84-posix 8.4.16-r0 apk +php84-session 8.4.16-r0 apk +php84-simplexml 8.4.16-r0 apk +php84-soap 8.4.16-r0 apk +php84-sockets 8.4.16-r0 apk +php84-sodium 8.4.16-r0 apk +php84-sqlite3 8.4.16-r0 apk +php84-tokenizer 8.4.16-r0 apk +php84-xml 8.4.16-r0 apk +php84-xmlreader 8.4.16-r0 apk +php84-xmlwriter 8.4.16-r0 apk +php84-xsl 8.4.16-r0 apk +php84-zip 8.4.16-r0 apk pinentry 1.3.1-r0 apk -pip 25.3 python -pkb-client 2.2.0 python -platformdirs 4.2.2 python +pip 26.0.1 python +pkb-client 2.3.1 python +platformdirs 4.4.0 python popt 1.19-r4 apk procps-ng 4.0.4-r3 apk -proto-plus 1.26.1 python -protobuf 6.33.2 python +proto-plus 1.27.2 python +protobuf 7.34.1 python pyacmedns 0.4 python -pyasn1 0.6.1 python +pyasn1 0.6.3 python pyasn1-modules 0.4.2 python -pyc 3.12.12-r0 apk -pycparser 2.23 python -pyjwt 2.10.1 python +pyc 3.12.13-r0 apk +pycparser 3.0 python +pyjwt 2.12.1 python pynamecheap 0.0.3 python -pyopenssl 25.3.0 python +pyopenssl 26.0.0 python pyotp 2.9.0 python -pyparsing 3.2.5 python +pyparsing 3.3.2 python pyrfc3339 2.1.0 python python-dateutil 2.9.0.post0 python python-digitalocean 1.17.0 python python-transip 0.6.0 python -python3 3.12.12-r0 apk -python3-pyc 3.12.12-r0 apk -python3-pycache-pyc0 3.12.12-r0 apk +python3 3.12.13-r0 apk +python3-pyc 3.12.13-r0 apk +python3-pycache-pyc0 3.12.13-r0 apk pyyaml 6.0.3 python readline 8.2.13-r1 apk -requests 2.32.5 python +requests 2.33.1 python requests-file 3.0.1 python requests-mock 1.12.1 python -rsa 4.9.1 python s3transfer 0.16.0 python scanelf 1.3.8-r1 apk -setuptools 80.9.0 python +setuptools 82.0.1 python shadow 4.17.3-r0 apk six 1.17.0 python skalibs-libs 2.14.4.0-r0 apk -soupsieve 2.8 python +soupsieve 2.8.3 python sqlite-libs 3.49.2-r1 apk ssl_client 1.37.0-r20 apk tiff 4.7.1-r0 apk -tldextract 5.3.0 python -tomli 2.0.1 python -typeguard 4.3.0 python -typing-extensions 4.12.2 python +tldextract 5.3.1 python +tomli 2.4.0 python typing-extensions 4.15.0 python -tzdata 2025b-r0 apk +tzdata 2026a-r0 apk unixodbc 2.3.12-r0 apk uritemplate 4.2.0 python -urllib3 2.6.2 python +urllib3 2.6.3 python utmps-libs 0.1.3.1-r0 apk -wheel 0.45.1 python (+1 duplicate) +wheel 0.46.3 python (+1 duplicate) whois 5.6.3-r0 apk xz-libs 5.8.1-r0 apk -zipp 3.19.2 python -zlib 1.3.1-r2 apk -zope-interface 8.1.1 python +zipp 3.23.0 python +zlib 1.3.2-r0 apk +zope-interface 8.3 python zstd-libs 1.5.7-r0 apk diff --git a/readme-vars.yml b/readme-vars.yml index edad8cc..27bde09 100644 --- a/readme-vars.yml +++ b/readme-vars.yml @@ -32,7 +32,7 @@ opt_param_usage_include_env: true opt_param_env_vars: - {env_var: "SUBDOMAINS", env_value: "www,", desc: "Subdomains you'd like the cert to cover (comma separated, no spaces) ie. `www,ftp,cloud`. For a wildcard cert, set this *exactly* to `wildcard` (wildcard cert is available via `dns` validation only)"} - {env_var: "CERTPROVIDER", env_value: "", desc: "Optionally define the cert provider. Set to `zerossl` for ZeroSSL certs (requires existing [ZeroSSL account](https://app.zerossl.com/signup) and the e-mail address entered in `EMAIL` env var). Otherwise defaults to Let's Encrypt."} - - {env_var: "DNSPLUGIN", env_value: "cloudflare", desc: "Required if `VALIDATION` is set to `dns`. Options are `acmedns`, `aliyun`, `azure`, `bunny`, `cloudflare`, `cpanel`, `desec`, `digitalocean`, `directadmin`, `dnsimple`, `dnsmadeeasy`, `dnspod`, `do`, `domeneshop`, `dreamhost`, `duckdns`, `dynu`, `freedns`, `gandi`, `gehirn`, `glesys`, `godaddy`, `google`, `he`, `hetzner`, `infomaniak`, `inwx`, `ionos`, `linode`, `loopia`, `luadns`, `namecheap`, `netcup`, `njalla`, `nsone`, `ovh`, `porkbun`, `rfc2136`, `route53`, `sakuracloud`, `standalone`, `transip`, and `vultr`. Also need to enter the credentials into the corresponding ini (or json for some plugins) file under `/config/dns-conf`."} + - {env_var: "DNSPLUGIN", env_value: "cloudflare", desc: "Required if `VALIDATION` is set to `dns`. Options are `acmedns`, `aliyun`, `azure`, `bunny`, `cloudflare`, `cpanel`, `desec`, `digitalocean`, `directadmin`, `dnsimple`, `dnsmadeeasy`, `dnspod`, `do`, `domeneshop`, `dreamhost`, `duckdns`, `dynu`, `freedns`, `gandi`, `gehirn`, `glesys`, `godaddy`, `google`, `he`, `hetzner`, `hetzner-cloud`, `infomaniak`, `inwx`, `ionos`, `linode`, `loopia`, `luadns`, `namecheap`, `netcup`, `njalla`, `nsone`, `ovh`, `porkbun`, `rfc2136`, `route53`, `sakuracloud`, `standalone`, `transip`, and `vultr`. Also need to enter the credentials into the corresponding ini (or json for some plugins) file under `/config/dns-conf`."} - {env_var: "PROPAGATION", env_value: "", desc: "Optionally override (in seconds) the default propagation time for the dns plugins."} - {env_var: "EMAIL", env_value: "", desc: "Optional e-mail address used for cert expiration notifications (Required for ZeroSSL)."} - {env_var: "ONLY_SUBDOMAINS", env_value: "false", desc: "If you wish to get certs only for certain subdomains, but not the main domain (main domain may be hosted on another machine and cannot be validated), set this to `true`"} @@ -177,7 +177,7 @@ init_diagram: | init-mods-end -> init-custom-files init-adduser -> init-device-perms base -> init-envfile - init-swag-samples -> init-fail2ban-config + init-require-url -> init-fail2ban-config init-os-end -> init-folders init-php -> init-keygen base -> init-migrations @@ -198,9 +198,10 @@ init_diagram: | init-folders -> init-samples init-custom-files -> init-services init-fail2ban-config -> init-swag-config - init-require-url -> init-swag-folders + init-permissions -> init-swag-folders init-swag-folders -> init-swag-samples init-permissions -> init-version-checks + init-swag-samples -> init-version-checks init-services -> svc-cron svc-cron -> legacy-services init-services -> svc-fail2ban @@ -218,6 +219,8 @@ init_diagram: | "swag:latest" <- Base Images # changelog changelogs: + - {date: "23.01.26:", desc: "Reorder init to fix proxy conf version checks."} + - {date: "21.12.25:", desc: "Add support for hetzner-cloud dns validation."} - {date: "04.11.25:", desc: "Switch default Gandi credentials from API Key to Token, allow DNS propagation time for Azure DNS plugin."} - {date: "18.07.25:", desc: "Rebase to Alpine 3.22 with PHP 8.4. Add QUIC support. Drop PHP bindings for mcrypt as it is no longer maintained."} - {date: "05.05.25:", desc: "Disable Certbot's built in log rotation."} diff --git a/root/defaults/dns-conf/hetzner-cloud.ini b/root/defaults/dns-conf/hetzner-cloud.ini new file mode 100644 index 0000000..dea6f6c --- /dev/null +++ b/root/defaults/dns-conf/hetzner-cloud.ini @@ -0,0 +1,2 @@ +# Hetzner Cloud API Token +dns_hetzner_cloud_api_token = your_api_token_here diff --git a/root/defaults/nginx/site-confs/default.conf.sample b/root/defaults/nginx/site-confs/default.conf.sample index e240496..4b6df44 100644 --- a/root/defaults/nginx/site-confs/default.conf.sample +++ b/root/defaults/nginx/site-confs/default.conf.sample @@ -1,4 +1,4 @@ -## Version 2025/07/18 - Changelog: https://github.com/linuxserver/docker-swag/commits/master/root/defaults/nginx/site-confs/default.conf.sample +## Version 2026/03/07 - Changelog: https://github.com/linuxserver/docker-swag/commits/master/root/defaults/nginx/site-confs/default.conf.sample # redirect all traffic to https server { @@ -36,6 +36,9 @@ server { # enable for Authentik (requires authentik-location.conf in the location block) #include /config/nginx/authentik-server.conf; + # enable for Tinyauth (requires tinyauth-location.conf in the location block) + #include /config/nginx/tinyauth-server.conf; + location / { # enable for basic auth #auth_basic "Restricted"; @@ -50,6 +53,9 @@ server { # enable for Authentik (requires authentik-server.conf in the server block) #include /config/nginx/authentik-location.conf; + # enable for Tinyauth (requires tinyauth-server.conf in the server block) + #include /config/nginx/tinyauth-location.conf; + try_files $uri $uri/ /index.html /index.htm /index.php$is_args$args; } diff --git a/root/etc/s6-overlay/s6-rc.d/init-certbot-config/run b/root/etc/s6-overlay/s6-rc.d/init-certbot-config/run index 31bd3d6..5e34aaa 100755 --- a/root/etc/s6-overlay/s6-rc.d/init-certbot-config/run +++ b/root/etc/s6-overlay/s6-rc.d/init-certbot-config/run @@ -168,9 +168,9 @@ fi rm -rf /config/keys/letsencrypt if [[ "${ONLY_SUBDOMAINS}" = "true" ]] && [[ ! "${SUBDOMAINS}" = "wildcard" ]]; then DOMAIN="$(echo "${SUBDOMAINS}" | tr ',' ' ' | awk '{print $1}').${URL}" - ln -s /config/etc/letsencrypt/live/"${DOMAIN}" /config/keys/letsencrypt + ln -s ../etc/letsencrypt/live/"${DOMAIN}" /config/keys/letsencrypt else - ln -s /config/etc/letsencrypt/live/"${URL}" /config/keys/letsencrypt + ln -s ../etc/letsencrypt/live/"${URL}" /config/keys/letsencrypt fi # cleanup unused csr and keys folders diff --git a/root/etc/s6-overlay/s6-rc.d/init-swag-folders/dependencies.d/init-require-url b/root/etc/s6-overlay/s6-rc.d/init-fail2ban-config/dependencies.d/init-require-url similarity index 100% rename from root/etc/s6-overlay/s6-rc.d/init-swag-folders/dependencies.d/init-require-url rename to root/etc/s6-overlay/s6-rc.d/init-fail2ban-config/dependencies.d/init-require-url diff --git a/root/etc/s6-overlay/s6-rc.d/init-fail2ban-config/dependencies.d/init-swag-samples b/root/etc/s6-overlay/s6-rc.d/init-swag-folders/dependencies.d/init-permissions similarity index 100% rename from root/etc/s6-overlay/s6-rc.d/init-fail2ban-config/dependencies.d/init-swag-samples rename to root/etc/s6-overlay/s6-rc.d/init-swag-folders/dependencies.d/init-permissions diff --git a/root/etc/s6-overlay/s6-rc.d/init-version-checks/dependencies.d/init-swag-samples b/root/etc/s6-overlay/s6-rc.d/init-version-checks/dependencies.d/init-swag-samples new file mode 100644 index 0000000..e69de29