浏览代码

jakies drobne zmiany

master
Lukasz Jarosz 6 年前
父节点
当前提交
02fe87463c
共有 2 个文件被更改,包括 5 次插入2 次删除
  1. 4
    1
      README.md
  2. 1
    1
      files/usr/bin/ssl-auto-renew

+ 4
- 1
README.md 查看文件

@@ -11,4 +11,7 @@ MariaDB is automatically bootstrapped into /data/mariadb. To add additional my.c
11 11
 
12 12
 ## SSL
13 13
 Image supports using SSL with nginx which acts as reverse proxy for Gitea. It has embedded Lets Encrypt support with auto renewal. If you don't have account.key script will generate it for you.
14
-Required files for cert are /data/ssl/cert.crt /data/ssl/cert.key . 
14
+Required files for cert are /data/ssl/cert.crt /data/ssl/cert.key .
15
+
16
+## Gitea
17
+There are a few tweaks to app.ini template. Most of them are around disabling unecessary logs and features that may lead to potentional exploit of installation.  

+ 1
- 1
files/usr/bin/ssl-auto-renew 查看文件

@@ -5,6 +5,6 @@ if [ -n $ENABLE_SSL ]; then
5 5
     [[ ! -f $file ]] && exit
6 6
   done
7 7
 
8
-  python3 -m acme_tiny --account-key /data/ssl/account.key --csr /data/ssl/domain.csr --acme-dir /run/nginx/challenges > /data/ssl/cert.crt
8
+  python3 -m acme_tiny --account-key /data/ssl/account.key --csr /data/ssl/domain.csr --acme-dir /run/nginx/challenges > /tmp/cert.crt && mv /tmp/cert.crt /data/ssl/cert.crt
9 9
   s6-svc -du /etc/s6/nginx
10 10
 fi

正在加载...
取消
保存