Writes configuration files for nginx based on running services and certificates
You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

generate.py 3.1KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465
  1. #!/usr/bin/env python3
  2. import argparse
  3. import etcdlib
  4. import jinja2
  5. import os
  6. import os.path
  7. parser = argparse.ArgumentParser()
  8. parser.add_argument('--name', help='Name of the docker host to request certificates for', default='unknown')
  9. parser.add_argument('--etcd-port', type=int, help='Port to connect to etcd on', default=2379)
  10. parser.add_argument('--etcd-host', help='Host to connect to etcd on', default='etcd')
  11. parser.add_argument('--etcd-prefix', help='Prefix to use when retrieving keys from etcd', default='/docker')
  12. parser.add_argument('--trusted-cert-path', help='Path to use for trusted CA certificate. Use "%s" for hostname', default='/letsencrypt/certs/%s/chain.pem')
  13. parser.add_argument('--cert-path', help='Path to use for certificates. Use "%s" for hostname', default='/letsencrypt/certs/%s/fullchain.pem')
  14. parser.add_argument('--cert-key-path', help='Path to use for certificate private keys. Use "%s" for hostname', default='/letsencrypt/certs/%s/privkey.pem')
  15. parser.add_argument('--wellknown-path', help='Path to use for wellknown directory for http-01 challenge.', default='/letsencrypt/well-known/')
  16. args = parser.parse_args()
  17. jinja_env = jinja2.Environment(loader=jinja2.FileSystemLoader('/'))
  18. template = jinja_env.get_template('nginx.tpl')
  19. fetcher = etcdlib.Connection(args.etcd_host, args.etcd_port, args.etcd_prefix)
  20. while True:
  21. wroteConfig = False;
  22. services = {}
  23. domains = {k: v.split(',') for k, v in fetcher.get_label('com.chameth.vhost').items()}
  24. protocols = fetcher.get_label('com.chameth.proxy.protocol')
  25. defaults = fetcher.get_label('com.chameth.proxy.default')
  26. loadbalance = fetcher.get_label('com.chameth.proxy.loadbalance')
  27. for container, values in fetcher.get_label('com.chameth.proxy').items():
  28. networks = fetcher.get_networks(container)
  29. certfile = args.cert_path % domains[container][0];
  30. up = 'lb_' + loadbalance[container] if container in loadbalance else 'ct_' + container
  31. if os.path.isfile(certfile):
  32. if not up in services:
  33. services[up] = {
  34. 'upstream': up,
  35. 'protocol': protocols[container] if container in protocols else 'http',
  36. 'vhosts': domains[container],
  37. 'hosts': [],
  38. 'certificate': args.cert_path % domains[container][0],
  39. 'trusted_certificate': args.trusted_cert_path % domains[container][0],
  40. 'certificate_key': args.cert_key_path % domains[container][0],
  41. 'default': container in defaults,
  42. }
  43. services[up]['hosts'].append({
  44. 'host': next(iter(networks.values())), # TODO: Pick a bridge sensibly?
  45. 'port': values,
  46. })
  47. if wroteConfig or len(services) > 0 or not os.path.isfile('/nginx-config/vhosts.conf'):
  48. with open('/nginx-config/vhosts.conf', 'w') as f:
  49. print('Writing vhosts.conf...', flush=True)
  50. f.write(template.render(services=services, wellknown_path=args.wellknown_path))
  51. wroteConfig = True;
  52. print('Done writing config.', flush=True)
  53. else:
  54. print('Not writing empty config. Ensure that your letsencrypt certificates are accessible to this container.')
  55. print('Done writing config.', flush=True)
  56. fetcher.wait_for_update()