4 Commits
Author SHA1 Message Date
bitdeals 45eb85fae8 refactor: move the renewal loop into a script, reset the base entrypoint
The loop lived in a shell-form ENTRYPOINT one-liner: unlintable, uncommentable,
and expanded by docker into two nested shells. It is a file now, and the loop
is CMD with the base image's `certbot` entrypoint reset — CMD is appended to
ENTRYPOINT rather than replacing it, so without the reset the loop would have
arrived as arguments to certbot. In exchange a one-off run replaces the loop
outright and needs no --entrypoint:

    docker run --rm -v letsencrypt:/etc/letsencrypt <image> certbot certificates

`wait $(jobs -p)` became a bare `wait`: the command substitution runs in a
subshell that reports the parent's jobs in bash but not in dash, and bare
`wait` waits for every background job in either. A failed pass is now reported
rather than passing silently, and the trap covers INT as well so Ctrl-C in an
interactive run works.

What this does not fix: a signal arriving while certbot is talking to Let's
Encrypt is held until that call returns, because a POSIX shell runs a trap only
after the foreground command finishes. That can outlast docker's ten-second
stop grace. Set stop_grace_period on the service if a clean stop matters.
2026-08-07 13:39:43 +00:00
private-user 12f9464fd4 add entrypoint
Build docker image and push to registry.bitdeals.org / main-build-job (push) Successful in 2m19s
2026-03-26 14:02:14 +03:00
private-user 84a470bdfe dockerfile fix 2024-11-19 12:10:04 +03:00
private-user 10e8804de5 add dockerfile and scripts 2024-11-02 13:20:43 +03:00