Writes configuration files for nginx based on running services and certificates
選択できるのは25トピックまでです。 トピックは、先頭が英数字で、英数字とダッシュ('-')を使用した35文字以内のものにしてください。

generate.py 1.8KB

1234567891011121314151617181920212223242526272829303132333435363738394041
  1. #!/usr/bin/env python3
  2. from collections import defaultdict
  3. import argparse
  4. import etcdlib
  5. import jinja2
  6. import os
  7. parser = argparse.ArgumentParser()
  8. parser.add_argument('--name', help='Name of the docker host to request certificates for', default='unknown')
  9. parser.add_argument('--etcd-port', type=int, help='Port to connect to etcd on', default=2379)
  10. parser.add_argument('--etcd-host', help='Host to connect to etcd on', default='etcd')
  11. parser.add_argument('--etcd-prefix', help='Prefix to use when retrieving keys from etcd', default='/docker')
  12. parser.add_argument('--cert-path', help='Path to use for certificates. Use "%s" for hostname', default='/letsencrypt/certs/%s/fullchain.pem')
  13. parser.add_argument('--cert-key-path', help='Path to use for certificate private keys. Use "%s" for hostname', default='/letsencrypt/certs/%s/privkey.pem')
  14. args = parser.parse_args()
  15. jinja_env = jinja2.Environment(loader=jinja2.FileSystemLoader('/'))
  16. template = jinja_env.get_template('nginx.tpl')
  17. fetcher = etcdlib.Connection(args.etcd_host, args.etcd_port, args.etcd_prefix)
  18. while True:
  19. services = []
  20. domains = {k: v.split(',') for k, v in fetcher.get_label('com.chameth.vhost').items()}
  21. protocols = fetcher.get_label('com.chameth.proxy.protocol')
  22. for container, values in fetcher.get_label('com.chameth.proxy').items():
  23. networks = fetcher.get_networks(container)
  24. services.append({
  25. 'protocol': protocols[container] if container in protocols else 'http',
  26. 'vhosts': domains[container],
  27. 'host': next(iter(networks.values())), # TODO: Pick a bridge sensibly?
  28. 'port': values,
  29. 'certificate': args.cert_path % domains[container][0],
  30. 'certificate_key': args.cert_key_path % domains[container][0]
  31. })
  32. print(template.render(services=services)) # TODO: Actually write it out
  33. print('Done writing config.', flush=True)
  34. fetcher.wait_for_update()