From 9fdbb10a45f243d102fd6a14e10646bc89fbe09f Mon Sep 17 00:00:00 2001 From: "push-app-to-main[bot]" <203845782+push-app-to-main[bot]@users.noreply.github.com> Date: Sat, 10 Oct 2026 09:11:09 +0200 Subject: [PATCH] Add certmate (ct) (#17803) Co-authored-by: push-app-to-main[bot] <203845782+push-app-to-main[bot]@users.noreply.github.com> --- ct/certmate.sh | 65 ++++++++++++++++++++++++++++++++++ install/certmate-install.sh | 69 +++++++++++++++++++++++++++++++++++++ 2 files changed, 134 insertions(+) create mode 100644 ct/certmate.sh create mode 100644 install/certmate-install.sh diff --git a/ct/certmate.sh b/ct/certmate.sh new file mode 100644 index 000000000..6cc25f89d --- /dev/null +++ b/ct/certmate.sh @@ -0,0 +1,65 @@ +#!/usr/bin/env bash +_cs_boot="${COMMUNITY_SCRIPTS_CORE_DIR:-$(dirname "${BASH_SOURCE[0]}")/../../core}/core/build.func" +source "$_cs_boot" 2>/dev/null || source <(curl -fsSL "${COMMUNITY_SCRIPTS_CORE_URL:-https://raw.githubusercontent.com/community-scripts/core/main}/core/build.func") +# Copyright (c) 2021-2026 community-scripts ORG +# Author: fabriziosalmi +# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE +# Source: https://github.com/fabriziosalmi/certmate + +APP="CertMate" +var_tags="${var_tags:-ssl;certificates;acme}" +var_cpu="${var_cpu:-2}" +var_ram="${var_ram:-2048}" +var_disk="${var_disk:-8}" +var_os="${var_os:-debian}" +var_version="${var_version:-13}" +#var_arm64="${var_arm64:-no}" # unset = ask the user; set yes/no only when verified +var_unprivileged="${var_unprivileged:-1}" + +header_info "$APP" +variables +color +catch_errors + +function update_script() { + header_info + check_container_storage + check_container_resources + + if [[ ! -d /opt/certmate ]]; then + msg_error "No ${APP} Installation Found!" + exit + fi + + if check_for_gh_release "certmate" "fabriziosalmi/certmate"; then + msg_info "Stopping CertMate" + systemctl stop certmate + msg_ok "Stopped CertMate" + + PYTHON_VERSION="3.12" setup_uv + CLEAN_INSTALL=1 fetch_and_deploy_gh_release "certmate" "fabriziosalmi/certmate" "tarball" + + msg_info "Installing CertMate Dependencies" + cd /opt/certmate + $STD uv venv --python 3.12 /opt/certmate/.venv + $STD uv pip sync --python /opt/certmate/.venv/bin/python requirements.lock + $STD /opt/certmate/.venv/bin/certbot --version + msg_ok "Installed CertMate Dependencies" + + msg_info "Starting CertMate" + systemctl start certmate + msg_ok "Started CertMate" + msg_ok "Updated successfully!" + fi + exit +} + +start +build_container +description + +msg_ok "Completed Successfully!\n" +echo -e "${CREATING}${GN}${APP} setup has been successfully initialized!${CL}" +echo -e "${INFO}${YW}Access it using the following URL:${CL}" +echo -e "${GATEWAY}${BGN}http://${IP}:8000${CL}" +echo -e "${INFO}${YW}The first page creates the admin account and asks for the API token: grep API_BEARER_TOKEN /opt/certmate_data/.env${CL}" diff --git a/install/certmate-install.sh b/install/certmate-install.sh new file mode 100644 index 000000000..ccef821e8 --- /dev/null +++ b/install/certmate-install.sh @@ -0,0 +1,69 @@ +#!/usr/bin/env bash + +# Copyright (c) 2021-2026 community-scripts ORG +# Author: fabriziosalmi +# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE +# Source: https://github.com/fabriziosalmi/certmate + +source /dev/stdin <<<"$FUNCTIONS_FILE_PATH" +color +verb_ip6 +catch_errors +setting_up_container +network_check +update_os + +PYTHON_VERSION="3.12" setup_uv +fetch_and_deploy_gh_release "certmate" "fabriziosalmi/certmate" "tarball" + +msg_info "Installing CertMate Dependencies" +cd /opt/certmate +$STD uv venv --python 3.12 /opt/certmate/.venv +# requirements.lock is the fully pinned set the official image is built from +$STD uv pip sync --python /opt/certmate/.venv/bin/python requirements.lock +$STD /opt/certmate/.venv/bin/certbot --version +msg_ok "Installed CertMate Dependencies" + +msg_info "Configuring CertMate" +mkdir -p /opt/certmate_data/{certificates,data,backups,logs} +cat </opt/certmate_data/.env +API_BEARER_TOKEN=$(openssl rand -hex 32) +SECRET_KEY=$(openssl rand -hex 32) +CERTMATE_BACKUP_PASSPHRASE=$(openssl rand -hex 32) +BEHIND_PROXY=false +EOF +chmod 600 /opt/certmate_data/.env +msg_ok "Configured CertMate" + +msg_info "Creating Service" +cat </etc/systemd/system/certmate.service +[Unit] +Description=CertMate SSL Certificate Manager +After=network-online.target +Wants=network-online.target + +[Service] +Type=simple +User=root +WorkingDirectory=/opt/certmate +Environment=PATH=/opt/certmate/.venv/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin +Environment=CERTMATE_CERT_DIR=/opt/certmate_data/certificates +Environment=CERTMATE_DATA_DIR=/opt/certmate_data/data +Environment=CERTMATE_BACKUP_DIR=/opt/certmate_data/backups +Environment=CERTMATE_LOGS_DIR=/opt/certmate_data/logs +Environment=ACME_CHALLENGES_DIR=/opt/certmate_data/data/acme-challenges +EnvironmentFile=/opt/certmate_data/.env +# One worker: the renewal scheduler, sessions and rate limits live in-process +ExecStart=/opt/certmate/.venv/bin/gunicorn --bind 0.0.0.0:8000 --workers 1 --threads 8 --timeout 300 --no-control-socket app:app +Restart=on-failure +RestartSec=5 + +[Install] +WantedBy=multi-user.target +EOF +systemctl enable -q --now certmate +msg_ok "Created Service" + +motd_ssh +customize +cleanup_lxc