about summary refs log tree commit diff stats
path: root/internal/server/tls.go
diff options
context:
space:
mode:
authorAlan Pearce2024-07-09 20:32:15 +0200
committerAlan Pearce2024-07-10 20:04:21 +0200
commitde704a079eb09b0b9126cb44839d1c0a34014173 (patch)
tree35d63d7df9d0f7872885d56be3a57a904bef7f4d /internal/server/tls.go
parentbfc935f6ea7b00c539192e486936b8ffbb5a403e (diff)
downloadwebsite-de704a079eb09b0b9126cb44839d1c0a34014173.tar.lz
website-de704a079eb09b0b9126cb44839d1c0a34014173.tar.zst
website-de704a079eb09b0b9126cb44839d1c0a34014173.zip
add wildcard domain redirect support
Diffstat (limited to 'internal/server/tls.go')
-rw-r--r--internal/server/tls.go23
1 files changed, 23 insertions, 0 deletions
diff --git a/internal/server/tls.go b/internal/server/tls.go
index 9481b6a..556013d 100644
--- a/internal/server/tls.go
+++ b/internal/server/tls.go
@@ -12,6 +12,7 @@ import (
 	"github.com/ardanlabs/conf/v3"
 	"github.com/caddyserver/caddy/v2"
 	"github.com/caddyserver/certmagic"
+	"github.com/libdns/acmedns"
 	certmagic_redis "github.com/pberkel/caddy-storage-redis"
 	"gitlab.com/tozd/go/errors"
 )
@@ -24,6 +25,13 @@ type redisConfig struct {
 	KeyPrefix     string `conf:"default:certmagic"`
 }
 
+type acmeConfig struct {
+	Username  string `conf:"required"`
+	Password  string `conf:"required"`
+	Subdomain string `conf:"required"`
+	ServerURL string `conf:"env:SERVER_URL,default:https://acme.alanpearce.eu"`
+}
+
 func (s *Server) serveTLS() (err error) {
 	log := s.log.Named("tls")
 
@@ -72,6 +80,21 @@ func (s *Server) serveTLS() (err error) {
 			return errors.Wrap(err, "could not parse redis config")
 		}
 
+		acme := &acmedns.Provider{}
+		_, err = conf.Parse("ACME", acme)
+		if err != nil {
+			return errors.Wrap(err, "could not parse ACME config")
+		}
+
+		issuer.DNS01Solver = &certmagic.DNS01Solver{
+			DNSManager: certmagic.DNSManager{
+				DNSProvider: acme,
+				Logger:      certmagic.Default.Logger,
+			},
+		}
+
+		log.Debug("acme", "username", acme.Username, "subdomain", acme.Subdomain, "server_url", acme.ServerURL)
+
 		rs := certmagic_redis.New()
 		rs.Address = []string{rc.Address}
 		rs.Username = rc.Username