Compare commits

...

129 Commits

Author SHA1 Message Date
Adam 08592fdb75 Merge pull request #624 from EVOTk/patch-1
Update ovh.ini
2026-08-16 19:12:24 +01:00
LinuxServer-CI f86ef34abd Bot Updating Package Versions 2026-08-16 15:24:50 +00:00
LinuxServer-CI 478c1fa964 Bot Updating Templated Files 2026-08-16 15:17:05 +00:00
LinuxServer-CI 0b43278151 Bot Updating Templated Files 2026-08-16 15:11:31 +00:00
Eric Nemchik 21237325ee Merge pull request #622 from linuxserver/rebase-3.24
Rebase to 3.24
2026-08-16 10:08:03 -05:00
LinuxServer-CI 8bccad2000 Bot Updating Package Versions 2026-08-15 03:44:37 +00:00
EVO 9bd4e3771e Update ovh.ini
Update the broken link
2026-08-08 19:55:04 +02:00
LinuxServer-CI 55a8c4fa88 Bot Updating Package Versions 2026-08-08 04:15:45 +00:00
LinuxServer-CI 733910a7a7 Bot Updating Package Versions 2026-08-01 06:00:50 +00:00
LinuxServer-CI 55a01c005c Bot Updating Package Versions 2026-07-25 05:48:28 +00:00
Eric Nemchik fb016e60ee Remove unnecessary PHP extensions from Dockerfiles
Signed-off-by: Eric Nemchik <eric@nemchik.com>
2026-07-19 21:13:30 -05:00
Eric Nemchik 415fbce955 Rebase to 3.24
Signed-off-by: Eric Nemchik <eric@nemchik.com>
2026-07-19 20:02:36 -05:00
LinuxServer-CI bc02502e97 Bot Updating Package Versions 2026-07-18 05:32:40 +00:00
LinuxServer-CI 2c22ce9573 Bot Updating Package Versions 2026-07-15 18:14:31 +00:00
Eric Nemchik 0a34712336 Merge pull request #594 from jonathanmajh/patch-1
Update tinyauth-location.conf.sample for Forward Auth
2026-07-11 21:48:18 -05:00
Eric Nemchik 4e7e4f7fee Merge branch 'master' into patch-1 2026-07-11 21:07:22 -05:00
Jonathan Ma e39c6487f7 Update root/defaults/nginx/tinyauth-location.conf.sample
Co-authored-by: Eric Nemchik <eric@nemchik.com>
2026-07-11 12:58:10 -04:00
LinuxServer-CI 493982d27e Bot Updating Templated Files 2026-07-10 22:15:07 +00:00
LinuxServer-CI 1e2b94980c Bot Updating Templated Files 2026-07-10 22:13:20 +00:00
Eric Nemchik b3185a5eff Merge pull request #607 from Sausageroll2077/master
Add CERT_PROFILE support and improve ARI renewal scheduling
2026-07-10 17:11:32 -05:00
Sausageroll2077 e857f808b0 Add CERT_PROFILE support and simplify renewal scheduling
Add CERT_PROFILE env var for Let's Encrypt cert profiles. Run certbot
twice daily via a cron entry with a random delay instead of the previous
sed-based cron randomization. Update changelog.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-11 00:09:29 +02:00
LinuxServer-CI 62d5e73cbb Bot Updating Package Versions 2026-07-10 21:57:02 +00:00
LinuxServer-CI 83ab984b17 Bot Updating Templated Files 2026-07-10 21:52:10 +00:00
Eric Nemchik 1a8290dec1 Merge pull request #618 from Sausageroll2077/add-dnsplugin-mijn-host
Add support for mijn.host DNS plugin
2026-07-10 16:50:25 -05:00
Sausageroll2077 057bbb5930 Merge branch 'master' into add-dnsplugin-mijn-host 2026-07-08 19:20:20 +02:00
LinuxServer-CI d6c053dd22 Bot Updating Package Versions 2026-07-04 06:25:57 +00:00
Sausageroll2077 883a216247 Merge branch 'master' into add-dnsplugin-mijn-host 2026-06-29 17:53:31 +02:00
LinuxServer-CI a57ebf0399 Bot Updating Package Versions 2026-06-27 06:34:42 +00:00
Sausageroll2077 37b074c528 Merge branch 'master' into add-dnsplugin-mijn-host 2026-06-26 15:52:01 +02:00
LinuxServer-CI d86d2dbb59 Bot Updating Package Versions 2026-06-25 20:47:23 +00:00
Sausageroll2077 25258a2f90 Merge branch 'master' into add-dnsplugin-mijn-host 2026-06-21 07:17:39 +02:00
LinuxServer-CI 88b7c77e02 Bot Updating Package Versions 2026-06-20 07:05:54 +00:00
Sausageroll2077 2cea93f9b1 Add support for mijn.host DNS plugin
Adds certbot-dns-mijn-host as a DNSPLUGIN option (mijn-host), including
the plugin in both Dockerfiles, a credentials template under
dns-conf, and the DNSPLUGIN list in readme-vars.yml.

Closes #606

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-19 20:21:49 +02:00
LinuxServer-CI a9d1f7f0ee Bot Updating Package Versions 2026-06-13 07:04:48 +00:00
LinuxServer-CI d3fe405b46 Bot Updating Package Versions 2026-06-06 06:35:32 +00:00
LinuxServer-CI 32c26223dd Bot Updating Package Versions 2026-06-01 16:09:07 +00:00
aptalca 60161a3baf Merge pull request #613 from linuxserver/cert-check
remove obsolete old cert check logic
2026-06-01 12:02:02 -04:00
aptalca 321837be0d remove obsolete old cert check logic 2026-06-01 11:04:38 -04:00
LinuxServer-CI c371973f5f Bot Updating Package Versions 2026-05-30 06:29:09 +00:00
LinuxServer-CI bc18a403ba Bot Updating Package Versions 2026-05-23 06:17:54 +00:00
LinuxServer-CI b104a66e06 Bot Updating Package Versions 2026-05-16 06:00:50 +00:00
LinuxServer-CI 80bc4b4243 Bot Updating Package Versions 2026-05-14 20:15:20 +00:00
LinuxServer-CI 7cf7838a87 Bot Updating Package Versions 2026-05-14 19:54:29 +00:00
LinuxServer-CI 0cb2c16f7d Bot Updating Package Versions 2026-05-11 17:29:24 +00:00
LinuxServer-CI 36129452e8 Bot Updating Package Versions 2026-05-09 05:55:56 +00:00
LinuxServer-CI bb2b29d9c1 Bot Updating Templated Files 2026-05-09 05:51:19 +00:00
LinuxServer-CI b7ea5c43ec Bot Updating Package Versions 2026-05-02 05:43:26 +00:00
LinuxServer-CI 8fbf8ab449 Bot Updating Package Versions 2026-04-25 05:17:58 +00:00
Jonathan Ma 6b1745980a Merge branch 'master' into patch-1 2026-04-23 08:56:57 -04:00
LinuxServer-CI 9c5ae4f09a Bot Updating Package Versions 2026-04-18 05:12:40 +00:00
LinuxServer-CI 321c7f3295 Bot Updating Package Versions 2026-04-11 05:00:44 +00:00
LinuxServer-CI 005a68591d Bot Updating Package Versions 2026-04-07 19:22:47 +00:00
LinuxServer-CI 01bfb62124 Bot Updating Templated Files 2026-04-07 19:18:28 +00:00
LinuxServer-CI 04ad8386bf Bot Updating Package Versions 2026-04-04 04:55:57 +00:00
LinuxServer-CI b409073642 Bot Updating Package Versions 2026-03-28 04:58:53 +00:00
LinuxServer-CI 1c8a8d004e Bot Updating Package Versions 2026-03-21 04:42:40 +00:00
LinuxServer-CI 9235e504a1 Bot Updating Package Versions 2026-03-14 04:48:10 +00:00
LinuxServer-CI ef520118f5 Bot Updating Package Versions 2026-03-10 19:42:05 +00:00
Adam 4a4e84d26b Merge pull request #602 from linuxserver/tinyauth-fix
Add missing tinyauth blocks to default conf
2026-03-07 14:05:10 +00:00
thespad 8c002e6c56 Add missing tinyauth blocks to default conf 2026-03-07 13:57:15 +00:00
LinuxServer-CI ea840fbfbc Bot Updating Package Versions 2026-03-07 04:26:21 +00:00
LinuxServer-CI 42ba97e46a Bot Updating Package Versions
Mark stale issues and pull requests / stale (push) Failing after 0s
External Trigger Scheduler / external-trigger-scheduler (push) Failing after 10s
2026-02-28 04:20:29 +00:00
LinuxServer-CI b4b73022db Bot Updating Package Versions
External Trigger Scheduler / external-trigger-scheduler (push) Has been cancelled
Mark stale issues and pull requests / stale (push) Has been cancelled
Package Trigger Scheduler / package-trigger-scheduler (push) Has been cancelled
2026-02-21 04:42:02 +00:00
LinuxServer-CI 9d5ebb6a7a Bot Updating Package Versions
External Trigger Scheduler / external-trigger-scheduler (push) Has been cancelled
Mark stale issues and pull requests / stale (push) Has been cancelled
Package Trigger Scheduler / package-trigger-scheduler (push) Has been cancelled
2026-02-14 04:50:10 +00:00
LinuxServer-CI 7ad019e68d Bot Updating Templated Files 2026-02-14 04:45:56 +00:00
LinuxServer-CI 59ef2df680 Bot Updating Templated Files 2026-02-14 04:44:20 +00:00
LinuxServer-CI db874b2c0f Bot Updating Package Versions
External Trigger Scheduler / external-trigger-scheduler (push) Has been cancelled
Mark stale issues and pull requests / stale (push) Has been cancelled
Package Trigger Scheduler / package-trigger-scheduler (push) Has been cancelled
2026-02-10 05:08:06 +00:00
LinuxServer-CI 6182a75998 Bot Updating Package Versions
External Trigger Scheduler / external-trigger-scheduler (push) Has been cancelled
Mark stale issues and pull requests / stale (push) Has been cancelled
2026-02-07 04:43:17 +00:00
LinuxServer-CI 145c5d84f6 Bot Updating Package Versions
External Trigger Scheduler / external-trigger-scheduler (push) Has been cancelled
Package Trigger Scheduler / package-trigger-scheduler (push) Has been cancelled
2026-02-06 14:17:14 +00:00
LinuxServer-CI 1039f2a04c Bot Updating Package Versions
External Trigger Scheduler / external-trigger-scheduler (push) Has been cancelled
Mark stale issues and pull requests / stale (push) Has been cancelled
2026-02-03 19:48:04 +00:00
LinuxServer-CI 156e3ac160 Bot Updating Package Versions
External Trigger Scheduler / external-trigger-scheduler (push) Has been cancelled
Mark stale issues and pull requests / stale (push) Has been cancelled
2026-01-31 04:29:28 +00:00
LinuxServer-CI e649bd71da Bot Updating Package Versions
External Trigger Scheduler / external-trigger-scheduler (push) Has been cancelled
Mark stale issues and pull requests / stale (push) Has been cancelled
Package Trigger Scheduler / package-trigger-scheduler (push) Has been cancelled
2026-01-26 00:38:36 +00:00
LinuxServer-CI b54c263769 Bot Updating Templated Files 2026-01-26 00:34:15 +00:00
aptalca 7b11fb9643 Merge pull request #600 from linuxserver/sample-race
reorder init to make sure samples are copied before version checks
2026-01-25 19:32:30 -05:00
LinuxServer-CI 72d187c734 Bot Updating Package Versions
External Trigger Scheduler / external-trigger-scheduler (push) Has been cancelled
Mark stale issues and pull requests / stale (push) Has been cancelled
2026-01-24 04:03:28 +00:00
aptalca b6752babcd sandwich swag folder creation and sample copying between nginx base's permissions and version checks to make sure samples are there when the check happens 2026-01-23 21:37:09 -05:00
Adam 6f38cebe04 Merge pull request #597 from hadjilucasL/patch-1
External Trigger Scheduler / external-trigger-scheduler (push) Has been cancelled
Mark stale issues and pull requests / stale (push) Has been cancelled
Package Trigger Scheduler / package-trigger-scheduler (push) Has been cancelled
2026-01-18 10:04:48 +00:00
LinuxServer-CI 62b3a02aed Bot Updating Package Versions
External Trigger Scheduler / external-trigger-scheduler (push) Has been cancelled
Mark stale issues and pull requests / stale (push) Has been cancelled
2026-01-17 03:59:34 +00:00
LinuxServer-CI 2deac3dac6 Bot Updating Package Versions
External Trigger Scheduler / external-trigger-scheduler (push) Has been cancelled
Mark stale issues and pull requests / stale (push) Has been cancelled
Package Trigger Scheduler / package-trigger-scheduler (push) Has been cancelled
2026-01-13 11:05:27 +00:00
LinuxServer-CI 48cbb269cc Bot Updating Templated Files 2026-01-13 11:00:44 +00:00
Adam 8489cde7c0 Merge pull request #596 from CaptivatingCat/hetzner-cloud 2026-01-13 10:59:01 +00:00
CaptivatingCat a120a68aae Merge branch 'master' into hetzner-cloud 2026-01-11 14:55:29 +01:00
LinuxServer-CI 1674ff4509 Bot Updating Package Versions
External Trigger Scheduler / external-trigger-scheduler (push) Has been cancelled
Mark stale issues and pull requests / stale (push) Has been cancelled
2026-01-10 04:00:48 +00:00
CaptivatingCat 52707530e2 Merge branch 'master' into hetzner-cloud 2026-01-07 23:30:22 +01:00
CaptivatingCat cbf78b31bb Fix missing quote in readme-vars.yml 2026-01-07 23:29:05 +01:00
Lucas Hadjilucas 2fc01f4e21 Merge branch 'master' into patch-1 2026-01-04 21:36:59 +02:00
LinuxServer-CI 5491278c13 Bot Updating Package Versions
External Trigger Scheduler / external-trigger-scheduler (push) Has been cancelled
Mark stale issues and pull requests / stale (push) Has been cancelled
Package Trigger Scheduler / package-trigger-scheduler (push) Has been cancelled
2026-01-03 03:59:18 +00:00
CaptivatingCat 4a7daa06ad Merge branch 'master' into hetzner-cloud 2025-12-31 22:39:27 +01:00
Lucas Hadjilucas 77dc5ff352 Merge branch 'master' into patch-1 2025-12-27 23:14:14 +02:00
LinuxServer-CI e834e13141 Bot Updating Package Versions
External Trigger Scheduler / external-trigger-scheduler (push) Has been cancelled
Mark stale issues and pull requests / stale (push) Has been cancelled
Package Trigger Scheduler / package-trigger-scheduler (push) Has been cancelled
2025-12-27 03:59:05 +00:00
Lucas Hadjilucas 0ab1a76dae Restore symlink paths for letsencrypt keys
To solve #549
2025-12-23 22:46:59 +02:00
CaptivatingCat 8b8b491df3 add support for hetzner-cloud dns validation 2025-12-21 00:55:30 +01:00
LinuxServer-CI 7f080d8564 Bot Updating Package Versions
External Trigger Scheduler / external-trigger-scheduler (push) Has been cancelled
Mark stale issues and pull requests / stale (push) Has been cancelled
Package Trigger Scheduler / package-trigger-scheduler (push) Has been cancelled
2025-12-20 03:52:51 +00:00
Jonathan Ma 3ffa4aaa77 Update tinyauth-location.conf.sample for Forward Auth
Updated version information and added headers for Forward Auth in the tinyauth NGINX configuration.
2025-12-17 15:28:03 -05:00
LinuxServer-CI bb730cbc72 Bot Updating Package Versions
External Trigger Scheduler / external-trigger-scheduler (push) Has been cancelled
Mark stale issues and pull requests / stale (push) Has been cancelled
Package Trigger Scheduler / package-trigger-scheduler (push) Has been cancelled
2025-12-13 03:53:30 +00:00
LinuxServer-CI 6b609ad159 Bot Updating Package Versions
External Trigger Scheduler / external-trigger-scheduler (push) Has been cancelled
Mark stale issues and pull requests / stale (push) Has been cancelled
Package Trigger Scheduler / package-trigger-scheduler (push) Has been cancelled
2025-12-10 18:35:07 +00:00
LinuxServer-CI f7a31bb18e Bot Updating Package Versions
External Trigger Scheduler / external-trigger-scheduler (push) Has been cancelled
Mark stale issues and pull requests / stale (push) Has been cancelled
2025-12-06 03:45:58 +00:00
LinuxServer-CI 01a5c0123e Bot Updating Package Versions
External Trigger Scheduler / external-trigger-scheduler (push) Has been cancelled
Mark stale issues and pull requests / stale (push) Has been cancelled
Package Trigger Scheduler / package-trigger-scheduler (push) Has been cancelled
2025-12-03 21:23:08 +00:00
LinuxServer-CI 012b4ac68f Bot Updating Package Versions
External Trigger Scheduler / external-trigger-scheduler (push) Has been cancelled
Mark stale issues and pull requests / stale (push) Has been cancelled
2025-11-29 03:49:15 +00:00
LinuxServer-CI 8961b7e923 Bot Updating Package Versions
External Trigger Scheduler / external-trigger-scheduler (push) Has been cancelled
Mark stale issues and pull requests / stale (push) Has been cancelled
Package Trigger Scheduler / package-trigger-scheduler (push) Has been cancelled
2025-11-22 03:43:45 +00:00
LinuxServer-CI 1e3524f927 Bot Updating Templated Files 2025-11-22 03:39:13 +00:00
LinuxServer-CI a2f969a62e Bot Updating Package Versions
External Trigger Scheduler / external-trigger-scheduler (push) Has been cancelled
Mark stale issues and pull requests / stale (push) Has been cancelled
Package Trigger Scheduler / package-trigger-scheduler (push) Has been cancelled
2025-11-15 03:43:31 +00:00
LinuxServer-CI caaaccb0b3 Bot Updating Package Versions
External Trigger Scheduler / external-trigger-scheduler (push) Has been cancelled
Mark stale issues and pull requests / stale (push) Has been cancelled
Package Trigger Scheduler / package-trigger-scheduler (push) Has been cancelled
2025-11-08 03:39:30 +00:00
LinuxServer-CI ae11ca79a0 Bot Updating Templated Files
External Trigger Scheduler / external-trigger-scheduler (push) Has been cancelled
Mark stale issues and pull requests / stale (push) Has been cancelled
Package Trigger Scheduler / package-trigger-scheduler (push) Has been cancelled
2025-11-05 12:06:21 +00:00
driz 9d7c0d6239 Merge pull request #590 from linuxserver/nemchik-patch-1
Update changelog for Gandi credentials update
2025-11-05 07:04:42 -05:00
Eric Nemchik eb151ebd19 Update changelog for Gandi credentials update
Updated the changelog to reflect changes in Gandi credentials and Azure DNS propagation.
2025-11-04 21:22:08 -06:00
Eric Nemchik 4076c6b012 Merge pull request #577 from jeanrobertjs/patch-1
External Trigger Scheduler / external-trigger-scheduler (push) Has been cancelled
2025-11-04 21:18:42 -06:00
LinuxServer-CI 8437debed5 Bot Updating Package Versions 2025-11-05 03:16:31 +00:00
Eric Nemchik 0f177af593 Merge branch 'master' into patch-1 2025-11-04 20:43:59 -06:00
Eric Nemchik 23dd0531f1 Merge pull request #562 from neoteq-it/master 2025-11-04 20:41:38 -06:00
LinuxServer-CI 56d0503cb3 Bot Updating Package Versions
External Trigger Scheduler / external-trigger-scheduler (push) Has been cancelled
Mark stale issues and pull requests / stale (push) Has been cancelled
2025-11-01 03:46:36 +00:00
LinuxServer-CI 9397e9c70f Bot Updating Package Versions
External Trigger Scheduler / external-trigger-scheduler (push) Has been cancelled
Mark stale issues and pull requests / stale (push) Has been cancelled
Package Trigger Scheduler / package-trigger-scheduler (push) Has been cancelled
2025-10-25 03:41:22 +00:00
LinuxServer-CI e87649ffcd Bot Updating Templated Files 2025-10-25 03:37:01 +00:00
LinuxServer-CI e11a8ded00 Bot Updating Package Versions
External Trigger Scheduler / external-trigger-scheduler (push) Has been cancelled
Mark stale issues and pull requests / stale (push) Has been cancelled
Package Trigger Scheduler / package-trigger-scheduler (push) Has been cancelled
2025-10-18 03:32:52 +00:00
LinuxServer-CI 576de0400c Bot Updating Package Versions
External Trigger Scheduler / external-trigger-scheduler (push) Has been cancelled
Mark stale issues and pull requests / stale (push) Has been cancelled
Package Trigger Scheduler / package-trigger-scheduler (push) Has been cancelled
2025-10-11 03:31:40 +00:00
LinuxServer-CI ad2d99029a Bot Updating Package Versions
External Trigger Scheduler / external-trigger-scheduler (push) Has been cancelled
Mark stale issues and pull requests / stale (push) Has been cancelled
Package Trigger Scheduler / package-trigger-scheduler (push) Has been cancelled
2025-10-07 18:32:33 +00:00
LinuxServer-CI b8d0c422ab Bot Updating Package Versions
External Trigger Scheduler / external-trigger-scheduler (push) Has been cancelled
Mark stale issues and pull requests / stale (push) Has been cancelled
2025-10-04 03:29:29 +00:00
LinuxServer-CI 07c7399089 Bot Updating Package Versions
External Trigger Scheduler / external-trigger-scheduler (push) Has been cancelled
Mark stale issues and pull requests / stale (push) Has been cancelled
Package Trigger Scheduler / package-trigger-scheduler (push) Has been cancelled
2025-09-27 03:32:32 +00:00
LinuxServer-CI 2d9590691c Bot Updating Package Versions
External Trigger Scheduler / external-trigger-scheduler (push) Has been cancelled
Mark stale issues and pull requests / stale (push) Has been cancelled
Package Trigger Scheduler / package-trigger-scheduler (push) Has been cancelled
2025-09-20 03:32:41 +00:00
LinuxServer-CI 72e5347c3b Bot Updating Package Versions
External Trigger Scheduler / external-trigger-scheduler (push) Has been cancelled
Mark stale issues and pull requests / stale (push) Has been cancelled
Package Trigger Scheduler / package-trigger-scheduler (push) Has been cancelled
2025-09-13 03:26:16 +00:00
LinuxServer-CI be7016bcc1 Bot Updating Package Versions
External Trigger Scheduler / external-trigger-scheduler (push) Has been cancelled
Mark stale issues and pull requests / stale (push) Has been cancelled
Package Trigger Scheduler / package-trigger-scheduler (push) Has been cancelled
2025-09-06 03:31:28 +00:00
LinuxServer-CI ccd2464a26 Bot Updating Package Versions
External Trigger Scheduler / external-trigger-scheduler (push) Has been cancelled
Mark stale issues and pull requests / stale (push) Has been cancelled
Package Trigger Scheduler / package-trigger-scheduler (push) Has been cancelled
2025-09-02 17:20:15 +00:00
LinuxServer-CI fb4ba0deb0 Bot Updating Package Versions
Mark stale issues and pull requests / stale (push) Has been cancelled
2025-08-30 03:33:52 +00:00
LinuxServer-CI 7d8332e624 Bot Updating Package Versions
Package Trigger Scheduler / package-trigger-scheduler (push) Has been cancelled
2025-08-23 03:39:14 +00:00
Jean-Robert JS 0e19ad9d0f Merge branch 'master' into patch-1 2025-08-19 12:13:04 +02:00
Jean-Robert JS f491b59335 Merge branch 'master' into patch-1 2025-07-31 23:30:29 +02:00
Jean-Robert JS d602e9bccf Update gandi.ini 2025-07-24 10:47:17 +02:00
Jean-Robert JS 284a8c66f9 Reflects the depreciation of the API key in favor of the personal access token (PAT) 2025-07-23 14:03:33 +02:00
Jean Stickelmann a5f1da0bcf Update run - Azure Supports propagation 2025-04-24 10:27:16 +02:00
18 changed files with 708 additions and 594 deletions
+32 -32
View File
@@ -1,6 +1,6 @@
# syntax=docker/dockerfile:1 # syntax=docker/dockerfile:1
FROM ghcr.io/linuxserver/baseimage-alpine-nginx:3.22 FROM ghcr.io/linuxserver/baseimage-alpine-nginx:3.24
# set version label # set version label
ARG BUILD_DATE ARG BUILD_DATE
@@ -49,36 +49,34 @@ RUN \
nginx-mod-stream \ nginx-mod-stream \
nginx-mod-stream-geoip2 \ nginx-mod-stream-geoip2 \
nginx-vim \ nginx-vim \
php84-bcmath \ php85-bcmath \
php84-bz2 \ php85-bz2 \
php84-dom \ php85-dom \
php84-exif \ php85-exif \
php84-ftp \ php85-ftp \
php84-gd \ php85-gd \
php84-gmp \ php85-gmp \
php84-imap \ php85-intl \
php84-intl \ php85-ldap \
php84-ldap \ php85-mysqli \
php84-mysqli \ php85-mysqlnd \
php84-mysqlnd \ php85-pdo_mysql \
php84-opcache \ php85-pdo_odbc \
php84-pdo_mysql \ php85-pdo_pgsql \
php84-pdo_odbc \ php85-pdo_sqlite \
php84-pdo_pgsql \ php85-pear \
php84-pdo_sqlite \ php85-pecl-apcu \
php84-pear \ php85-pecl-memcached \
php84-pecl-apcu \ php85-pecl-redis \
php84-pecl-memcached \ php85-pgsql \
php84-pecl-redis \ php85-posix \
php84-pgsql \ php85-soap \
php84-posix \ php85-sockets \
php84-soap \ php85-sodium \
php84-sockets \ php85-sqlite3 \
php84-sodium \ php85-tokenizer \
php84-sqlite3 \ php85-xmlreader \
php84-tokenizer \ php85-xsl \
php84-xmlreader \
php84-xsl \
whois && \ whois && \
echo "**** install certbot plugins ****" && \ echo "**** install certbot plugins ****" && \
if [ -z ${CERTBOT_VERSION+x} ]; then \ if [ -z ${CERTBOT_VERSION+x} ]; then \
@@ -88,7 +86,7 @@ RUN \
pip install -U --no-cache-dir \ pip install -U --no-cache-dir \
pip \ pip \
wheel && \ wheel && \
pip install -U --no-cache-dir --find-links https://wheel-index.linuxserver.io/alpine-3.22/ \ pip install -U --no-cache-dir --find-links https://wheel-index.linuxserver.io/alpine-3.24/ \
certbot==${CERTBOT_VERSION} \ certbot==${CERTBOT_VERSION} \
certbot-dns-acmedns \ certbot-dns-acmedns \
certbot-dns-aliyun \ certbot-dns-aliyun \
@@ -114,12 +112,14 @@ RUN \
certbot-dns-google \ certbot-dns-google \
certbot-dns-he \ certbot-dns-he \
certbot-dns-hetzner \ certbot-dns-hetzner \
certbot-dns-hetzner-cloud \
certbot-dns-infomaniak \ certbot-dns-infomaniak \
certbot-dns-inwx \ certbot-dns-inwx \
certbot-dns-ionos \ certbot-dns-ionos \
certbot-dns-linode \ certbot-dns-linode \
certbot-dns-loopia \ certbot-dns-loopia \
certbot-dns-luadns \ certbot-dns-luadns \
certbot-dns-mijn-host \
certbot-dns-namecheap \ certbot-dns-namecheap \
certbot-dns-netcup \ certbot-dns-netcup \
certbot-dns-njalla \ certbot-dns-njalla \
+32 -32
View File
@@ -1,6 +1,6 @@
# syntax=docker/dockerfile:1 # syntax=docker/dockerfile:1
FROM ghcr.io/linuxserver/baseimage-alpine-nginx:arm64v8-3.22 FROM ghcr.io/linuxserver/baseimage-alpine-nginx:arm64v8-3.24
# set version label # set version label
ARG BUILD_DATE ARG BUILD_DATE
@@ -49,36 +49,34 @@ RUN \
nginx-mod-stream \ nginx-mod-stream \
nginx-mod-stream-geoip2 \ nginx-mod-stream-geoip2 \
nginx-vim \ nginx-vim \
php84-bcmath \ php85-bcmath \
php84-bz2 \ php85-bz2 \
php84-dom \ php85-dom \
php84-exif \ php85-exif \
php84-ftp \ php85-ftp \
php84-gd \ php85-gd \
php84-gmp \ php85-gmp \
php84-imap \ php85-intl \
php84-intl \ php85-ldap \
php84-ldap \ php85-mysqli \
php84-mysqli \ php85-mysqlnd \
php84-mysqlnd \ php85-pdo_mysql \
php84-opcache \ php85-pdo_odbc \
php84-pdo_mysql \ php85-pdo_pgsql \
php84-pdo_odbc \ php85-pdo_sqlite \
php84-pdo_pgsql \ php85-pear \
php84-pdo_sqlite \ php85-pecl-apcu \
php84-pear \ php85-pecl-memcached \
php84-pecl-apcu \ php85-pecl-redis \
php84-pecl-memcached \ php85-pgsql \
php84-pecl-redis \ php85-posix \
php84-pgsql \ php85-soap \
php84-posix \ php85-sockets \
php84-soap \ php85-sodium \
php84-sockets \ php85-sqlite3 \
php84-sodium \ php85-tokenizer \
php84-sqlite3 \ php85-xmlreader \
php84-tokenizer \ php85-xsl \
php84-xmlreader \
php84-xsl \
whois && \ whois && \
echo "**** install certbot plugins ****" && \ echo "**** install certbot plugins ****" && \
if [ -z ${CERTBOT_VERSION+x} ]; then \ if [ -z ${CERTBOT_VERSION+x} ]; then \
@@ -88,7 +86,7 @@ RUN \
pip install -U --no-cache-dir \ pip install -U --no-cache-dir \
pip \ pip \
wheel && \ wheel && \
pip install -U --no-cache-dir --find-links https://wheel-index.linuxserver.io/alpine-3.22/ \ pip install -U --no-cache-dir --find-links https://wheel-index.linuxserver.io/alpine-3.24/ \
certbot==${CERTBOT_VERSION} \ certbot==${CERTBOT_VERSION} \
certbot-dns-acmedns \ certbot-dns-acmedns \
certbot-dns-aliyun \ certbot-dns-aliyun \
@@ -114,12 +112,14 @@ RUN \
certbot-dns-google \ certbot-dns-google \
certbot-dns-he \ certbot-dns-he \
certbot-dns-hetzner \ certbot-dns-hetzner \
certbot-dns-hetzner-cloud \
certbot-dns-infomaniak \ certbot-dns-infomaniak \
certbot-dns-inwx \ certbot-dns-inwx \
certbot-dns-ionos \ certbot-dns-ionos \
certbot-dns-linode \ certbot-dns-linode \
certbot-dns-loopia \ certbot-dns-loopia \
certbot-dns-luadns \ certbot-dns-luadns \
certbot-dns-mijn-host \
certbot-dns-namecheap \ certbot-dns-namecheap \
certbot-dns-netcup \ certbot-dns-netcup \
certbot-dns-njalla \ certbot-dns-njalla \
Vendored
+179 -123
View File
@@ -76,6 +76,8 @@ pipeline {
''' '''
script{ script{
env.EXIT_STATUS = '' env.EXIT_STATUS = ''
env.CI_TEST_ATTEMPTED = ''
env.PUSH_ATTEMPTED = ''
env.LS_RELEASE = sh( env.LS_RELEASE = sh(
script: '''docker run --rm quay.io/skopeo/stable:v1 inspect docker://ghcr.io/${LS_USER}/${CONTAINER_NAME}:latest 2>/dev/null | jq -r '.Labels.build_version' | awk '{print $3}' | grep '\\-ls' || : ''', script: '''docker run --rm quay.io/skopeo/stable:v1 inspect docker://ghcr.io/${LS_USER}/${CONTAINER_NAME}:latest 2>/dev/null | jq -r '.Labels.build_version' | awk '{print $3}' | grep '\\-ls' || : ''',
returnStdout: true).trim() returnStdout: true).trim()
@@ -208,6 +210,7 @@ pipeline {
env.META_TAG = env.EXT_RELEASE_CLEAN + '-ls' + env.LS_TAG_NUMBER env.META_TAG = env.EXT_RELEASE_CLEAN + '-ls' + env.LS_TAG_NUMBER
env.EXT_RELEASE_TAG = 'version-' + env.EXT_RELEASE_CLEAN env.EXT_RELEASE_TAG = 'version-' + env.EXT_RELEASE_CLEAN
env.BUILDCACHE = 'docker.io/lsiodev/buildcache,registry.gitlab.com/linuxserver.io/docker-jenkins-builder/lsiodev-buildcache,ghcr.io/linuxserver/lsiodev-buildcache,quay.io/linuxserver.io/lsiodev-buildcache' env.BUILDCACHE = 'docker.io/lsiodev/buildcache,registry.gitlab.com/linuxserver.io/docker-jenkins-builder/lsiodev-buildcache,ghcr.io/linuxserver/lsiodev-buildcache,quay.io/linuxserver.io/lsiodev-buildcache'
env.CITEST_IMAGETAG = 'latest'
} }
} }
} }
@@ -233,6 +236,7 @@ pipeline {
env.EXT_RELEASE_TAG = 'version-' + env.EXT_RELEASE_CLEAN env.EXT_RELEASE_TAG = 'version-' + env.EXT_RELEASE_CLEAN
env.DOCKERHUB_LINK = 'https://hub.docker.com/r/' + env.DEV_DOCKERHUB_IMAGE + '/tags/' env.DOCKERHUB_LINK = 'https://hub.docker.com/r/' + env.DEV_DOCKERHUB_IMAGE + '/tags/'
env.BUILDCACHE = 'docker.io/lsiodev/buildcache,registry.gitlab.com/linuxserver.io/docker-jenkins-builder/lsiodev-buildcache,ghcr.io/linuxserver/lsiodev-buildcache,quay.io/linuxserver.io/lsiodev-buildcache' env.BUILDCACHE = 'docker.io/lsiodev/buildcache,registry.gitlab.com/linuxserver.io/docker-jenkins-builder/lsiodev-buildcache,ghcr.io/linuxserver/lsiodev-buildcache,quay.io/linuxserver.io/lsiodev-buildcache'
env.CITEST_IMAGETAG = 'develop'
} }
} }
} }
@@ -258,6 +262,7 @@ pipeline {
env.CODE_URL = 'https://github.com/' + env.LS_USER + '/' + env.LS_REPO + '/pull/' + env.PULL_REQUEST env.CODE_URL = 'https://github.com/' + env.LS_USER + '/' + env.LS_REPO + '/pull/' + env.PULL_REQUEST
env.DOCKERHUB_LINK = 'https://hub.docker.com/r/' + env.PR_DOCKERHUB_IMAGE + '/tags/' env.DOCKERHUB_LINK = 'https://hub.docker.com/r/' + env.PR_DOCKERHUB_IMAGE + '/tags/'
env.BUILDCACHE = 'docker.io/lsiodev/buildcache,registry.gitlab.com/linuxserver.io/docker-jenkins-builder/lsiodev-buildcache,ghcr.io/linuxserver/lsiodev-buildcache,quay.io/linuxserver.io/lsiodev-buildcache' env.BUILDCACHE = 'docker.io/lsiodev/buildcache,registry.gitlab.com/linuxserver.io/docker-jenkins-builder/lsiodev-buildcache,ghcr.io/linuxserver/lsiodev-buildcache,quay.io/linuxserver.io/lsiodev-buildcache'
env.CITEST_IMAGETAG = 'develop'
} }
} }
} }
@@ -280,7 +285,7 @@ pipeline {
-v ${WORKSPACE}:/mnt \ -v ${WORKSPACE}:/mnt \
-e AWS_ACCESS_KEY_ID=\"${S3_KEY}\" \ -e AWS_ACCESS_KEY_ID=\"${S3_KEY}\" \
-e AWS_SECRET_ACCESS_KEY=\"${S3_SECRET}\" \ -e AWS_SECRET_ACCESS_KEY=\"${S3_SECRET}\" \
ghcr.io/linuxserver/baseimage-alpine:3.20 s6-envdir -fn -- /var/run/s6/container_environment /bin/bash -c "\ ghcr.io/linuxserver/baseimage-alpine:3.23 s6-envdir -fn -- /var/run/s6/container_environment /bin/bash -c "\
apk add --no-cache python3 && \ apk add --no-cache python3 && \
python3 -m venv /lsiopy && \ python3 -m venv /lsiopy && \
pip install --no-cache-dir -U pip && \ pip install --no-cache-dir -U pip && \
@@ -615,13 +620,16 @@ pipeline {
echo $GITHUB_TOKEN | docker login ghcr.io -u LinuxServer-CI --password-stdin echo $GITHUB_TOKEN | docker login ghcr.io -u LinuxServer-CI --password-stdin
echo $GITLAB_TOKEN | docker login registry.gitlab.com -u LinuxServer.io --password-stdin echo $GITLAB_TOKEN | docker login registry.gitlab.com -u LinuxServer.io --password-stdin
echo $QUAYPASS | docker login quay.io -u $QUAYUSER --password-stdin echo $QUAYPASS | docker login quay.io -u $QUAYUSER --password-stdin
if [[ "${PACKAGE_CHECK}" != "true" ]]; then if [[ "${PACKAGE_CHECK}" != "true" ]]; then
declare -A pids
IFS=',' read -ra CACHE <<< "$BUILDCACHE" IFS=',' read -ra CACHE <<< "$BUILDCACHE"
for i in "${CACHE[@]}"; do for i in "${CACHE[@]}"; do
docker push ${i}:amd64-${COMMIT_SHA}-${BUILD_NUMBER} & docker push ${i}:amd64-${COMMIT_SHA}-${BUILD_NUMBER} &
pids[$!]="$i"
done done
for p in $(jobs -p); do for p in "${!pids[@]}"; do
wait "$p" || { echo "job $p failed" >&2; exit 1; } wait "$p" || { [[ "${pids[$p]}" != *"quay.io"* ]] && exit 1; }
done done
fi fi
''' '''
@@ -681,13 +689,16 @@ pipeline {
echo $GITHUB_TOKEN | docker login ghcr.io -u LinuxServer-CI --password-stdin echo $GITHUB_TOKEN | docker login ghcr.io -u LinuxServer-CI --password-stdin
echo $GITLAB_TOKEN | docker login registry.gitlab.com -u LinuxServer.io --password-stdin echo $GITLAB_TOKEN | docker login registry.gitlab.com -u LinuxServer.io --password-stdin
echo $QUAYPASS | docker login quay.io -u $QUAYUSER --password-stdin echo $QUAYPASS | docker login quay.io -u $QUAYUSER --password-stdin
if [[ "${PACKAGE_CHECK}" != "true" ]]; then if [[ "${PACKAGE_CHECK}" != "true" ]]; then
declare -A pids
IFS=',' read -ra CACHE <<< "$BUILDCACHE" IFS=',' read -ra CACHE <<< "$BUILDCACHE"
for i in "${CACHE[@]}"; do for i in "${CACHE[@]}"; do
docker push ${i}:amd64-${COMMIT_SHA}-${BUILD_NUMBER} & docker push ${i}:amd64-${COMMIT_SHA}-${BUILD_NUMBER} &
pids[$!]="$i"
done done
for p in $(jobs -p); do for p in "${!pids[@]}"; do
wait "$p" || { echo "job $p failed" >&2; exit 1; } wait "$p" || { [[ "${pids[$p]}" != *"quay.io"* ]] && exit 1; }
done done
fi fi
''' '''
@@ -741,12 +752,14 @@ pipeline {
echo $GITLAB_TOKEN | docker login registry.gitlab.com -u LinuxServer.io --password-stdin echo $GITLAB_TOKEN | docker login registry.gitlab.com -u LinuxServer.io --password-stdin
echo $QUAYPASS | docker login quay.io -u $QUAYUSER --password-stdin echo $QUAYPASS | docker login quay.io -u $QUAYUSER --password-stdin
if [[ "${PACKAGE_CHECK}" != "true" ]]; then if [[ "${PACKAGE_CHECK}" != "true" ]]; then
declare -A pids
IFS=',' read -ra CACHE <<< "$BUILDCACHE" IFS=',' read -ra CACHE <<< "$BUILDCACHE"
for i in "${CACHE[@]}"; do for i in "${CACHE[@]}"; do
docker push ${i}:arm64v8-${COMMIT_SHA}-${BUILD_NUMBER} & docker push ${i}:arm64v8-${COMMIT_SHA}-${BUILD_NUMBER} &
pids[$!]="$i"
done done
for p in $(jobs -p); do for p in "${!pids[@]}"; do
wait "$p" || { echo "job $p failed" >&2; exit 1; } wait "$p" || { [[ "${pids[$p]}" != *"quay.io"* ]] && exit 1; }
done done
fi fi
''' '''
@@ -860,6 +873,7 @@ pipeline {
script{ script{
env.CI_URL = 'https://ci-tests.linuxserver.io/' + env.IMAGE + '/' + env.META_TAG + '/index.html' env.CI_URL = 'https://ci-tests.linuxserver.io/' + env.IMAGE + '/' + env.META_TAG + '/index.html'
env.CI_JSON_URL = 'https://ci-tests.linuxserver.io/' + env.IMAGE + '/' + env.META_TAG + '/report.json' env.CI_JSON_URL = 'https://ci-tests.linuxserver.io/' + env.IMAGE + '/' + env.META_TAG + '/report.json'
env.CI_TEST_ATTEMPTED = 'true'
} }
sh '''#! /bin/bash sh '''#! /bin/bash
set -e set -e
@@ -871,7 +885,7 @@ pipeline {
CI_DOCKERENV="LSIO_FIRST_PARTY=true" CI_DOCKERENV="LSIO_FIRST_PARTY=true"
fi fi
fi fi
docker pull ghcr.io/linuxserver/ci:latest docker pull ghcr.io/linuxserver/ci:${CITEST_IMAGETAG}
if [ "${MULTIARCH}" == "true" ]; then if [ "${MULTIARCH}" == "true" ]; then
docker pull ghcr.io/linuxserver/lsiodev-buildcache:arm64v8-${COMMIT_SHA}-${BUILD_NUMBER} --platform=arm64 docker pull ghcr.io/linuxserver/lsiodev-buildcache:arm64v8-${COMMIT_SHA}-${BUILD_NUMBER} --platform=arm64
docker tag ghcr.io/linuxserver/lsiodev-buildcache:arm64v8-${COMMIT_SHA}-${BUILD_NUMBER} ${IMAGE}:arm64v8-${META_TAG} docker tag ghcr.io/linuxserver/lsiodev-buildcache:arm64v8-${COMMIT_SHA}-${BUILD_NUMBER} ${IMAGE}:arm64v8-${META_TAG}
@@ -895,7 +909,9 @@ pipeline {
-e WEB_PATH=\"${CI_WEBPATH}\" \ -e WEB_PATH=\"${CI_WEBPATH}\" \
-e NODE_NAME=\"${NODE_NAME}\" \ -e NODE_NAME=\"${NODE_NAME}\" \
-e SYFT_IMAGE_TAG=\"${CI_SYFT_IMAGE_TAG:-${SYFT_IMAGE_TAG}}\" \ -e SYFT_IMAGE_TAG=\"${CI_SYFT_IMAGE_TAG:-${SYFT_IMAGE_TAG}}\" \
-t ghcr.io/linuxserver/ci:latest \ -e COMMIT_SHA=\"${COMMIT_SHA}\" \
-e BUILD_NUMBER=\"${BUILD_NUMBER}\" \
-t ghcr.io/linuxserver/ci:${CITEST_IMAGETAG} \
python3 test_build.py''' python3 test_build.py'''
} }
} }
@@ -910,6 +926,9 @@ pipeline {
environment name: 'EXIT_STATUS', value: '' environment name: 'EXIT_STATUS', value: ''
} }
steps { steps {
script{
env.PUSH_ATTEMPTED = 'true'
}
retry_backoff(5,5) { retry_backoff(5,5) {
sh '''#! /bin/bash sh '''#! /bin/bash
set -e set -e
@@ -921,9 +940,11 @@ pipeline {
CACHEIMAGE=${i} CACHEIMAGE=${i}
fi fi
done done
docker buildx imagetools create --prefer-index=false -t ${PUSHIMAGE}:${META_TAG} -t ${PUSHIMAGE}:latest -t ${PUSHIMAGE}:${EXT_RELEASE_TAG} ${CACHEIMAGE}:amd64-${COMMIT_SHA}-${BUILD_NUMBER} docker buildx imagetools create --prefer-index=false -t ${PUSHIMAGE}:${META_TAG} -t ${PUSHIMAGE}:latest -t ${PUSHIMAGE}:${EXT_RELEASE_TAG} ${CACHEIMAGE}:amd64-${COMMIT_SHA}-${BUILD_NUMBER} || \
{ if [[ "${PUSHIMAGE}" != "${QUAYIMAGE}" ]]; then exit 1; fi; }
if [ -n "${SEMVER}" ]; then if [ -n "${SEMVER}" ]; then
docker buildx imagetools create --prefer-index=false -t ${PUSHIMAGE}:${SEMVER} ${CACHEIMAGE}:amd64-${COMMIT_SHA}-${BUILD_NUMBER} docker buildx imagetools create --prefer-index=false -t ${PUSHIMAGE}:${SEMVER} ${CACHEIMAGE}:amd64-${COMMIT_SHA}-${BUILD_NUMBER} || \
{ if [[ "${PUSHIMAGE}" != "${QUAYIMAGE}" ]]; then exit 1; fi; }
fi fi
done done
''' '''
@@ -937,31 +958,45 @@ pipeline {
environment name: 'EXIT_STATUS', value: '' environment name: 'EXIT_STATUS', value: ''
} }
steps { steps {
script{
env.PUSH_ATTEMPTED = 'true'
}
retry_backoff(5,5) { retry_backoff(5,5) {
sh '''#! /bin/bash sh '''#! /bin/bash
set -e set -e
for MANIFESTIMAGE in "${IMAGE}" "${GITLABIMAGE}" "${GITHUBIMAGE}" "${QUAYIMAGE}"; do for MANIFESTIMAGE in "${IMAGE}" "${GITLABIMAGE}" "${GITHUBIMAGE}" "${QUAYIMAGE}"; do
[[ ${MANIFESTIMAGE%%/*} =~ \\. ]] && MANIFESTIMAGEPLUS="${MANIFESTIMAGE}" || MANIFESTIMAGEPLUS="docker.io/${MANIFESTIMAGE}" if [[ "${MANIFESTIMAGE%%/*}" =~ \\. ]]; then
MANIFESTIMAGEPLUS="${MANIFESTIMAGE}"
else
MANIFESTIMAGEPLUS="docker.io/${MANIFESTIMAGE}"
fi
IFS=',' read -ra CACHE <<< "$BUILDCACHE" IFS=',' read -ra CACHE <<< "$BUILDCACHE"
for i in "${CACHE[@]}"; do for i in "${CACHE[@]}"; do
if [[ "${MANIFESTIMAGEPLUS}" == "$(cut -d "/" -f1 <<< ${i})"* ]]; then if [[ "${MANIFESTIMAGEPLUS}" == "$(cut -d "/" -f1 <<< ${i})"* ]]; then
CACHEIMAGE=${i} CACHEIMAGE=${i}
fi fi
done done
docker buildx imagetools create --prefer-index=false -t ${MANIFESTIMAGE}:amd64-${META_TAG} -t ${MANIFESTIMAGE}:amd64-latest -t ${MANIFESTIMAGE}:amd64-${EXT_RELEASE_TAG} ${CACHEIMAGE}:amd64-${COMMIT_SHA}-${BUILD_NUMBER} docker buildx imagetools create --prefer-index=false -t ${MANIFESTIMAGE}:amd64-${META_TAG} -t ${MANIFESTIMAGE}:amd64-latest -t ${MANIFESTIMAGE}:amd64-${EXT_RELEASE_TAG} ${CACHEIMAGE}:amd64-${COMMIT_SHA}-${BUILD_NUMBER} || \
docker buildx imagetools create --prefer-index=false -t ${MANIFESTIMAGE}:arm64v8-${META_TAG} -t ${MANIFESTIMAGE}:arm64v8-latest -t ${MANIFESTIMAGE}:arm64v8-${EXT_RELEASE_TAG} ${CACHEIMAGE}:arm64v8-${COMMIT_SHA}-${BUILD_NUMBER} { if [[ "${MANIFESTIMAGE}" != "${QUAYIMAGE}" ]]; then exit 1; fi; }
docker buildx imagetools create --prefer-index=false -t ${MANIFESTIMAGE}:arm64v8-${META_TAG} -t ${MANIFESTIMAGE}:arm64v8-latest -t ${MANIFESTIMAGE}:arm64v8-${EXT_RELEASE_TAG} ${CACHEIMAGE}:arm64v8-${COMMIT_SHA}-${BUILD_NUMBER} || \
{ if [[ "${MANIFESTIMAGE}" != "${QUAYIMAGE}" ]]; then exit 1; fi; }
if [ -n "${SEMVER}" ]; then if [ -n "${SEMVER}" ]; then
docker buildx imagetools create --prefer-index=false -t ${MANIFESTIMAGE}:amd64-${SEMVER} ${CACHEIMAGE}:amd64-${COMMIT_SHA}-${BUILD_NUMBER} docker buildx imagetools create --prefer-index=false -t ${MANIFESTIMAGE}:amd64-${SEMVER} ${CACHEIMAGE}:amd64-${COMMIT_SHA}-${BUILD_NUMBER} || \
docker buildx imagetools create --prefer-index=false -t ${MANIFESTIMAGE}:arm64v8-${SEMVER} ${CACHEIMAGE}:arm64v8-${COMMIT_SHA}-${BUILD_NUMBER} { if [[ "${MANIFESTIMAGE}" != "${QUAYIMAGE}" ]]; then exit 1; fi; }
docker buildx imagetools create --prefer-index=false -t ${MANIFESTIMAGE}:arm64v8-${SEMVER} ${CACHEIMAGE}:arm64v8-${COMMIT_SHA}-${BUILD_NUMBER} || \
{ if [[ "${MANIFESTIMAGE}" != "${QUAYIMAGE}" ]]; then exit 1; fi; }
fi fi
done done
for MANIFESTIMAGE in "${IMAGE}" "${GITLABIMAGE}" "${GITHUBIMAGE}" "${QUAYIMAGE}"; do for MANIFESTIMAGE in "${IMAGE}" "${GITLABIMAGE}" "${GITHUBIMAGE}" "${QUAYIMAGE}"; do
docker buildx imagetools create -t ${MANIFESTIMAGE}:latest ${MANIFESTIMAGE}:amd64-latest ${MANIFESTIMAGE}:arm64v8-latest docker buildx imagetools create -t ${MANIFESTIMAGE}:latest ${MANIFESTIMAGE}:amd64-latest ${MANIFESTIMAGE}:arm64v8-latest || \
docker buildx imagetools create -t ${MANIFESTIMAGE}:${META_TAG} ${MANIFESTIMAGE}:amd64-${META_TAG} ${MANIFESTIMAGE}:arm64v8-${META_TAG} { if [[ "${MANIFESTIMAGE}" != "${QUAYIMAGE}" ]]; then exit 1; fi; }
docker buildx imagetools create -t ${MANIFESTIMAGE}:${META_TAG} ${MANIFESTIMAGE}:amd64-${META_TAG} ${MANIFESTIMAGE}:arm64v8-${META_TAG} || \
docker buildx imagetools create -t ${MANIFESTIMAGE}:${EXT_RELEASE_TAG} ${MANIFESTIMAGE}:amd64-${EXT_RELEASE_TAG} ${MANIFESTIMAGE}:arm64v8-${EXT_RELEASE_TAG} { if [[ "${MANIFESTIMAGE}" != "${QUAYIMAGE}" ]]; then exit 1; fi; }
docker buildx imagetools create -t ${MANIFESTIMAGE}:${EXT_RELEASE_TAG} ${MANIFESTIMAGE}:amd64-${EXT_RELEASE_TAG} ${MANIFESTIMAGE}:arm64v8-${EXT_RELEASE_TAG} || \
{ if [[ "${MANIFESTIMAGE}" != "${QUAYIMAGE}" ]]; then exit 1; fi; }
if [ -n "${SEMVER}" ]; then if [ -n "${SEMVER}" ]; then
docker buildx imagetools create -t ${MANIFESTIMAGE}:${SEMVER} ${MANIFESTIMAGE}:amd64-${SEMVER} ${MANIFESTIMAGE}:arm64v8-${SEMVER} docker buildx imagetools create -t ${MANIFESTIMAGE}:${SEMVER} ${MANIFESTIMAGE}:amd64-${SEMVER} ${MANIFESTIMAGE}:arm64v8-${SEMVER} || \
{ if [[ "${MANIFESTIMAGE}" != "${QUAYIMAGE}" ]]; then exit 1; fi; }
fi fi
done done
''' '''
@@ -979,23 +1014,41 @@ pipeline {
environment name: 'EXIT_STATUS', value: '' environment name: 'EXIT_STATUS', value: ''
} }
steps { steps {
echo "Pushing New tag for current commit ${META_TAG}"
sh '''curl -H "Authorization: token ${GITHUB_TOKEN}" -X POST https://api.github.com/repos/${LS_USER}/${LS_REPO}/git/tags \
-d '{"tag":"'${META_TAG}'",\
"object": "'${COMMIT_SHA}'",\
"message": "Tagging Release '${EXT_RELEASE_CLEAN}'-ls'${LS_TAG_NUMBER}' to master",\
"type": "commit",\
"tagger": {"name": "LinuxServer-CI","email": "ci@linuxserver.io","date": "'${GITHUB_DATE}'"}}' '''
echo "Pushing New release for Tag"
sh '''#! /bin/bash sh '''#! /bin/bash
echo "Auto-generating release notes"
if [ "$(git tag --points-at HEAD)" != "" ]; then
echo "Existing tag points to current commit, suggesting no new LS changes"
AUTO_RELEASE_NOTES="No changes"
else
AUTO_RELEASE_NOTES=$(curl -fsL -H "Authorization: token ${GITHUB_TOKEN}" -H "Accept: application/vnd.github+json" -X POST https://api.github.com/repos/${LS_USER}/${LS_REPO}/releases/generate-notes \
-d '{"tag_name":"'${META_TAG}'",\
"target_commitish": "master"}' \
| jq -r '.body' | sed 's|## What.s Changed||')
fi
echo "Pushing New tag for current commit ${META_TAG}"
curl -H "Authorization: token ${GITHUB_TOKEN}" -X POST https://api.github.com/repos/${LS_USER}/${LS_REPO}/git/tags \
-d '{"tag":"'${META_TAG}'",\
"object": "'${COMMIT_SHA}'",\
"message": "Tagging Release '${EXT_RELEASE_CLEAN}'-ls'${LS_TAG_NUMBER}' to master",\
"type": "commit",\
"tagger": {"name": "LinuxServer-CI","email": "ci@linuxserver.io","date": "'${GITHUB_DATE}'"}}'
echo "Pushing New release for Tag"
echo "Updating PIP version of ${EXT_PIP} to ${EXT_RELEASE_CLEAN}" > releasebody.json echo "Updating PIP version of ${EXT_PIP} to ${EXT_RELEASE_CLEAN}" > releasebody.json
echo '{"tag_name":"'${META_TAG}'",\ jq -n \
"target_commitish": "master",\ --arg tag_name "$META_TAG" \
"name": "'${META_TAG}'",\ --arg target_commitish "master" \
"body": "**CI Report:**\\n\\n'${CI_URL:-N/A}'\\n\\n**LinuxServer Changes:**\\n\\n'${LS_RELEASE_NOTES}'\\n\\n**Remote Changes:**\\n\\n' > start --arg ci_url "${CI_URL:-N/A}" \
printf '","draft": false,"prerelease": false}' >> releasebody.json --arg ls_notes "$AUTO_RELEASE_NOTES" \
paste -d'\\0' start releasebody.json > releasebody.json.done --arg remote_notes "$(cat releasebody.json)" \
curl -H "Authorization: token ${GITHUB_TOKEN}" -X POST https://api.github.com/repos/${LS_USER}/${LS_REPO}/releases -d @releasebody.json.done''' '{
"tag_name": $tag_name,
"target_commitish": $target_commitish,
"name": $tag_name,
"body": ("**CI Report:**\\n\\n" + $ci_url + "\\n\\n**LinuxServer Changes:**\\n\\n" + $ls_notes + "\\n\\n**Remote Changes:**\\n\\n" + $remote_notes),
"draft": false,
"prerelease": false }' > releasebody.json.done
curl -H "Authorization: token ${GITHUB_TOKEN}" -X POST https://api.github.com/repos/${LS_USER}/${LS_REPO}/releases -d @releasebody.json.done
'''
} }
} }
// Add protection to the release branch // Add protection to the release branch
@@ -1033,98 +1086,13 @@ EOF
) ''' ) '''
} }
} }
// If this is a Pull request send the CI link as a comment on it
stage('Pull Request Comment') {
when {
not {environment name: 'CHANGE_ID', value: ''}
environment name: 'EXIT_STATUS', value: ''
}
steps {
sh '''#! /bin/bash
# Function to retrieve JSON data from URL
get_json() {
local url="$1"
local response=$(curl -s "$url")
if [ $? -ne 0 ]; then
echo "Failed to retrieve JSON data from $url"
return 1
fi
local json=$(echo "$response" | jq .)
if [ $? -ne 0 ]; then
echo "Failed to parse JSON data from $url"
return 1
fi
echo "$json"
}
build_table() {
local data="$1"
# Get the keys in the JSON data
local keys=$(echo "$data" | jq -r 'to_entries | map(.key) | .[]')
# Check if keys are empty
if [ -z "$keys" ]; then
echo "JSON report data does not contain any keys or the report does not exist."
return 1
fi
# Build table header
local header="| Tag | Passed |\\n| --- | --- |\\n"
# Loop through the JSON data to build the table rows
local rows=""
for build in $keys; do
local status=$(echo "$data" | jq -r ".[\\"$build\\"].test_success")
if [ "$status" = "true" ]; then
status="✅"
else
status="❌"
fi
local row="| "$build" | "$status" |\\n"
rows="${rows}${row}"
done
local table="${header}${rows}"
local escaped_table=$(echo "$table" | sed 's/\"/\\\\"/g')
echo "$escaped_table"
}
if [[ "${CI}" = "true" ]]; then
# Retrieve JSON data from URL
data=$(get_json "$CI_JSON_URL")
# Create table from JSON data
table=$(build_table "$data")
echo -e "$table"
curl -X POST -H "Authorization: token $GITHUB_TOKEN" \
-H "Accept: application/vnd.github.v3+json" \
"https://api.github.com/repos/$LS_USER/$LS_REPO/issues/$PULL_REQUEST/comments" \
-d "{\\"body\\": \\"I am a bot, here are the test results for this PR: \\n${CI_URL}\\n${SHELLCHECK_URL}\\n${table}\\"}"
else
curl -X POST -H "Authorization: token $GITHUB_TOKEN" \
-H "Accept: application/vnd.github.v3+json" \
"https://api.github.com/repos/$LS_USER/$LS_REPO/issues/$PULL_REQUEST/comments" \
-d "{\\"body\\": \\"I am a bot, here is the pushed image/manifest for this PR: \\n\\n\\`${GITHUBIMAGE}:${META_TAG}\\`\\"}"
fi
'''
}
}
} }
/* ###################### /* ######################
Send status to Discord Comment on PR and Send status to Discord
###################### */ ###################### */
post { post {
always { always {
sh '''#!/bin/bash script {
rm -rf /config/.ssh/id_sign
rm -rf /config/.ssh/id_sign.pub
git config --global --unset gpg.format
git config --global --unset user.signingkey
git config --global --unset commit.gpgsign
'''
script{
env.JOB_DATE = sh( env.JOB_DATE = sh(
script: '''date '+%Y-%m-%dT%H:%M:%S%:z' ''', script: '''date '+%Y-%m-%dT%H:%M:%S%:z' ''',
returnStdout: true).trim() returnStdout: true).trim()
@@ -1167,6 +1135,94 @@ EOF
"username": "Jenkins"}' ${BUILDS_DISCORD} ''' "username": "Jenkins"}' ${BUILDS_DISCORD} '''
} }
} }
script {
if (env.GITHUBIMAGE =~ /lspipepr/){
if (env.CI_TEST_ATTEMPTED == "true" || env.PUSH_ATTEMPTED == "true"){
sh '''#! /bin/bash
# Function to retrieve JSON data from URL
get_json() {
local url="$1"
local response=$(curl -s "$url")
if [ $? -ne 0 ]; then
echo "Failed to retrieve JSON data from $url"
return 1
fi
local json=$(echo "$response" | jq .)
if [ $? -ne 0 ]; then
echo "Failed to parse JSON data from $url"
return 1
fi
echo "$json"
}
build_table() {
local data="$1"
# Get the keys in the JSON data
local keys=$(echo "$data" | jq -r 'to_entries | map(.key) | .[]')
# Check if keys are empty
if [ -z "$keys" ]; then
echo "JSON report data does not contain any keys or the report does not exist."
return 1
fi
# Build table header
local header="| Tag | Passed |\\n| --- | --- |\\n"
# Loop through the JSON data to build the table rows
local rows=""
for build in $keys; do
local status=$(echo "$data" | jq -r ".[\\"$build\\"].test_success")
if [ "$status" = "true" ]; then
status="✅"
else
status="❌"
fi
local row="| "$build" | "$status" |\\n"
rows="${rows}${row}"
done
local table="${header}${rows}"
local escaped_table=$(echo "$table" | sed 's/\"/\\\\"/g')
echo "$escaped_table"
}
if [[ "${CI}" = "true" ]]; then
# Retrieve JSON data from URL
data=$(get_json "$CI_JSON_URL")
# Create table from JSON data
table=$(build_table "$data")
echo -e "$table"
curl -X POST -H "Authorization: token $GITHUB_TOKEN" \
-H "Accept: application/vnd.github.v3+json" \
"https://api.github.com/repos/$LS_USER/$LS_REPO/issues/$PULL_REQUEST/comments" \
-d "{\\"body\\": \\"I am a bot, here are the test results for this PR for commit ${COMMIT_SHA:0:7} : \\n${CI_URL}\\n${SHELLCHECK_URL}\\n${table}\\"}"
else
curl -X POST -H "Authorization: token $GITHUB_TOKEN" \
-H "Accept: application/vnd.github.v3+json" \
"https://api.github.com/repos/$LS_USER/$LS_REPO/issues/$PULL_REQUEST/comments" \
-d "{\\"body\\": \\"I am a bot, here is the pushed image/manifest for this PR for commit ${COMMIT_SHA:0:7} : \\n\\n\\`${GITHUBIMAGE}:${META_TAG}\\`\\"}"
fi
'''
} else {
sh '''#! /bin/bash
curl -X POST -H "Authorization: token $GITHUB_TOKEN" \
-H "Accept: application/vnd.github.v3+json" \
"https://api.github.com/repos/$LS_USER/$LS_REPO/issues/$PULL_REQUEST/comments" \
-d "{\\"body\\": \\"I am a bot, the build for PR commit ${COMMIT_SHA:0:7} failed and as a result no CI test was attempted and no images were pushed.\\"}"
'''
}
}
}
sh '''#!/bin/bash
rm -rf /config/.ssh/id_sign
rm -rf /config/.ssh/id_sign.pub
git config --global --unset gpg.format
git config --global --unset user.signingkey
git config --global --unset commit.gpgsign
'''
} }
cleanup { cleanup {
sh '''#! /bin/bash sh '''#! /bin/bash
+13 -3
View File
@@ -68,7 +68,7 @@ The architectures supported by this image are:
2. Certs that cover sub-subdomains of your main subdomain (ie. `*.yoursubdomain.duckdns.org`, set the `SUBDOMAINS` variable to `wildcard`) 2. Certs that cover sub-subdomains of your main subdomain (ie. `*.yoursubdomain.duckdns.org`, set the `SUBDOMAINS` variable to `wildcard`)
* `--cap-add=NET_ADMIN` is required for fail2ban to modify iptables * `--cap-add=NET_ADMIN` is required for fail2ban to modify iptables
* After setup, navigate to `https://example.com` to access the default homepage (http access through port 80 is disabled by default, you can enable it by editing the default site config at `/config/nginx/site-confs/default.conf`). * After setup, navigate to `https://example.com` to access the default homepage (http access through port 80 is disabled by default, you can enable it by editing the default site config at `/config/nginx/site-confs/default.conf`).
* Certs are checked nightly and if expiration is within 30 days, renewal is attempted. If your cert is about to expire in less than 30 days, check the logs under `/config/log/letsencrypt` to see why the renewals have been failing. It is recommended to input your e-mail in docker parameters so you receive expiration notices from Let's Encrypt in those circumstances. * Certs are checked twice daily using ACME Renewal Information (ARI) to determine the optimal renewal window. If your cert is about to expire, check the logs under `/config/log/letsencrypt` to see why the renewals have been failing.
### Certbot Plugins ### Certbot Plugins
@@ -170,7 +170,7 @@ This image can be run with a read-only container filesystem. For details please
To help you get started creating a container from this image you can either use docker-compose or the docker cli. To help you get started creating a container from this image you can either use docker-compose or the docker cli.
>[!NOTE] >[!NOTE]
>Unless a parameter is flaged as 'optional', it is *mandatory* and a value must be provided. >Unless a parameter is flagged as 'optional', it is *mandatory* and a value must be provided.
### docker-compose (recommended, [click here for more info](https://docs.linuxserver.io/general/docker-compose)) ### docker-compose (recommended, [click here for more info](https://docs.linuxserver.io/general/docker-compose))
@@ -190,6 +190,7 @@ services:
- VALIDATION=http - VALIDATION=http
- SUBDOMAINS=www, #optional - SUBDOMAINS=www, #optional
- CERTPROVIDER= #optional - CERTPROVIDER= #optional
- CERT_PROFILE= #optional
- DNSPLUGIN=cloudflare #optional - DNSPLUGIN=cloudflare #optional
- PROPAGATION= #optional - PROPAGATION= #optional
- EMAIL= #optional - EMAIL= #optional
@@ -221,6 +222,7 @@ docker run -d \
-e VALIDATION=http \ -e VALIDATION=http \
-e SUBDOMAINS=www, `#optional` \ -e SUBDOMAINS=www, `#optional` \
-e CERTPROVIDER= `#optional` \ -e CERTPROVIDER= `#optional` \
-e CERT_PROFILE= `#optional` \
-e DNSPLUGIN=cloudflare `#optional` \ -e DNSPLUGIN=cloudflare `#optional` \
-e PROPAGATION= `#optional` \ -e PROPAGATION= `#optional` \
-e EMAIL= `#optional` \ -e EMAIL= `#optional` \
@@ -254,7 +256,8 @@ Containers are configured using parameters passed at runtime (such as those abov
| `-e VALIDATION=http` | Certbot validation method to use, options are `http` or `dns` (`dns` method also requires `DNSPLUGIN` variable set). | | `-e VALIDATION=http` | Certbot validation method to use, options are `http` or `dns` (`dns` method also requires `DNSPLUGIN` variable set). |
| `-e SUBDOMAINS=www,` | Subdomains you'd like the cert to cover (comma separated, no spaces) ie. `www,ftp,cloud`. For a wildcard cert, set this *exactly* to `wildcard` (wildcard cert is available via `dns` validation only) | | `-e SUBDOMAINS=www,` | Subdomains you'd like the cert to cover (comma separated, no spaces) ie. `www,ftp,cloud`. For a wildcard cert, set this *exactly* to `wildcard` (wildcard cert is available via `dns` validation only) |
| `-e CERTPROVIDER=` | Optionally define the cert provider. Set to `zerossl` for ZeroSSL certs (requires existing [ZeroSSL account](https://app.zerossl.com/signup) and the e-mail address entered in `EMAIL` env var). Otherwise defaults to Let's Encrypt. | | `-e CERTPROVIDER=` | Optionally define the cert provider. Set to `zerossl` for ZeroSSL certs (requires existing [ZeroSSL account](https://app.zerossl.com/signup) and the e-mail address entered in `EMAIL` env var). Otherwise defaults to Let's Encrypt. |
| `-e DNSPLUGIN=cloudflare` | Required if `VALIDATION` is set to `dns`. Options are `acmedns`, `aliyun`, `azure`, `bunny`, `cloudflare`, `cpanel`, `desec`, `digitalocean`, `directadmin`, `dnsimple`, `dnsmadeeasy`, `dnspod`, `do`, `domeneshop`, `dreamhost`, `duckdns`, `dynu`, `freedns`, `gandi`, `gehirn`, `glesys`, `godaddy`, `google`, `he`, `hetzner`, `infomaniak`, `inwx`, `ionos`, `linode`, `loopia`, `luadns`, `namecheap`, `netcup`, `njalla`, `nsone`, `ovh`, `porkbun`, `rfc2136`, `route53`, `sakuracloud`, `standalone`, `transip`, and `vultr`. Also need to enter the credentials into the corresponding ini (or json for some plugins) file under `/config/dns-conf`. | | `-e CERT_PROFILE=` | Optionally define a cert profile to use for cert generation. This is useful if you want to use a custom cert profile instead of the default one. Currently only supported for Let's Encrypt. See https://letsencrypt.org/docs/profiles/ |
| `-e DNSPLUGIN=cloudflare` | Required if `VALIDATION` is set to `dns`. Options are `acmedns`, `aliyun`, `azure`, `bunny`, `cloudflare`, `cpanel`, `desec`, `digitalocean`, `directadmin`, `dnsimple`, `dnsmadeeasy`, `dnspod`, `do`, `domeneshop`, `dreamhost`, `duckdns`, `dynu`, `freedns`, `gandi`, `gehirn`, `glesys`, `godaddy`, `google`, `he`, `hetzner`, `hetzner-cloud`, `infomaniak`, `inwx`, `ionos`, `linode`, `loopia`, `luadns`, `mijn-host`, `namecheap`, `netcup`, `njalla`, `nsone`, `ovh`, `porkbun`, `rfc2136`, `route53`, `sakuracloud`, `standalone`, `transip`, and `vultr`. Also need to enter the credentials into the corresponding ini (or json for some plugins) file under `/config/dns-conf`. |
| `-e PROPAGATION=` | Optionally override (in seconds) the default propagation time for the dns plugins. | | `-e PROPAGATION=` | Optionally override (in seconds) the default propagation time for the dns plugins. |
| `-e EMAIL=` | Optional e-mail address used for cert expiration notifications (Required for ZeroSSL). | | `-e EMAIL=` | Optional e-mail address used for cert expiration notifications (Required for ZeroSSL). |
| `-e ONLY_SUBDOMAINS=false` | If you wish to get certs only for certain subdomains, but not the main domain (main domain may be hosted on another machine and cannot be validated), set this to `true` | | `-e ONLY_SUBDOMAINS=false` | If you wish to get certs only for certain subdomains, but not the main domain (main domain may be hosted on another machine and cannot be validated), set this to `true` |
@@ -433,6 +436,13 @@ Once registered you can define the dockerfile to use with `-f Dockerfile.aarch64
## Versions ## Versions
* **19.07.26:** - Rebase to Alpine 3.24 with PHP 8.5.
* **10.07.26:** - Add support for Let's Encrypt cert profiles. Run certbot twice daily with a random delay.
* **19.06.26:** - Add support for mijn.host dns validation.
* **01.06.26:** - Remove obsolete old cert check logic.
* **23.01.26:** - Reorder init to fix proxy conf version checks.
* **21.12.25:** - Add support for hetzner-cloud dns validation.
* **04.11.25:** - Switch default Gandi credentials from API Key to Token, allow DNS propagation time for Azure DNS plugin.
* **18.07.25:** - Rebase to Alpine 3.22 with PHP 8.4. Add QUIC support. Drop PHP bindings for mcrypt as it is no longer maintained. * **18.07.25:** - Rebase to Alpine 3.22 with PHP 8.4. Add QUIC support. Drop PHP bindings for mcrypt as it is no longer maintained.
* **05.05.25:** - Disable Certbot's built in log rotation. * **05.05.25:** - Disable Certbot's built in log rotation.
* **19.01.25:** - Add [Auto Reload](https://github.com/linuxserver/docker-mods/tree/swag-auto-reload) functionality to SWAG. * **19.01.25:** - Add [Auto Reload](https://github.com/linuxserver/docker-mods/tree/swag-auto-reload) functionality to SWAG.
+382 -372
View File
@@ -1,372 +1,382 @@
NAME VERSION TYPE NAME VERSION TYPE
Simple Launcher 1.1.0.14 binary (+5 duplicates) Simple Launcher 1.1.0.14 binary (+5 duplicates)
acl-libs 2.3.2-r1 apk acl-libs 2.3.2-r1 apk
acme 4.2.0 python acme 5.7.0 python
alpine-baselayout 3.7.0-r0 apk alpine-baselayout 3.7.2-r1 apk
alpine-baselayout-data 3.7.0-r0 apk alpine-baselayout-data 3.7.2-r1 apk
alpine-keys 2.5-r0 apk alpine-keys 2.6-r0 apk
alpine-release 3.22.1-r0 apk alpine-release 3.24.1-r0 apk
aom-libs 3.12.1-r0 apk annotated-types 0.8.0 python
apache2-utils 2.4.65-r0 apk anyio 4.14.2 python
apk-tools 2.14.9-r2 apk aom-libs 3.14.1-r0 apk
apr 1.7.5-r0 apk apache2-utils 2.4.68-r0 apk
apr-util 1.6.3-r1 apk apk-tools 3.0.7-r0 apk
argon2-libs 20190702-r5 apk apr 1.7.6-r0 apk
attrs 25.3.0 python apr-util 1.6.4-r0 apk
autocommand 2.2.2 python argon2-libs 20190702-r5 apk
azure-common 1.1.28 python autocommand 2.2.2 python
azure-core 1.35.0 python azure-common 1.1.28 python
azure-identity 1.24.0 python azure-core 1.41.0 python
azure-mgmt-core 1.6.0 python azure-identity 1.25.3 python
azure-mgmt-dns 9.0.0 python azure-mgmt-core 1.6.0 python
backports-tarfile 1.2.0 python azure-mgmt-dns 9.0.0 python
bash 5.2.37-r0 apk backports-tarfile 1.2.0 python
beautifulsoup4 4.13.4 python bash 5.3.9-r1 apk
boto3 1.40.11 python beautifulsoup4 4.15.0 python
botocore 1.40.11 python boto3 1.43.72 python
brotli-libs 1.1.0-r2 apk botocore 1.43.72 python
bs4 0.0.2 python brotli-libs 1.2.0-r1 apk
busybox 1.37.0-r19 apk bs4 0.0.2 python
busybox-binsh 1.37.0-r19 apk busybox 1.37.0-r31 apk
c-ares 1.34.5-r0 apk busybox-binsh 1.37.0-r31 apk
c-client 2007f-r15 apk c-ares 1.34.8-r0 apk
ca-certificates 20250619-r0 apk ca-certificates 20260611-r0 apk
ca-certificates-bundle 20250619-r0 apk ca-certificates-bundle 20260611-r0 apk
cachetools 5.5.2 python catatonit 0.2.1-r0 apk
catatonit 0.2.1-r0 apk certbot 5.7.0 python
certbot 4.2.0 python certbot-dns-acmedns 0.1.0 python
certbot-dns-acmedns 0.1.0 python certbot-dns-aliyun 2.0.0 python
certbot-dns-aliyun 2.0.0 python certbot-dns-azure 1.5.0 python
certbot-dns-azure 1.5.0 python certbot-dns-bunny 3.0.0 python
certbot-dns-bunny 3.0.0 python certbot-dns-cloudflare 5.7.0 python
certbot-dns-cloudflare 4.2.0 python certbot-dns-cpanel 0.4.0 python
certbot-dns-cpanel 0.4.0 python certbot-dns-desec 1.3.2 python
certbot-dns-desec 1.2.1 python certbot-dns-digitalocean 5.7.0 python
certbot-dns-digitalocean 4.2.0 python certbot-dns-directadmin 1.0.15 python
certbot-dns-directadmin 1.0.15 python certbot-dns-dnsimple 5.7.0 python
certbot-dns-dnsimple 4.2.0 python certbot-dns-dnsmadeeasy 5.7.0 python
certbot-dns-dnsmadeeasy 4.2.0 python certbot-dns-dnspod 0.1.0 python
certbot-dns-dnspod 0.1.0 python certbot-dns-do 0.31.0 python
certbot-dns-do 0.31.0 python certbot-dns-domeneshop 0.2.9 python
certbot-dns-domeneshop 0.2.9 python certbot-dns-dreamhost 1.0 python
certbot-dns-dreamhost 1.0 python certbot-dns-duckdns 1.9.0 python
certbot-dns-duckdns 1.6 python certbot-dns-dynudns 0.0.6 python
certbot-dns-dynudns 0.0.6 python certbot-dns-freedns 0.2.0 python
certbot-dns-freedns 0.2.0 python certbot-dns-gehirn 5.7.0 python
certbot-dns-gehirn 4.2.0 python certbot-dns-glesys 2.1.0 python
certbot-dns-glesys 2.1.0 python certbot-dns-godaddy 2.8.0 python
certbot-dns-godaddy 2.8.0 python certbot-dns-google 5.7.0 python
certbot-dns-google 4.2.0 python certbot-dns-he 1.0.0 python
certbot-dns-he 1.0.0 python certbot-dns-hetzner 4.0.0 python
certbot-dns-hetzner 2.0.1 python certbot-dns-hetzner-cloud 1.0.5 python
certbot-dns-infomaniak 0.2.3 python certbot-dns-infomaniak 0.3.2 python
certbot-dns-inwx 3.0.3 python certbot-dns-inwx 3.0.3 python
certbot-dns-ionos 2024.11.9 python certbot-dns-ionos 2024.11.9 python
certbot-dns-linode 4.2.0 python certbot-dns-linode 5.7.0 python
certbot-dns-loopia 1.0.1 python certbot-dns-loopia 1.0.1 python
certbot-dns-luadns 4.2.0 python certbot-dns-luadns 5.7.0 python
certbot-dns-namecheap 1.0.0 python certbot-dns-mijn-host 0.0.9 python
certbot-dns-netcup 1.4.4 python certbot-dns-namecheap 1.0.0 python
certbot-dns-njalla 2.0.2 python certbot-dns-netcup 2.0.3 python
certbot-dns-nsone 4.2.0 python certbot-dns-njalla 2.0.2 python
certbot-dns-ovh 4.2.0 python certbot-dns-nsone 5.7.0 python
certbot-dns-porkbun 0.10.1 python certbot-dns-ovh 5.7.0 python
certbot-dns-rfc2136 4.2.0 python certbot-dns-porkbun 0.11.0 python
certbot-dns-route53 4.2.0 python certbot-dns-rfc2136 5.7.0 python
certbot-dns-sakuracloud 4.2.0 python certbot-dns-route53 5.7.0 python
certbot-dns-standalone 1.2.1 python certbot-dns-sakuracloud 5.7.0 python
certbot-dns-transip 0.5.2 python certbot-dns-standalone 1.2.1 python
certbot-dns-vultr 1.1.0 python certbot-dns-transip 0.5.2 python
certbot-plugin-gandi 1.5.0 python certbot-dns-vultr 1.1.0 python
certifi 2025.8.3 python certbot-plugin-gandi 1.5.0 python
cffi 1.17.1 python certifi 2024.8.30 python
charset-normalizer 3.4.3 python cffi 1.17.0 python
cli UNKNOWN binary charset-normalizer 3.3.2 python
cli-32 UNKNOWN binary cli UNKNOWN binary
cli-64 UNKNOWN binary cli-32 UNKNOWN binary
cli-arm64 UNKNOWN binary cli-64 UNKNOWN binary
cloudflare 2.19.4 python cli-arm64 UNKNOWN binary
composer 2.8.10 binary cloudflare 5.6.0 python
configargparse 1.7.1 python composer 2.10.2 binary
configobj 5.0.9 python configargparse 1.7 python
coreutils 9.7-r1 apk configobj 5.0.8 python
coreutils-env 9.7-r1 apk coreutils 9.11-r0 apk
coreutils-fmt 9.7-r1 apk coreutils-env 9.11-r0 apk
coreutils-sha512sum 9.7-r1 apk coreutils-fmt 9.11-r0 apk
cryptography 45.0.6 python coreutils-sha512sum 9.11-r0 apk
curl 8.14.1-r1 apk cryptography 45.0.7 python
distro 1.9.0 python curl 8.21.0-r0 apk
dns-lexicon 3.21.1 python distro 1.9.0 python
dnslib 0.9.26 python dns-lexicon 3.25.2 python
dnspython 2.7.0 python dnslib 0.9.26 python
domeneshop 0.4.4 python dnspython 2.8.0 python
fail2ban 1.1.0 python domeneshop 0.4.4 python
fail2ban 1.1.0-r3 apk fail2ban 1.1.0 python
fail2ban-pyc 1.1.0-r3 apk fail2ban 1.1.0-r3 apk
filelock 3.19.1 python fail2ban-pyc 1.1.0-r3 apk
findutils 4.10.0-r0 apk filelock 3.32.3 python
fontconfig 2.15.0-r3 apk findutils 4.10.0-r1 apk
freetype 2.13.3-r0 apk fontconfig 2.17.1-r1 apk
future 1.0.0 python freetype 2.14.3-r0 apk
gdbm 1.24-r0 apk future 1.0.0 python
git 2.49.1-r0 apk gdbm 1.26-r0 apk
git-init-template 2.49.1-r0 apk git 2.54.0-r0 apk
git-perl 2.49.1-r0 apk git-init-template 2.54.0-r0 apk
gmp 6.3.0-r3 apk git-perl 2.54.0-r0 apk
gnupg 2.4.7-r0 apk gmp 6.3.0-r4 apk
gnupg-dirmngr 2.4.7-r0 apk gnupg 2.4.9-r1 apk
gnupg-gpgconf 2.4.7-r0 apk gnupg-dirmngr 2.4.9-r1 apk
gnupg-keyboxd 2.4.7-r0 apk gnupg-gpgconf 2.4.9-r1 apk
gnupg-utils 2.4.7-r0 apk gnupg-keyboxd 2.4.9-r1 apk
gnupg-wks-client 2.4.7-r0 apk gnupg-utils 2.4.9-r1 apk
gnutls 3.8.8-r0 apk gnupg-wks-client 2.4.9-r1 apk
google-api-core 2.25.1 python gnutls 3.8.13-r0 apk
google-api-python-client 2.179.0 python google-api-core 2.30.3 python
google-auth 2.40.3 python google-api-python-client 2.198.0 python
google-auth-httplib2 0.2.0 python google-auth 2.56.3 python
googleapis-common-protos 1.70.0 python google-auth-httplib2 0.4.1 python
gpg 2.4.7-r0 apk googleapis-common-protos 1.75.1 python
gpg-agent 2.4.7-r0 apk gpg 2.4.9-r1 apk
gpg-wks-server 2.4.7-r0 apk gpg-agent 2.4.9-r1 apk
gpgsm 2.4.7-r0 apk gpg-wks-server 2.4.9-r1 apk
gpgv 2.4.7-r0 apk gpgsm 2.4.9-r1 apk
gui UNKNOWN binary gpgv 2.4.9-r1 apk
gui-32 UNKNOWN binary gui UNKNOWN binary
gui-64 UNKNOWN binary gui-32 UNKNOWN binary
gui-arm64 UNKNOWN binary gui-64 UNKNOWN binary
httplib2 0.22.0 python gui-arm64 UNKNOWN binary
icu-data-en 76.1-r1 apk h11 0.16.0 python
icu-libs 76.1-r1 apk hcloud 2.23.0 python
idna 3.10 python httpcore 1.0.9 python
importlib-metadata 8.0.0 python httplib2 0.32.0 python
inflect 7.3.1 python httpx 0.28.1 python
inotify-tools 4.23.9.0-r0 apk icu-data-en 78.1-r0 apk
inotify-tools-libs 4.23.9.0-r0 apk icu-libs 78.1-r0 apk
inwx-domrobot 3.2.0 python idna 3.8 python
iptables 1.8.11-r1 apk importlib-metadata 8.0.0 python
iptables-legacy 1.8.11-r1 apk importlib-resources 6.4.0 python
isodate 0.7.2 python inflect 7.3.1 python
jaraco-collections 5.1.0 python inotify-tools 4.23.9.0-r0 apk
jaraco-context 5.3.0 python inotify-tools-libs 4.23.9.0-r0 apk
jaraco-functools 4.0.1 python inwx-domrobot 3.2.0 python
jaraco-text 3.12.1 python iptables 1.8.13-r0 apk
jinja2 3.1.6 python iptables-legacy 1.8.13-r0 apk
jmespath 1.0.1 python isodate 0.7.2 python
josepy 2.1.0 python jaraco-context 5.3.0 python
jq 1.8.0-r0 apk jaraco-functools 4.0.1 python
jsonlines 4.0.0 python jaraco-text 3.12.1 python
jsonpickle 4.1.1 python jinja2 3.1.6 python
libapk2 2.14.9-r2 apk jmespath 1.1.0 python
libassuan 2.5.7-r0 apk josepy 2.2.0 python
libattr 2.5.2-r2 apk jq 1.8.1-r0 apk
libavif 1.3.0-r0 apk jsonpickle 4.1.2 python
libbsd 0.12.2-r0 apk libapk 3.0.7-r0 apk
libbz2 1.0.8-r6 apk libassuan 3.0.2-r0 apk
libcrypto3 3.5.1-r0 apk libattr 2.5.2-r2 apk
libcurl 8.14.1-r1 apk libavif 1.4.1-r0 apk
libdav1d 1.5.1-r0 apk libbsd 0.12.2-r0 apk
libedit 20250104.3.1-r1 apk libbz2 1.0.8-r6 apk
libevent 2.1.12-r8 apk libcrypto3 3.5.7-r0 apk
libexpat 2.7.1-r0 apk libcurl 8.21.0-r0 apk
libffi 3.4.8-r0 apk libdav1d 1.5.3-r0 apk
libgcc 14.2.0-r6 apk libedit 20260508.3.1-r1 apk
libgcrypt 1.10.3-r1 apk libevent 2.1.13-r0 apk
libgd 2.3.3-r10 apk libexpat 2.8.2-r0 apk
libgpg-error 1.55-r0 apk libffi 3.5.2-r1 apk
libice 1.1.2-r0 apk libgcc 15.2.0-r5 apk
libidn2 2.3.7-r0 apk libgcrypt 1.12.2-r0 apk
libintl 0.24.1-r0 apk libgd 2.3.3-r10 apk
libip4tc 1.8.11-r1 apk libgpg-error 1.61-r0 apk
libip6tc 1.8.11-r1 apk libice 1.1.2-r0 apk
libjpeg-turbo 3.1.0-r0 apk libidn2 2.3.8-r0 apk
libksba 1.6.7-r0 apk libintl 1.0-r0 apk
libldap 2.6.8-r0 apk libip4tc 1.8.13-r0 apk
libmaxminddb-libs 1.9.1-r0 apk libip6tc 1.8.13-r0 apk
libmd 1.1.0-r0 apk libjpeg-turbo 3.1.3-r0 apk
libmemcached-libs 1.1.4-r1 apk libksba 1.7.0-r0 apk
libmnl 1.0.5-r2 apk libldap 2.6.14-r0 apk
libncursesw 6.5_p20250503-r0 apk libmaxminddb-libs 1.13.3-r0 apk
libnftnl 1.2.9-r0 apk libmd 1.2.0-r0 apk
libpanelw 6.5_p20250503-r0 apk libmemcached-libs 1.1.4-r1 apk
libpng 1.6.47-r0 apk libmnl 1.0.5-r2 apk
libpq 17.5-r0 apk libncursesw 6.6_p20260516-r0 apk
libproc2 4.0.4-r3 apk libnftnl 1.3.1-r0 apk
libpsl 0.21.5-r3 apk libpanelw 6.6_p20260516-r0 apk
libsasl 2.1.28-r8 apk libpng 1.6.58-r1 apk
libseccomp 2.6.0-r0 apk libpq 18.6-r0 apk
libsharpyuv 1.5.0-r0 apk libproc2 4.0.6-r0 apk
libsm 1.2.5-r0 apk libpsl 0.21.5-r3 apk
libsodium 1.0.20-r0 apk libsasl 2.1.28-r9 apk
libssl3 3.5.1-r0 apk libseccomp 2.6.0-r2 apk
libstdc++ 14.2.0-r6 apk libsharpyuv 1.6.0-r0 apk
libtasn1 4.20.0-r0 apk libsm 1.2.6-r0 apk
libunistring 1.3-r0 apk libsodium 1.0.22-r0 apk
libuuid 2.41-r9 apk libssl3 3.5.7-r0 apk
libwebp 1.5.0-r0 apk libstdc++ 15.2.0-r5 apk
libx11 1.8.11-r0 apk libtasn1 4.21.0-r0 apk
libxau 1.0.12-r0 apk libunistring 1.4.2-r0 apk
libxcb 1.17.0-r0 apk libuuid 2.42.1-r0 apk
libxdmcp 1.1.5-r1 apk libwebp 1.6.0-r0 apk
libxext 1.3.6-r2 apk libx11 1.8.13-r0 apk
libxml2 2.13.8-r0 apk libxau 1.0.12-r0 apk
libxpm 3.5.17-r0 apk libxcb 1.17.0-r2 apk
libxslt 1.1.43-r3 apk libxdmcp 1.1.5-r1 apk
libxt 1.3.1-r0 apk libxext 1.3.7-r0 apk
libxtables 1.8.11-r1 apk libxml2 2.13.9-r2 apk
libyuv 0.0.1887.20251502-r1 apk libxpm 3.5.19-r0 apk
libzip 1.11.4-r0 apk libxslt 1.1.43-r3 apk
linux-pam 1.7.0-r4 apk libxt 1.3.1-r0 apk
logrotate 3.21.0-r1 apk libxtables 1.8.13-r0 apk
loopialib 0.2.0 python libyuv 0.0.1928-r0 apk
lxml 6.0.0 python libzip 1.11.4-r2 apk
lz4-libs 1.10.0-r0 apk linux-pam 1.7.1-r2 apk
markupsafe 3.0.2 python logrotate 3.22.0-r0 apk
memcached 1.6.32-r0 apk loopialib 0.2.0 python
mock 5.2.0 python lxml 6.1.1 python
more-itertools 10.3.0 python lz4-libs 1.10.0-r1 apk
mpdecimal 4.0.1-r0 apk markupsafe 3.0.3 python
msal 1.33.0 python memcached 1.6.42-r0 apk
msal-extensions 1.3.1 python mock 5.2.0 python
musl 1.2.5-r10 apk more-itertools 10.3.0 python
musl-utils 1.2.5-r10 apk mpdecimal 4.0.1-r0 apk
my-test-package 1.0 python msal 1.37.0 python
nano 8.4-r0 apk msal-extensions 1.3.1 python
ncurses-terminfo-base 6.5_p20250503-r0 apk musl 1.2.6-r2 apk
netcat-openbsd 1.229.1-r0 apk musl-utils 1.2.6-r2 apk
nettle 3.10.1-r0 apk my-test-package 1.0 python
nghttp2-libs 1.65.0-r0 apk nano 9.2-r0 apk
nginx 1.28.0-r3 apk ncurses-terminfo-base 6.6_p20260516-r0 apk
nginx-mod-devel-kit 1.28.0-r3 apk netcat-openbsd 1.234.1-r0 apk
nginx-mod-http-brotli 1.28.0-r3 apk nettle 3.10.2-r0 apk
nginx-mod-http-dav-ext 1.28.0-r3 apk nghttp2-libs 1.69.0-r0 apk
nginx-mod-http-echo 1.28.0-r3 apk nginx 1.30.4-r1 apk
nginx-mod-http-fancyindex 1.28.0-r3 apk nginx-mod-devel-kit 1.30.4-r1 apk
nginx-mod-http-geoip2 1.28.0-r3 apk nginx-mod-http-brotli 1.30.4-r1 apk
nginx-mod-http-headers-more 1.28.0-r3 apk nginx-mod-http-dav-ext 1.30.4-r1 apk
nginx-mod-http-image-filter 1.28.0-r3 apk nginx-mod-http-echo 1.30.4-r1 apk
nginx-mod-http-perl 1.28.0-r3 apk nginx-mod-http-fancyindex 1.30.4-r1 apk
nginx-mod-http-redis2 1.28.0-r3 apk nginx-mod-http-geoip2 1.30.4-r1 apk
nginx-mod-http-set-misc 1.28.0-r3 apk nginx-mod-http-headers-more 1.30.4-r1 apk
nginx-mod-http-upload-progress 1.28.0-r3 apk nginx-mod-http-image-filter 1.30.4-r1 apk
nginx-mod-http-xslt-filter 1.28.0-r3 apk nginx-mod-http-perl 1.30.4-r1 apk
nginx-mod-mail 1.28.0-r3 apk nginx-mod-http-redis2 1.30.4-r1 apk
nginx-mod-rtmp 1.28.0-r3 apk nginx-mod-http-set-misc 1.30.4-r1 apk
nginx-mod-stream 1.28.0-r3 apk nginx-mod-http-upload-progress 1.30.4-r1 apk
nginx-mod-stream-geoip2 1.28.0-r3 apk nginx-mod-http-xslt-filter 1.30.4-r1 apk
nginx-vim 1.28.0-r3 apk nginx-mod-mail 1.30.4-r1 apk
npth 1.8-r0 apk nginx-mod-rtmp 1.30.4-r1 apk
oniguruma 6.9.10-r0 apk nginx-mod-stream 1.30.4-r1 apk
openssl 3.5.1-r0 apk nginx-mod-stream-geoip2 1.30.4-r1 apk
p11-kit 0.25.5-r2 apk nginx-vim 1.30.4-r1 apk
packaging 24.2 python npth 1.8-r0 apk
parsedatetime 2.6 python oniguruma 6.9.10-r0 apk
pcre2 10.43-r1 apk openssl 3.5.7-r0 apk
perl 5.40.3-r0 apk p11-kit 0.26.2-r0 apk
perl-error 0.17030-r0 apk packaging 24.1 python
perl-git 2.49.1-r0 apk packaging 26.3 python
php84 8.4.11-r0 apk parsedatetime 2.6 python
php84-bcmath 8.4.11-r0 apk pcre2 10.47-r1 apk
php84-bz2 8.4.11-r0 apk perl 5.42.2-r0 apk
php84-common 8.4.11-r0 apk perl-error 0.17030-r0 apk
php84-ctype 8.4.11-r0 apk perl-git 2.54.0-r0 apk
php84-curl 8.4.11-r0 apk php85 8.5.9-r0 apk
php84-dom 8.4.11-r0 apk php85-bcmath 8.5.9-r0 apk
php84-exif 8.4.11-r0 apk php85-bz2 8.5.9-r0 apk
php84-fileinfo 8.4.11-r0 apk php85-common 8.5.9-r0 apk
php84-fpm 8.4.11-r0 apk php85-ctype 8.5.9-r0 apk
php84-ftp 8.4.11-r0 apk php85-curl 8.5.9-r0 apk
php84-gd 8.4.11-r0 apk php85-dom 8.5.9-r0 apk
php84-gmp 8.4.11-r0 apk php85-exif 8.5.9-r0 apk
php84-iconv 8.4.11-r0 apk php85-fileinfo 8.5.9-r0 apk
php84-intl 8.4.11-r0 apk php85-fpm 8.5.9-r0 apk
php84-ldap 8.4.11-r0 apk php85-ftp 8.5.9-r0 apk
php84-mbstring 8.4.11-r0 apk php85-gd 8.5.9-r0 apk
php84-mysqli 8.4.11-r0 apk php85-gmp 8.5.9-r0 apk
php84-mysqlnd 8.4.11-r0 apk php85-iconv 8.5.9-r0 apk
php84-opcache 8.4.11-r0 apk php85-intl 8.5.9-r0 apk
php84-openssl 8.4.11-r0 apk php85-ldap 8.5.9-r0 apk
php84-pdo 8.4.11-r0 apk php85-mbstring 8.5.9-r0 apk
php84-pdo_mysql 8.4.11-r0 apk php85-mysqli 8.5.9-r0 apk
php84-pdo_odbc 8.4.11-r0 apk php85-mysqlnd 8.5.9-r0 apk
php84-pdo_pgsql 8.4.11-r0 apk php85-openssl 8.5.9-r0 apk
php84-pdo_sqlite 8.4.11-r0 apk php85-pdo 8.5.9-r0 apk
php84-pear 8.4.11-r0 apk php85-pdo_mysql 8.5.9-r0 apk
php84-pecl-apcu 5.1.26-r0 apk php85-pdo_odbc 8.5.9-r0 apk
php84-pecl-igbinary 3.2.16-r1 apk php85-pdo_pgsql 8.5.9-r0 apk
php84-pecl-imap 1.0.3-r0 apk php85-pdo_sqlite 8.5.9-r0 apk
php84-pecl-memcached 3.3.0-r0 apk php85-pear 8.5.9-r0 apk
php84-pecl-msgpack 3.0.0-r0 apk php85-pecl-apcu 5.1.28-r0 apk
php84-pecl-redis 6.2.0-r0 apk php85-pecl-igbinary 3.2.17_rc1-r0 apk
php84-pgsql 8.4.11-r0 apk php85-pecl-memcached 3.4.0-r0 apk
php84-phar 8.4.11-r0 apk php85-pecl-msgpack 3.0.1-r0 apk
php84-posix 8.4.11-r0 apk php85-pecl-redis 6.3.0-r0 apk
php84-session 8.4.11-r0 apk php85-pgsql 8.5.9-r0 apk
php84-simplexml 8.4.11-r0 apk php85-phar 8.5.9-r0 apk
php84-soap 8.4.11-r0 apk php85-posix 8.5.9-r0 apk
php84-sockets 8.4.11-r0 apk php85-session 8.5.9-r0 apk
php84-sodium 8.4.11-r0 apk php85-simplexml 8.5.9-r0 apk
php84-sqlite3 8.4.11-r0 apk php85-soap 8.5.9-r0 apk
php84-tokenizer 8.4.11-r0 apk php85-sockets 8.5.9-r0 apk
php84-xml 8.4.11-r0 apk php85-sodium 8.5.9-r0 apk
php84-xmlreader 8.4.11-r0 apk php85-sqlite3 8.5.9-r0 apk
php84-xmlwriter 8.4.11-r0 apk php85-tokenizer 8.5.9-r0 apk
php84-xsl 8.4.11-r0 apk php85-xml 8.5.9-r0 apk
php84-zip 8.4.11-r0 apk php85-xmlreader 8.5.9-r0 apk
pinentry 1.3.1-r0 apk php85-xmlwriter 8.5.9-r0 apk
pip 25.2 python php85-xsl 8.5.9-r0 apk
pkb-client 2.2.0 python php85-zip 8.5.9-r0 apk
platformdirs 4.2.2 python pinentry 1.3.2-r0 apk
popt 1.19-r4 apk pip 26.2.1 python
procps-ng 4.0.4-r3 apk pkb-client 2.3.1 python
proto-plus 1.26.1 python platformdirs 4.2.2 python
protobuf 6.32.0 python popt 1.19-r4 apk
pyacmedns 0.4 python procps-ng 4.0.6-r0 apk
pyasn1 0.6.1 python proto-plus 1.28.3 python
pyasn1-modules 0.4.2 python protobuf 7.35.1 python
pyc 3.12.11-r0 apk pyacmedns 0.4 python
pycparser 2.22 python pyasn1 0.6.4 python
pyjwt 2.10.1 python pyasn1-modules 0.4.2 python
pynamecheap 0.0.3 python pyc 3.14.7-r1 apk
pyopenssl 25.1.0 python pycparser 2.22 python
pyotp 2.9.0 python pydantic 2.13.4 python
pyparsing 3.2.3 python pydantic-core 2.46.4 python
pyrfc3339 2.0.1 python pyjwt 2.13.0 python
python-dateutil 2.9.0.post0 python pynamecheap 0.0.3 python
python-digitalocean 1.17.0 python pyopenssl 25.3.0 python
python-transip 0.6.0 python pyotp 2.10.0 python
python3 3.12.11-r0 apk pyparsing 3.3.2 python
python3-pyc 3.12.11-r0 apk pyrfc3339 1.1 python
python3-pycache-pyc0 3.12.11-r0 apk python-dateutil 2.9.0.post0 python
pyyaml 6.0.2 python python-digitalocean 1.17.0 python
readline 8.2.13-r1 apk python-transip 0.6.0 python
requests 2.32.4 python python3 3.14.7-r1 apk
requests-file 2.1.0 python python3-pyc 3.14.7-r1 apk
requests-mock 1.12.1 python python3-pycache-pyc0 3.14.7-r1 apk
rsa 4.9.1 python pytz 2024.1 python
s3transfer 0.13.1 python pyyaml 6.0.3 python
scanelf 1.3.8-r1 apk readline 8.3.3-r1 apk
setuptools 80.9.0 python requests 2.32.3 python
shadow 4.17.3-r0 apk requests-file 3.0.1 python
six 1.17.0 python requests-mock 1.12.1 python
skalibs-libs 2.14.4.0-r0 apk requests-unixsocket 0.4.1 python
soupsieve 2.7 python ruff 0.6.3 python
sqlite-libs 3.49.2-r1 apk s3transfer 0.19.2 python
ssl_client 1.37.0-r19 apk scanelf 1.3.9-r1 apk
tiff 4.7.0-r0 apk setuptools 74.0.0 python
tldextract 5.3.0 python shadow 4.18.0-r1 apk
tomli 2.0.1 python six 1.16.0 python
typeguard 4.3.0 python skalibs-libs 2.15.0.0-r0 apk
typing-extensions 4.12.2 python sniffio 1.3.1 python
typing-extensions 4.14.1 python soupsieve 2.9.2 python
tzdata 2025b-r0 apk sqlite-libs 3.53.2-r0 apk
unixodbc 2.3.12-r0 apk ssl_client 1.37.0-r31 apk
uritemplate 4.2.0 python tiff 4.7.1-r0 apk
urllib3 2.5.0 python tldextract 5.3.2 python
utmps-libs 0.1.3.1-r0 apk tomli 2.0.1 python
wheel 0.45.1 python (+1 duplicate) typeguard 4.3.0 python
whois 5.6.3-r0 apk typing-extensions 4.12.2 python
xz-libs 5.8.1-r0 apk typing-extensions 4.16.0 python
zipp 3.19.2 python typing-inspection 0.4.4 python
zlib 1.3.1-r2 apk tzdata 2026c-r0 apk
zope-interface 7.2 python unixodbc 2.3.14-r1 apk
zstd-libs 1.5.7-r0 apk uritemplate 4.2.0 python
urllib3 2.2.2 python
utmps-libs 0.1.3.3-r0 apk
wheel 0.43.0 python
wheel 0.44.0 python
whois 5.6.6-r0 apk
xz-libs 5.8.3-r0 apk
zipp 3.19.2 python
zlib 1.3.2-r0 apk
zope-interface 8.5 python
zstd-libs 1.5.7-r2 apk
+14 -5
View File
@@ -32,7 +32,8 @@ opt_param_usage_include_env: true
opt_param_env_vars: opt_param_env_vars:
- {env_var: "SUBDOMAINS", env_value: "www,", desc: "Subdomains you'd like the cert to cover (comma separated, no spaces) ie. `www,ftp,cloud`. For a wildcard cert, set this *exactly* to `wildcard` (wildcard cert is available via `dns` validation only)"} - {env_var: "SUBDOMAINS", env_value: "www,", desc: "Subdomains you'd like the cert to cover (comma separated, no spaces) ie. `www,ftp,cloud`. For a wildcard cert, set this *exactly* to `wildcard` (wildcard cert is available via `dns` validation only)"}
- {env_var: "CERTPROVIDER", env_value: "", desc: "Optionally define the cert provider. Set to `zerossl` for ZeroSSL certs (requires existing [ZeroSSL account](https://app.zerossl.com/signup) and the e-mail address entered in `EMAIL` env var). Otherwise defaults to Let's Encrypt."} - {env_var: "CERTPROVIDER", env_value: "", desc: "Optionally define the cert provider. Set to `zerossl` for ZeroSSL certs (requires existing [ZeroSSL account](https://app.zerossl.com/signup) and the e-mail address entered in `EMAIL` env var). Otherwise defaults to Let's Encrypt."}
- {env_var: "DNSPLUGIN", env_value: "cloudflare", desc: "Required if `VALIDATION` is set to `dns`. Options are `acmedns`, `aliyun`, `azure`, `bunny`, `cloudflare`, `cpanel`, `desec`, `digitalocean`, `directadmin`, `dnsimple`, `dnsmadeeasy`, `dnspod`, `do`, `domeneshop`, `dreamhost`, `duckdns`, `dynu`, `freedns`, `gandi`, `gehirn`, `glesys`, `godaddy`, `google`, `he`, `hetzner`, `infomaniak`, `inwx`, `ionos`, `linode`, `loopia`, `luadns`, `namecheap`, `netcup`, `njalla`, `nsone`, `ovh`, `porkbun`, `rfc2136`, `route53`, `sakuracloud`, `standalone`, `transip`, and `vultr`. Also need to enter the credentials into the corresponding ini (or json for some plugins) file under `/config/dns-conf`."} - {env_var: "CERT_PROFILE", env_value: "", desc: "Optionally define a cert profile to use for cert generation. This is useful if you want to use a custom cert profile instead of the default one. Currently only supported for Let's Encrypt. See https://letsencrypt.org/docs/profiles/ "}
- {env_var: "DNSPLUGIN", env_value: "cloudflare", desc: "Required if `VALIDATION` is set to `dns`. Options are `acmedns`, `aliyun`, `azure`, `bunny`, `cloudflare`, `cpanel`, `desec`, `digitalocean`, `directadmin`, `dnsimple`, `dnsmadeeasy`, `dnspod`, `do`, `domeneshop`, `dreamhost`, `duckdns`, `dynu`, `freedns`, `gandi`, `gehirn`, `glesys`, `godaddy`, `google`, `he`, `hetzner`, `hetzner-cloud`, `infomaniak`, `inwx`, `ionos`, `linode`, `loopia`, `luadns`, `mijn-host`, `namecheap`, `netcup`, `njalla`, `nsone`, `ovh`, `porkbun`, `rfc2136`, `route53`, `sakuracloud`, `standalone`, `transip`, and `vultr`. Also need to enter the credentials into the corresponding ini (or json for some plugins) file under `/config/dns-conf`."}
- {env_var: "PROPAGATION", env_value: "", desc: "Optionally override (in seconds) the default propagation time for the dns plugins."} - {env_var: "PROPAGATION", env_value: "", desc: "Optionally override (in seconds) the default propagation time for the dns plugins."}
- {env_var: "EMAIL", env_value: "", desc: "Optional e-mail address used for cert expiration notifications (Required for ZeroSSL)."} - {env_var: "EMAIL", env_value: "", desc: "Optional e-mail address used for cert expiration notifications (Required for ZeroSSL)."}
- {env_var: "ONLY_SUBDOMAINS", env_value: "false", desc: "If you wish to get certs only for certain subdomains, but not the main domain (main domain may be hosted on another machine and cannot be validated), set this to `true`"} - {env_var: "ONLY_SUBDOMAINS", env_value: "false", desc: "If you wish to get certs only for certain subdomains, but not the main domain (main domain may be hosted on another machine and cannot be validated), set this to `true`"}
@@ -65,7 +66,7 @@ app_setup_block: |
2. Certs that cover sub-subdomains of your main subdomain (ie. `*.yoursubdomain.duckdns.org`, set the `SUBDOMAINS` variable to `wildcard`) 2. Certs that cover sub-subdomains of your main subdomain (ie. `*.yoursubdomain.duckdns.org`, set the `SUBDOMAINS` variable to `wildcard`)
* `--cap-add=NET_ADMIN` is required for fail2ban to modify iptables * `--cap-add=NET_ADMIN` is required for fail2ban to modify iptables
* After setup, navigate to `https://example.com` to access the default homepage (http access through port 80 is disabled by default, you can enable it by editing the default site config at `/config/nginx/site-confs/default.conf`). * After setup, navigate to `https://example.com` to access the default homepage (http access through port 80 is disabled by default, you can enable it by editing the default site config at `/config/nginx/site-confs/default.conf`).
* Certs are checked nightly and if expiration is within 30 days, renewal is attempted. If your cert is about to expire in less than 30 days, check the logs under `/config/log/letsencrypt` to see why the renewals have been failing. It is recommended to input your e-mail in docker parameters so you receive expiration notices from Let's Encrypt in those circumstances. * Certs are checked twice daily using ACME Renewal Information (ARI) to determine the optimal renewal window. If your cert is about to expire, check the logs under `/config/log/letsencrypt` to see why the renewals have been failing.
### Certbot Plugins ### Certbot Plugins
@@ -177,7 +178,7 @@ init_diagram: |
init-mods-end -> init-custom-files init-mods-end -> init-custom-files
init-adduser -> init-device-perms init-adduser -> init-device-perms
base -> init-envfile base -> init-envfile
init-swag-samples -> init-fail2ban-config init-require-url -> init-fail2ban-config
init-os-end -> init-folders init-os-end -> init-folders
init-php -> init-keygen init-php -> init-keygen
base -> init-migrations base -> init-migrations
@@ -198,9 +199,10 @@ init_diagram: |
init-folders -> init-samples init-folders -> init-samples
init-custom-files -> init-services init-custom-files -> init-services
init-fail2ban-config -> init-swag-config init-fail2ban-config -> init-swag-config
init-require-url -> init-swag-folders init-permissions -> init-swag-folders
init-swag-folders -> init-swag-samples init-swag-folders -> init-swag-samples
init-permissions -> init-version-checks init-permissions -> init-version-checks
init-swag-samples -> init-version-checks
init-services -> svc-cron init-services -> svc-cron
svc-cron -> legacy-services svc-cron -> legacy-services
init-services -> svc-fail2ban init-services -> svc-fail2ban
@@ -213,11 +215,18 @@ init_diagram: |
svc-swag-auto-reload -> legacy-services svc-swag-auto-reload -> legacy-services
} }
Base Images: { Base Images: {
"baseimage-alpine-nginx:3.22" <- "baseimage-alpine:3.22" "baseimage-alpine-nginx:3.24" <- "baseimage-alpine:3.24"
} }
"swag:latest" <- Base Images "swag:latest" <- Base Images
# changelog # changelog
changelogs: changelogs:
- {date: "19.07.26:", desc: "Rebase to Alpine 3.24 with PHP 8.5."}
- {date: "10.07.26:", desc: "Add support for Let's Encrypt cert profiles. Run certbot twice daily with a random delay."}
- {date: "19.06.26:", desc: "Add support for mijn.host dns validation."}
- {date: "01.06.26:", desc: "Remove obsolete old cert check logic."}
- {date: "23.01.26:", desc: "Reorder init to fix proxy conf version checks."}
- {date: "21.12.25:", desc: "Add support for hetzner-cloud dns validation."}
- {date: "04.11.25:", desc: "Switch default Gandi credentials from API Key to Token, allow DNS propagation time for Azure DNS plugin."}
- {date: "18.07.25:", desc: "Rebase to Alpine 3.22 with PHP 8.4. Add QUIC support. Drop PHP bindings for mcrypt as it is no longer maintained."} - {date: "18.07.25:", desc: "Rebase to Alpine 3.22 with PHP 8.4. Add QUIC support. Drop PHP bindings for mcrypt as it is no longer maintained."}
- {date: "05.05.25:", desc: "Disable Certbot's built in log rotation."} - {date: "05.05.25:", desc: "Disable Certbot's built in log rotation."}
- {date: "19.01.25:", desc: "Add [Auto Reload](https://github.com/linuxserver/docker-mods/tree/swag-auto-reload) functionality to SWAG."} - {date: "19.01.25:", desc: "Add [Auto Reload](https://github.com/linuxserver/docker-mods/tree/swag-auto-reload) functionality to SWAG."}
+2 -3
View File
@@ -1,7 +1,6 @@
# Instructions: https://github.com/obynio/certbot-plugin-gandi#usage # Instructions: https://github.com/obynio/certbot-plugin-gandi#usage
# Replace with your value # Replace with your Gandi Live DNS v5 Personal Access Token
# live dns v5 api key dns_gandi_token=TOKEN
dns_gandi_api_key=APIKEY
# optional organization id, remove it if not used # optional organization id, remove it if not used
#dns_gandi_sharing_id=SHARINGID #dns_gandi_sharing_id=SHARINGID
+2
View File
@@ -0,0 +1,2 @@
# Hetzner Cloud API Token
dns_hetzner_cloud_api_token = your_api_token_here
+3
View File
@@ -0,0 +1,3 @@
# Instructions: https://github.com/mijnhost/certbot-dns-mijn-host
# Replace with your API key from your mijn.host account.
dns_mijn_host_api_key = yourapikeygoeshere
+1 -1
View File
@@ -1,4 +1,4 @@
# Instructions: https://github.com/certbot/certbot/blob/master/certbot-dns-ovh/certbot_dns_ovh/__init__.py#L20 # Instructions: https://github.com/certbot/certbot/blob/main/certbot-dns-ovh/src/certbot_dns_ovh/__init__.py#L24
# Replace with your values # Replace with your values
dns_ovh_endpoint = ovh-eu dns_ovh_endpoint = ovh-eu
dns_ovh_application_key = MDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAw dns_ovh_application_key = MDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAw
@@ -1,4 +1,4 @@
## Version 2025/07/18 - Changelog: https://github.com/linuxserver/docker-swag/commits/master/root/defaults/nginx/site-confs/default.conf.sample ## Version 2026/03/07 - Changelog: https://github.com/linuxserver/docker-swag/commits/master/root/defaults/nginx/site-confs/default.conf.sample
# redirect all traffic to https # redirect all traffic to https
server { server {
@@ -36,6 +36,9 @@ server {
# enable for Authentik (requires authentik-location.conf in the location block) # enable for Authentik (requires authentik-location.conf in the location block)
#include /config/nginx/authentik-server.conf; #include /config/nginx/authentik-server.conf;
# enable for Tinyauth (requires tinyauth-location.conf in the location block)
#include /config/nginx/tinyauth-server.conf;
location / { location / {
# enable for basic auth # enable for basic auth
#auth_basic "Restricted"; #auth_basic "Restricted";
@@ -50,6 +53,9 @@ server {
# enable for Authentik (requires authentik-server.conf in the server block) # enable for Authentik (requires authentik-server.conf in the server block)
#include /config/nginx/authentik-location.conf; #include /config/nginx/authentik-location.conf;
# enable for Tinyauth (requires tinyauth-server.conf in the server block)
#include /config/nginx/tinyauth-location.conf;
try_files $uri $uri/ /index.html /index.htm /index.php$is_args$args; try_files $uri $uri/ /index.html /index.htm /index.php$is_args$args;
} }
@@ -1,4 +1,4 @@
## Version 2025/06/08 - Changelog: https://github.com/linuxserver/docker-swag/commits/master/root/defaults/nginx/tinyauth-location.conf.sample ## Version 2025/12/17 - Changelog: https://github.com/linuxserver/docker-swag/commits/master/root/defaults/nginx/tinyauth-location.conf.sample
# Make sure that your tinyauth container is in the same user defined bridge network and is named tinyauth # Make sure that your tinyauth container is in the same user defined bridge network and is named tinyauth
# Rename /config/nginx/proxy-confs/tinyauth.subdomain.conf.sample to /config/nginx/proxy-confs/tinyauth.subdomain.conf # Rename /config/nginx/proxy-confs/tinyauth.subdomain.conf.sample to /config/nginx/proxy-confs/tinyauth.subdomain.conf
@@ -7,3 +7,17 @@ auth_request /tinyauth;
## If the subreqest returns 200 pass to the backend, if the subrequest returns 401 redirect to the portal ## If the subreqest returns 200 pass to the backend, if the subrequest returns 401 redirect to the portal
error_page 401 = @tinyauth_login; error_page 401 = @tinyauth_login;
## Translate the user information response headers from the auth subrequest into variables
auth_request_set $email $upstream_http_remote_email;
auth_request_set $groups $upstream_http_remote_groups;
auth_request_set $name $upstream_http_remote_name;
auth_request_set $user $upstream_http_remote_user;
## Inject the user information into the request made to the actual upstream
proxy_set_header Remote-Email $email;
proxy_set_header Remote-Groups $groups;
proxy_set_header Remote-Name $name;
proxy_set_header Remote-User $user;
## Can be extended with more custom headers https://tinyauth.app/docs/reference/headers#nginxnginx-proxy-manager
+1 -1
View File
@@ -5,4 +5,4 @@
0 3 * * 6 run-parts /etc/periodic/weekly 0 3 * * 6 run-parts /etc/periodic/weekly
0 5 1 * * run-parts /etc/periodic/monthly 0 5 1 * * run-parts /etc/periodic/monthly
8 2 * * * /app/le-renew.sh >> /config/log/letsencrypt/renewal.log 2>&1 0 */12 * * * sleep $((60 + $RANDOM % 230)); /app/le-renew.sh >> /config/log/letsencrypt/renewal.log 2>&1
@@ -12,12 +12,13 @@ EXTRA_DOMAINS=${EXTRA_DOMAINS}\\n\
ONLY_SUBDOMAINS=${ONLY_SUBDOMAINS}\\n\ ONLY_SUBDOMAINS=${ONLY_SUBDOMAINS}\\n\
VALIDATION=${VALIDATION}\\n\ VALIDATION=${VALIDATION}\\n\
CERTPROVIDER=${CERTPROVIDER}\\n\ CERTPROVIDER=${CERTPROVIDER}\\n\
CERT_PROFILE=${CERT_PROFILE}\\n\
DNSPLUGIN=${DNSPLUGIN}\\n\ DNSPLUGIN=${DNSPLUGIN}\\n\
EMAIL=${EMAIL}\\n\ EMAIL=${EMAIL}\\n\
STAGING=${STAGING}\\n" STAGING=${STAGING}\\n"
# Sanitize variables # Sanitize variables
SANED_VARS=(DNSPLUGIN EMAIL EXTRA_DOMAINS ONLY_SUBDOMAINS STAGING SUBDOMAINS URL VALIDATION CERTPROVIDER) SANED_VARS=(DNSPLUGIN EMAIL EXTRA_DOMAINS ONLY_SUBDOMAINS STAGING SUBDOMAINS URL VALIDATION CERTPROVIDER CERT_PROFILE)
for i in "${SANED_VARS[@]}"; do for i in "${SANED_VARS[@]}"; do
export echo "${i}"="${!i//\"/}" export echo "${i}"="${!i//\"/}"
export echo "${i}"="$(echo "${!i}" | tr '[:upper:]' '[:lower:]')" export echo "${i}"="$(echo "${!i}" | tr '[:upper:]' '[:lower:]')"
@@ -80,7 +81,7 @@ if [[ -f "/config/donoteditthisfile.conf" ]]; then
mv /config/donoteditthisfile.conf /config/.donoteditthisfile.conf mv /config/donoteditthisfile.conf /config/.donoteditthisfile.conf
fi fi
if [[ ! -f "/config/.donoteditthisfile.conf" ]]; then if [[ ! -f "/config/.donoteditthisfile.conf" ]]; then
echo -e "ORIGURL=\"${URL}\" ORIGSUBDOMAINS=\"${SUBDOMAINS}\" ORIGONLY_SUBDOMAINS=\"${ONLY_SUBDOMAINS}\" ORIGEXTRA_DOMAINS=\"${EXTRA_DOMAINS}\" ORIGVALIDATION=\"${VALIDATION}\" ORIGDNSPLUGIN=\"${DNSPLUGIN}\" ORIGPROPAGATION=\"${PROPAGATION}\" ORIGSTAGING=\"${STAGING}\" ORIGCERTPROVIDER=\"${CERTPROVIDER}\" ORIGEMAIL=\"${EMAIL}\"" >/config/.donoteditthisfile.conf echo -e "ORIGURL=\"${URL}\" ORIGSUBDOMAINS=\"${SUBDOMAINS}\" ORIGONLY_SUBDOMAINS=\"${ONLY_SUBDOMAINS}\" ORIGEXTRA_DOMAINS=\"${EXTRA_DOMAINS}\" ORIGVALIDATION=\"${VALIDATION}\" ORIGDNSPLUGIN=\"${DNSPLUGIN}\" ORIGPROPAGATION=\"${PROPAGATION}\" ORIGSTAGING=\"${STAGING}\" ORIGCERTPROVIDER=\"${CERTPROVIDER}\" ORIGEMAIL=\"${EMAIL}\" ORIGCERT_PROFILE=\"${CERT_PROFILE}\"" >/config/.donoteditthisfile.conf
echo "Created .donoteditthisfile.conf" echo "Created .donoteditthisfile.conf"
fi fi
@@ -168,9 +169,9 @@ fi
rm -rf /config/keys/letsencrypt rm -rf /config/keys/letsencrypt
if [[ "${ONLY_SUBDOMAINS}" = "true" ]] && [[ ! "${SUBDOMAINS}" = "wildcard" ]]; then if [[ "${ONLY_SUBDOMAINS}" = "true" ]] && [[ ! "${SUBDOMAINS}" = "wildcard" ]]; then
DOMAIN="$(echo "${SUBDOMAINS}" | tr ',' ' ' | awk '{print $1}').${URL}" DOMAIN="$(echo "${SUBDOMAINS}" | tr ',' ' ' | awk '{print $1}').${URL}"
ln -s /config/etc/letsencrypt/live/"${DOMAIN}" /config/keys/letsencrypt ln -s ../etc/letsencrypt/live/"${DOMAIN}" /config/keys/letsencrypt
else else
ln -s /config/etc/letsencrypt/live/"${URL}" /config/keys/letsencrypt ln -s ../etc/letsencrypt/live/"${URL}" /config/keys/letsencrypt
fi fi
# cleanup unused csr and keys folders # cleanup unused csr and keys folders
@@ -186,7 +187,8 @@ if [[ ! "${URL}" = "${ORIGURL}" ]] ||
[[ ! "${DNSPLUGIN}" = "${ORIGDNSPLUGIN}" ]] || [[ ! "${DNSPLUGIN}" = "${ORIGDNSPLUGIN}" ]] ||
[[ ! "${PROPAGATION}" = "${ORIGPROPAGATION}" ]] || [[ ! "${PROPAGATION}" = "${ORIGPROPAGATION}" ]] ||
[[ ! "${STAGING}" = "${ORIGSTAGING}" ]] || [[ ! "${STAGING}" = "${ORIGSTAGING}" ]] ||
[[ ! "${CERTPROVIDER}" = "${ORIGCERTPROVIDER}" ]]; then [[ ! "${CERTPROVIDER}" = "${ORIGCERTPROVIDER}" ]] ||
[[ ! "${CERT_PROFILE}" = "${ORIGCERT_PROFILE}" ]]; then
echo "Different validation parameters entered than what was used before. Revoking and deleting existing certificate, and an updated one will be created" echo "Different validation parameters entered than what was used before. Revoking and deleting existing certificate, and an updated one will be created"
if [[ "${ORIGCERTPROVIDER}" = "zerossl" ]]; then if [[ "${ORIGCERTPROVIDER}" = "zerossl" ]]; then
REV_ACMESERVER=("https://acme.zerossl.com/v2/DV90") REV_ACMESERVER=("https://acme.zerossl.com/v2/DV90")
@@ -204,19 +206,7 @@ if [[ ! "${URL}" = "${ORIGURL}" ]] ||
fi fi
# saving new variables # saving new variables
echo -e "ORIGURL=\"${URL}\" ORIGSUBDOMAINS=\"${SUBDOMAINS}\" ORIGONLY_SUBDOMAINS=\"${ONLY_SUBDOMAINS}\" ORIGEXTRA_DOMAINS=\"${EXTRA_DOMAINS}\" ORIGVALIDATION=\"${VALIDATION}\" ORIGDNSPLUGIN=\"${DNSPLUGIN}\" ORIGPROPAGATION=\"${PROPAGATION}\" ORIGSTAGING=\"${STAGING}\" ORIGCERTPROVIDER=\"${CERTPROVIDER}\" ORIGEMAIL=\"${EMAIL}\"" >/config/.donoteditthisfile.conf echo -e "ORIGURL=\"${URL}\" ORIGSUBDOMAINS=\"${SUBDOMAINS}\" ORIGONLY_SUBDOMAINS=\"${ONLY_SUBDOMAINS}\" ORIGEXTRA_DOMAINS=\"${EXTRA_DOMAINS}\" ORIGVALIDATION=\"${VALIDATION}\" ORIGDNSPLUGIN=\"${DNSPLUGIN}\" ORIGPROPAGATION=\"${PROPAGATION}\" ORIGSTAGING=\"${STAGING}\" ORIGCERTPROVIDER=\"${CERTPROVIDER}\" ORIGEMAIL=\"${EMAIL}\" ORIGCERT_PROFILE=\"${CERT_PROFILE}\"" >/config/.donoteditthisfile.conf
# Check if the cert is using the old LE root cert, revoke and regen if necessary
if [[ -f "/config/keys/letsencrypt/chain.pem" ]] && { [[ "${CERTPROVIDER}" == "letsencrypt" ]] || [[ "${CERTPROVIDER}" == "" ]]; } && [[ "${STAGING}" != "true" ]] && ! openssl x509 -in /config/keys/letsencrypt/chain.pem -noout -issuer | grep -q "ISRG Root X"; then
echo "The cert seems to be using the old LE root cert, which is no longer valid. Deleting and revoking."
REV_ACMESERVER=("https://acme-v02.api.letsencrypt.org/directory")
if [[ -f /config/etc/letsencrypt/live/"${ORIGDOMAIN}"/fullchain.pem ]]; then
certbot revoke --config-dir /config/etc/letsencrypt --logs-dir /config/log/letsencrypt --work-dir /tmp/letsencrypt --config /config/etc/letsencrypt/cli.ini --non-interactive --cert-path /config/etc/letsencrypt/live/"${ORIGDOMAIN}"/fullchain.pem --server "${REV_ACMESERVER[@]}" || true
else
certbot revoke --config-dir /config/etc/letsencrypt --logs-dir /config/log/letsencrypt --work-dir /tmp/letsencrypt --config /config/etc/letsencrypt/cli.ini --non-interactive --cert-name "${ORIGDOMAIN}" --server "${REV_ACMESERVER[@]}" || true
fi
rm -rf /config/etc/letsencrypt/{accounts,archive,live,renewal}
fi
# if zerossl is selected or staging is set to true, use the relevant server # if zerossl is selected or staging is set to true, use the relevant server
if [[ "${CERTPROVIDER}" = "zerossl" ]] && [[ "${STAGING}" = "true" ]]; then if [[ "${CERTPROVIDER}" = "zerossl" ]] && [[ "${STAGING}" = "true" ]]; then
@@ -239,6 +229,21 @@ fi
set_ini_value "server" "${ACMESERVER}" /config/etc/letsencrypt/cli.ini set_ini_value "server" "${ACMESERVER}" /config/etc/letsencrypt/cli.ini
# set certificate profile (e.g. "shortlived" for 6-day certs, "classic" for 90-day)
# Profiles are a Let's Encrypt ACME feature; ZeroSSL ignores it.
if [[ -n "${CERT_PROFILE}" ]]; then
if [[ "${CERTPROVIDER}" = "zerossl" ]]; then
echo "ZeroSSL does not support ACME profiles, ignoring CERT_PROFILE variable"
sed -i "/^preferred-profile\b/d" /config/etc/letsencrypt/cli.ini
else
echo "Requesting certificate with profile: ${CERT_PROFILE}"
set_ini_value "preferred-profile" "${CERT_PROFILE}" /config/etc/letsencrypt/cli.ini
fi
else
# remove if previously set so going back to default works
sed -i "/^preferred-profile\b/d" /config/etc/letsencrypt/cli.ini
fi
# figuring out domain only vs domain & subdomains vs subdomains only # figuring out domain only vs domain & subdomains vs subdomains only
DOMAINS_ARRAY=() DOMAINS_ARRAY=()
if [[ -z "${SUBDOMAINS}" ]] || [[ "${ONLY_SUBDOMAINS}" != true ]]; then if [[ -z "${SUBDOMAINS}" ]] || [[ "${ONLY_SUBDOMAINS}" != true ]]; then
@@ -303,7 +308,7 @@ if [[ "${VALIDATION}" = "dns" ]]; then
sed -i "/^dns-${DNSPLUGIN}-credentials\b/d" /config/etc/letsencrypt/cli.ini sed -i "/^dns-${DNSPLUGIN}-credentials\b/d" /config/etc/letsencrypt/cli.ini
fi fi
# plugins that don't support setting propagation # plugins that don't support setting propagation
if [[ "${DNSPLUGIN}" =~ ^(azure|gandi|route53|standalone)$ ]]; then if [[ "${DNSPLUGIN}" =~ ^(gandi|route53|standalone)$ ]]; then
if [[ -n "${PROPAGATION}" ]]; then echo "${DNSPLUGIN} dns plugin does not support setting propagation time"; fi if [[ -n "${PROPAGATION}" ]]; then echo "${DNSPLUGIN} dns plugin does not support setting propagation time"; fi
sed -i "/^dns-${DNSPLUGIN}-propagation-seconds\b/d" /config/etc/letsencrypt/cli.ini sed -i "/^dns-${DNSPLUGIN}-propagation-seconds\b/d" /config/etc/letsencrypt/cli.ini
fi fi
+1 -1
View File
@@ -3,7 +3,7 @@
# Check if the cert is expired or expires within a day, if so, renew # Check if the cert is expired or expires within a day, if so, renew
if openssl x509 -in /config/keys/letsencrypt/fullchain.pem -noout -checkend 86400 >/dev/null; then if openssl x509 -in /config/keys/letsencrypt/fullchain.pem -noout -checkend 86400 >/dev/null; then
echo "The cert does not expire within the next day. Letting the cron script handle the renewal attempts overnight (2:08am)." echo "The cert does not expire within the next day. Letting the cron script handle the renewal attempts."
else else
echo "The cert is either expired or it expires within the next day. Attempting to renew. This could take up to 10 minutes." echo "The cert is either expired or it expires within the next day. Attempting to renew. This could take up to 10 minutes."
/app/le-renew.sh /app/le-renew.sh