fix(mail): maddy cert-renew hook used $HOSTNAME, empty under cron
All checks were successful
CI / lint (push) Successful in 33s
CI / test (push) Successful in 14m57s
Deploy / notebooks (push) Has been skipped
Deploy / zotero (push) Has been skipped
Deploy / docs (push) Has been skipped
Deploy / api (push) Has been skipped
Deploy / mc (push) Has been skipped
CI / notebooks-smoke (push) Successful in 1m31s
Deploy / report (push) Successful in 13s
Notebooks Integration / notebooks-integration (push) Successful in 7m18s
Zotero Sync / zotero-sync (push) Successful in 55s
Package Supply Chain / pkg-supply-chain (push) Successful in 53s
All checks were successful
CI / lint (push) Successful in 33s
CI / test (push) Successful in 14m57s
Deploy / notebooks (push) Has been skipped
Deploy / zotero (push) Has been skipped
Deploy / docs (push) Has been skipped
Deploy / api (push) Has been skipped
Deploy / mc (push) Has been skipped
CI / notebooks-smoke (push) Successful in 1m31s
Deploy / report (push) Successful in 13s
Notebooks Integration / notebooks-integration (push) Successful in 7m18s
Zotero Sync / zotero-sync (push) Successful in 55s
Package Supply Chain / pkg-supply-chain (push) Successful in 53s
The daily /etc/cron.daily/maddy-cert-renew deploy-hook referenced
/etc/letsencrypt/live/${HOSTNAME}/, but HOSTNAME is unset in cron's
environment, so it expanded to /etc/letsencrypt/live//fullchain.pem —
the copy failed silently every renewal. certbot renewed the cert into
/etc/letsencrypt/live but it never reached /srv/mail/tls, so maddy kept
serving the old cert until it expired (2026-07-14), breaking IMAPS/SMTP
TLS for every client (caught by corwins sentinel as a mail-poller
CERTIFICATE_VERIFY_FAILED).
Use $RENEWED_LINEAGE — the cert-dir path certbot exports into the
deploy-hook environment — and single-quote the hook so it stays literal
until certbot expands it at deploy time. The live droplet was fixed
out-of-band (cert copied, maddy restarted, hook replaced); this makes a
fresh provision correct too.
This commit is contained in:
@@ -106,12 +106,18 @@ if [ -f "/etc/letsencrypt/live/${HOSTNAME}/fullchain.pem" ]; then
|
|||||||
fi
|
fi
|
||||||
|
|
||||||
# Daily renew hook — DNS-01 doesn't need port 80.
|
# Daily renew hook — DNS-01 doesn't need port 80.
|
||||||
|
#
|
||||||
|
# The deploy-hook references the cert dir by $RENEWED_LINEAGE, the path
|
||||||
|
# certbot exports into the hook's environment — NOT ${HOSTNAME}. Under cron
|
||||||
|
# HOSTNAME is unset, so the old hook expanded to
|
||||||
|
# /etc/letsencrypt/live//fullchain.pem, the copy failed silently, the
|
||||||
|
# renewed cert never reached /srv/mail/tls, and maddy served the stale cert
|
||||||
|
# until it expired (2026-07). Single-quoting the deploy-hook keeps
|
||||||
|
# $RENEWED_LINEAGE literal so certbot expands it at deploy time.
|
||||||
cat > /etc/cron.daily/maddy-cert-renew <<'CRON_EOF'
|
cat > /etc/cron.daily/maddy-cert-renew <<'CRON_EOF'
|
||||||
#!/bin/bash
|
#!/bin/bash
|
||||||
set -e
|
set -e
|
||||||
certbot renew --quiet --deploy-hook "cp /etc/letsencrypt/live/${HOSTNAME}/fullchain.pem /srv/mail/tls/ && \
|
certbot renew --quiet --deploy-hook 'cp "$RENEWED_LINEAGE/fullchain.pem" /srv/mail/tls/fullchain.pem && cp "$RENEWED_LINEAGE/privkey.pem" /srv/mail/tls/privkey.pem && chmod 644 /srv/mail/tls/fullchain.pem && chmod 600 /srv/mail/tls/privkey.pem && docker restart mail'
|
||||||
cp /etc/letsencrypt/live/${HOSTNAME}/privkey.pem /srv/mail/tls/ && \
|
|
||||||
docker restart mail"
|
|
||||||
CRON_EOF
|
CRON_EOF
|
||||||
chmod +x /etc/cron.daily/maddy-cert-renew
|
chmod +x /etc/cron.daily/maddy-cert-renew
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user