File size: 1,916 Bytes
793e953 | 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 | #!/bin/bash
# ================================================================
# VetCopilot HTTPS 证书自动获取脚本
#
# 使用 Let's Encrypt + certbot 免费获取 SSL 证书
# 适用:阿里云 / 腾讯云 + 已备案域名
#
# 前置条件:
# 1. 域名已解析到服务器 IP
# 2. 80 端口已开放(防火墙/安全组)
# 3. Nginx 已启动
#
# 使用方法:
# chmod +x deploy/setup-https.sh
# sudo ./deploy/setup-https.sh your-domain.com your-email@example.com
# ================================================================
set -e
DOMAIN=${1:-""}
EMAIL=${2:-""}
if [ -z "$DOMAIN" ] || [ -z "$EMAIL" ]; then
echo "用法: $0 <域名> <邮箱>"
echo "示例: $0 vetcopilot.example.com admin@example.com"
exit 1
fi
echo "============================================"
echo "VetCopilot HTTPS 证书配置"
echo "域名: $DOMAIN"
echo "邮箱: $EMAIL"
echo "============================================"
# 安装 certbot
if ! command -v certbot &> /dev/null; then
echo "安装 certbot..."
apt-get update
apt-get install -y certbot python3-certbot-nginx
fi
# 获取证书(standalone 模式,certbot 临时启动 web 服务器验证)
echo "获取 SSL 证书..."
certbot certonly --standalone \
--non-interactive \
--agree-tos \
--email "$EMAIL" \
-d "$DOMAIN" \
--preferred-challenges http
# 更新 Nginx 配置中的域名
echo "更新 Nginx 配置..."
sed -i "s/YOUR_DOMAIN/$DOMAIN/g" /etc/nginx/conf.d/default.conf
# 重载 Nginx
echo "重载 Nginx..."
nginx -t && nginx -s reload
# 自动续期(已由 certbot timer 自动处理)
echo ""
echo "============================================"
echo "HTTPS 配置完成!"
echo "请访问: https://$DOMAIN"
echo ""
echo "证书自动续期已启用(certbot renew timer)"
echo "可手动续期测试: certbot renew --dry-run"
echo "============================================"
|