#!/bin/bash # ================================================================ # VetCopilot HTTPS 证书自动获取脚本 # # 使用 Let's Encrypt + certbot 免费获取 SSL 证书 # 适用:阿里云 / 腾讯云 + 已备案域名 # # 前置条件: # 1. 域名已解析到服务器 IP # 2. 80 端口已开放(防火墙/安全组) # 3. Nginx 已启动 # # 使用方法: # chmod +x deploy/setup-https.sh # sudo ./deploy/setup-https.sh your-domain.com your-email@example.com # ================================================================ set -e DOMAIN=${1:-""} EMAIL=${2:-""} if [ -z "$DOMAIN" ] || [ -z "$EMAIL" ]; then echo "用法: $0 <域名> <邮箱>" echo "示例: $0 vetcopilot.example.com admin@example.com" exit 1 fi echo "============================================" echo "VetCopilot HTTPS 证书配置" echo "域名: $DOMAIN" echo "邮箱: $EMAIL" echo "============================================" # 安装 certbot if ! command -v certbot &> /dev/null; then echo "安装 certbot..." apt-get update apt-get install -y certbot python3-certbot-nginx fi # 获取证书(standalone 模式,certbot 临时启动 web 服务器验证) echo "获取 SSL 证书..." certbot certonly --standalone \ --non-interactive \ --agree-tos \ --email "$EMAIL" \ -d "$DOMAIN" \ --preferred-challenges http # 更新 Nginx 配置中的域名 echo "更新 Nginx 配置..." sed -i "s/YOUR_DOMAIN/$DOMAIN/g" /etc/nginx/conf.d/default.conf # 重载 Nginx echo "重载 Nginx..." nginx -t && nginx -s reload # 自动续期(已由 certbot timer 自动处理) echo "" echo "============================================" echo "HTTPS 配置完成!" echo "请访问: https://$DOMAIN" echo "" echo "证书自动续期已启用(certbot renew timer)" echo "可手动续期测试: certbot renew --dry-run" echo "============================================"