add dev/scripts/install_certs.sh for automated cert trust setup
Some checks failed
ci/woodpecker/push/infra-ci Pipeline was successful
ci/woodpecker/push/deploy Pipeline failed
coverage 99% coverage
ci/woodpecker/push/ci Pipeline was successful

Installs the self-signed homelab CA into:
- System trust store (update-ca-certificates)
- Firefox profiles (~/.mozilla and ~/.config/mozilla)
- Chromium/Chrome (~/.pki/nssdb)
- Prints NODE_EXTRA_CA_CERTS export for Node.js

Run once after clone: ./dev/scripts/install_certs.sh
This commit is contained in:
kert
2026-03-21 16:25:48 -04:00
parent 3a60d65e19
commit d45f60deb6

51
dev/scripts/install_certs.sh Executable file
View File

@@ -0,0 +1,51 @@
#!/usr/bin/env bash
# Install the homelab self-signed CA into the local trust stores.
# Run once after cloning the repo or regenerating certs.
#
# Usage: ./dev/scripts/install_certs.sh
set -uo pipefail
CERT="$(cd "$(dirname "$0")/../.." && pwd)/traefik/certs/homelab.crt"
if [ ! -f "$CERT" ]; then
echo "ERROR: $CERT not found. Run from the project root."
exit 1
fi
echo "Installing homelab CA from $CERT"
# ── System trust store (Debian/Ubuntu) ────────────────────────
if command -v update-ca-certificates &>/dev/null; then
echo " → system trust store (update-ca-certificates)"
sudo cp "$CERT" /usr/local/share/ca-certificates/homelab-fhirworx.crt
sudo update-ca-certificates 2>/dev/null
fi
# ── Firefox (all profiles) ────────────────────────────────────
if command -v certutil &>/dev/null; then
echo " → Firefox profiles"
find "$HOME/.mozilla/firefox" "$HOME/.config/mozilla/firefox" -name "cert9.db" -printf '%h\n' 2>/dev/null | sort -u | while read -r dir; do
profile="$(basename "$dir")"
echo " profile: $profile"
certutil -d "sql:$dir" -A -t "C,," -n "homelab-fhirworx" -i "$CERT" 2>/dev/null || true
done
else
echo " ⚠ certutil not found — install libnss3-tools for Firefox cert import"
echo " sudo apt install libnss3-tools"
fi
# ── Chromium / Chrome ─────────────────────────────────────────
NSS_DB="$HOME/.pki/nssdb"
if [ -d "$NSS_DB" ] && command -v certutil &>/dev/null; then
echo " → Chromium/Chrome ($NSS_DB)"
certutil -d "sql:$NSS_DB" -A -t "C,," -n "homelab-fhirworx" -i "$CERT" 2>/dev/null || true
fi
# ── Node.js (for Docusaurus builds) ──────────────────────────
echo " → NODE_EXTRA_CA_CERTS=$CERT"
echo " Add to your shell profile:"
echo " export NODE_EXTRA_CA_CERTS=$CERT"
echo ""
echo "Done. Restart Firefox/Chrome to pick up the new CA."
echo "HTTPS: https://docs.homelab.fhirworx.io should now load without warnings."