-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathnew-domain.py
executable file
·171 lines (130 loc) · 4.11 KB
/
new-domain.py
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
#!/usr/bin/env python3
"""Утилита для автоматизации настройки нового поддомена.
Скрипт выполняет следующие действия:
- Создаёт директорию ~/Documents/<subdomain>
- Создаёт конфиг nginx из шаблона template.conf:
/etc/nginx/sites-available/<subdomain>.<domain>.conf
- Создаёт директорию для логов nginx:
/web/sites/kinside/<subdomain>.<domain>/logs
- Генерирует self-signed ssl сертификат:
/etc/nginx/certs/<subdomain>.<domain>.crt
/etc/nginx/certs/<subdomain>.<domain>.key
При запуске скрипта вы должны указать имя поддомена и опциональное
имя домена в аргументах:
new-domain.py <subdomain> [-d <domain>]
"""
import argparse
import pathlib
import subprocess
DOCUMENTS_DIRECTORY_PATH = pathlib.Path('/home/jam/Documents')
TEMPLATE_FILE_PATH = pathlib.Path('template.conf').resolve()
DEFAULT_DOMAIN_NAME = 'ktep-inside.local'
SITES_DIRECTORY_PATH = pathlib.Path('/web/sites/kinside')
CERTIFICATE_SUBJECT = {
'CN': 'KInsideAdmin',
'O': 'KTEP',
'OU': 'KInside',
'C': 'RU',
'ST': 'Kaluga region',
'L': 'Kaluga',
'emailAddress': 'ktep-inside@mail.ru',
}
NGINX_ROOT_PATH = pathlib.Path('/etc/nginx')
NGINX_SITES_AVAILABLE_PATH = NGINX_ROOT_PATH / 'sites-available'
NGINX_CERTIFICATES_PATH = NGINX_ROOT_PATH / 'certs'
def create_directory_in_documents(subdomain: str) -> None:
path = DOCUMENTS_DIRECTORY_PATH / subdomain
path.mkdir(exist_ok=True)
def create_nginx_config(
subdomain: str,
domain: str,
) -> None:
path = resolve_nginx_config_file_path(subdomain, domain)
content = generate_nginx_config_from_template(domain, subdomain)
path.write_text(content)
def resolve_nginx_config_file_path(
subdomain: str,
domain: str,
) -> pathlib.Path:
name = f'{subdomain}.{domain}.conf'
return NGINX_SITES_AVAILABLE_PATH / name
def generate_nginx_config_from_template(
subdomain: str,
domain: str,
) -> str:
content = TEMPLATE_FILE_PATH.read_text()
rendered_content = content.format(domain=domain, subdomain=subdomain)
return rendered_content
def create_logs_directory(
subdomain: str,
domain: str,
) -> None:
path = resolve_logs_directory_path(subdomain, domain)
path.mkdir(parents=True, exist_ok=True)
def resolve_logs_directory_path(
subdomain: str,
domain: str,
) -> pathlib.Path:
site_directory = f'{subdomain}.{domain}'
return SITES_DIRECTORY_PATH / site_directory / 'logs'
def create_ssl_certificate(
subdomain: str,
domain: str,
) -> None:
path = resolve_ssl_certificate_file_path(subdomain, domain)
key_path = resolve_ssl_certificate_key_file_path(subdomain, domain)
subject = generate_ssl_certificate_subject()
run_openssl(path, key_path, subject)
def resolve_ssl_certificate_file_path(
subdomain: str,
domain: str,
) -> pathlib.Path:
name = f'{subdomain}.{domain}.crt'
return NGINX_CERTIFICATES_PATH / name
def resolve_ssl_certificate_key_file_path(
subdomain: str,
domain: str,
) -> pathlib.Path:
name = f'{subdomain}.{domain}.key'
return NGINX_CERTIFICATES_PATH / name
def generate_ssl_certificate_subject() -> str:
string = ''
for key, value in CERTIFICATE_SUBJECT.items():
string += f'/{key}={value}'
return string
def run_openssl(
certificate_file_path: pathlib.Path,
certificate_key_file_path: pathlib.Path,
subject_string: str,
) -> None:
subprocess.run([
'openssl', 'req',
'-x509',
'-nodes',
'-days', '365',
'-newkey', 'rsa:2048',
'-out', certificate_file_path,
'-keyout', certificate_key_file_path,
'-subj', subject_string,
])
def parse_args() -> argparse.Namespace:
parser = argparse.ArgumentParser()
parser.add_argument(
'subdomain',
)
parser.add_argument(
'-d',
'--domain',
default=DEFAULT_DOMAIN_NAME,
)
return parser.parse_args()
def main():
args = parse_args()
subdomain = args.subdomain
domain = args.domain
create_directory_in_documents(subdomain)
create_nginx_config(subdomain, domain)
create_logs_directory(subdomain, domain)
create_ssl_certificate(subdomain, domain)
if __name__ == '__main__':
main()