配置服务器

This commit is contained in:
2026-07-07 11:43:03 +08:00
parent 98022b936f
commit 1dcc9aa1f4
2 changed files with 112 additions and 0 deletions
+59
View File
@@ -0,0 +1,59 @@
#!/usr/bin/env bash
# runxian.top 裸域名申请 Let's Encrypt 并启用 HTTPS
set -euo pipefail
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd)"
DOMAIN=runxian.top
EMAIL="${CERTBOT_EMAIL:-admin@runxian.top}"
echo "==> 检查 DNS: $DOMAIN"
ip="$(dig +short "$DOMAIN" A @223.5.5.5 | tail -1)"
if [[ -z "$ip" ]]; then
echo "ERROR: $DOMAIN 无 A 记录,请先在 DNS 添加指向本机公网 IP(当前服务器: $(curl -sf ifconfig.me || echo unknown)"
exit 1
fi
echo " $DOMAIN -> $ip"
mkdir -p /var/www/certbot /var/log/nginx/dukang
# 若尚未有证书,先部署仅 HTTP 的配置以便 ACME 校验
if [[ ! -f /etc/letsencrypt/live/runxian.top/fullchain.pem ]]; then
echo "==> 临时 HTTP 配置(用于 ACME..."
cat > /etc/nginx/conf.d/dukang-runxian-apex.conf <<'EOF'
server {
listen 80;
server_name runxian.top;
root /opt/dukang-haoke/public;
index index.html;
location ^~ /.well-known/acme-challenge/ {
root /var/www/certbot;
default_type "text/plain";
}
location ~ ^/MP_verify_.*\.txt$ {
default_type text/plain;
access_log off;
}
location / {
try_files $uri $uri/ =404;
}
}
EOF
nginx -t
systemctl reload nginx
fi
echo "==> 申请证书..."
certbot certonly --webroot -w /var/www/certbot \
--cert-name runxian.top \
-d runxian.top \
--non-interactive --agree-tos -m "$EMAIL"
echo "==> 切换 HTTPS 配置..."
install -m 644 "$SCRIPT_DIR/nginx-runxian-apex.conf" /etc/nginx/conf.d/dukang-runxian-apex.conf
nginx -t
systemctl reload nginx
echo "==> 验证..."
code="$(curl -sf -o /dev/null -w '%{http_code}' "https://$DOMAIN/MP_verify_ayPJ4CQqbUcec3jX.txt" || echo fail)"
echo " https://$DOMAIN/MP_verify_ayPJ4CQqbUcec3jX.txt -> $code"
echo "==> runxian.top HTTPS 已启用"
+53
View File
@@ -0,0 +1,53 @@
# runxian.top 裸域名 — 静态公共资源(微信域名校验等)
# HTTP: 保留 MP_verify + ACME;其余跳转 HTTPS
# HTTPS: deploy/enable-runxian-apex-ssl.sh 申请证书后启用
server {
listen 80;
server_name runxian.top;
access_log /var/log/nginx/dukang/runxian-apex.access.log main;
error_log /var/log/nginx/dukang/runxian-apex.error.log warn;
root /opt/dukang-haoke/public;
index index.html;
location ^~ /.well-known/acme-challenge/ {
root /var/www/certbot;
default_type "text/plain";
}
location ~ ^/MP_verify_.*\.txt$ {
default_type text/plain;
access_log off;
}
location / {
return 301 https://$host$request_uri;
}
}
server {
listen 443 ssl;
server_name runxian.top;
access_log /var/log/nginx/dukang/runxian-apex.access.log main;
error_log /var/log/nginx/dukang/runxian-apex.error.log warn;
ssl_certificate /etc/letsencrypt/live/runxian.top/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/runxian.top/privkey.pem;
ssl_protocols TLSv1.2 TLSv1.3;
ssl_prefer_server_ciphers on;
root /opt/dukang-haoke/public;
index index.html;
location ~ ^/MP_verify_.*\.txt$ {
default_type text/plain;
access_log off;
}
location / {
try_files $uri $uri/ =404;
}
}