Fix pasted certificate path handling

This commit is contained in:
i
2026-07-22 20:40:37 +08:00
parent abed566ba2
commit db476f533f
+31 -15
View File
@@ -133,6 +133,22 @@ read_multiline_block() {
printf -v "$var" '%s' "$block"
}
normalize_path() {
# normalize_path <path>
# Convert Windows drive-letter paths to MSYS-style paths when running under Git Bash.
local path="$1"
if [[ "$path" =~ ^[A-Za-z]:[\\/].* ]]; then
local drive="${path:0:1}"
local rest="${path:2}"
rest="${rest//\\//}"
rest="${rest#/}"
printf '/mnt/%s/%s' "${drive,,}" "$rest"
else
printf '%s' "$path"
fi
}
# ── Arg parsing ───────────────────────────────────────────────────────────────
DRY_RUN=false
OUTPUT_DIR="."
@@ -148,6 +164,7 @@ for arg in "$@"; do
esac
done
OUTPUT_DIR="$(normalize_path "$OUTPUT_DIR")"
mkdir -p "$OUTPUT_DIR"
# ── Banner ────────────────────────────────────────────────────────────────────
@@ -230,6 +247,7 @@ for (( i=1; i<=RELAY_COUNT; i++ )); do
# ── Output directory (ask first so we can read existing config) ───────────
ask RELAY_DIR " Output directory for this relay's files" "/opt/netbird-relay"
RELAY_DIR="$(normalize_path "$RELAY_DIR")"
# ── Load existing config as defaults if relay.env is present ─────────────
EX_DOMAIN=""; EX_LISTEN_PORT="443"; EX_LOG_LEVEL="info"
@@ -291,13 +309,14 @@ for (( i=1; i<=RELAY_COUNT; i++ )); do
| awk -F: '{print $1}' | sed 's/^ *- *//' || true
)"
ask CERT_HOST_PATH " Host path to certs directory" "${_EX_CERT_HOST:-/opt/1panel/www/sites/${DOMAIN}/ssl}"
CERT_HOST_PATH="$(normalize_path "$CERT_HOST_PATH")"
ask CERT_FILE " Cert file path inside container" "${EX_CERT_FILE:-/certs/fullchain.pem}"
ask KEY_FILE " Key file path inside container" "${EX_KEY_FILE:-/certs/privkey.pem}"
LE_EMAIL=""; LE_DATA_DIR=""
elif [[ "$TLS_MODE" == "4" ]]; then
echo ""
echo " ── Pasted certificate details ──"
CERT_HOST_PATH="${RELAY_DIR}/certs"
CERT_HOST_PATH="$(normalize_path "${RELAY_DIR}/certs")"
CERT_FILE="/certs/fullchain.pem"
KEY_FILE="/certs/privkey.pem"
LE_EMAIL=""; LE_DATA_DIR=""
@@ -305,6 +324,17 @@ for (( i=1; i<=RELAY_COUNT; i++ )); do
success " Certificate directory: ${CERT_HOST_PATH}"
read_multiline_block PASTED_CERT " Paste the certificate PEM" "END_CERT"
read_multiline_block PASTED_KEY " Paste the private key PEM" "END_KEY"
info " Writing pasted certificate ..."
printf '%s' "${PASTED_CERT}" > "${CERT_HOST_PATH}/fullchain.pem"
printf '%s' "${PASTED_KEY}" > "${CERT_HOST_PATH}/privkey.pem"
chmod 600 "${CERT_HOST_PATH}/privkey.pem"
if [[ ! -s "${CERT_HOST_PATH}/fullchain.pem" ]] || [[ ! -s "${CERT_HOST_PATH}/privkey.pem" ]]; then
error " Failed to write pasted certificate files to ${CERT_HOST_PATH}."
error " Please re-run and paste complete PEM blocks ending with END_CERT and END_KEY."
exit 1
fi
success " Certificate : ${CERT_HOST_PATH}/fullchain.pem"
success " Private key : ${CERT_HOST_PATH}/privkey.pem"
else
echo ""
echo " ── Self-signed certificate details ──"
@@ -570,20 +600,6 @@ volumes:
info " SANs : ${SS_SANS}"
info " Valid for : ${SS_DAYS} days"
fi
if [[ "$TLS_MODE" == "4" ]]; then
info " Writing pasted certificate ..."
mkdir -p "${CERT_HOST_PATH}"
printf '%s' "${PASTED_CERT}" > "${CERT_HOST_PATH}/fullchain.pem"
printf '%s' "${PASTED_KEY}" > "${CERT_HOST_PATH}/privkey.pem"
chmod 600 "${CERT_HOST_PATH}/privkey.pem"
if [[ ! -s "${CERT_HOST_PATH}/fullchain.pem" ]] || [[ ! -s "${CERT_HOST_PATH}/privkey.pem" ]]; then
error " Failed to write pasted certificate files to ${CERT_HOST_PATH}."
error " Please re-run and paste complete PEM blocks ending with END_CERT and END_KEY."
exit 1
fi
success " Certificate : ${CERT_HOST_PATH}/fullchain.pem"
success " Private key : ${CERT_HOST_PATH}/privkey.pem"
fi
fi
fi