From 6d8c4218f171305324c71fcf1810081d21b6c232 Mon Sep 17 00:00:00 2001 From: chaptergy Date: Thu, 7 Oct 2021 17:13:48 +0200 Subject: [PATCH] Replaces fixed certbot plugin version with optional version requirements --- backend/internal/certificate.js | 2 +- backend/setup.js | 2 +- global/certbot-dns-plugins.js | 104 ++++++++++++++++---------------- 3 files changed, 54 insertions(+), 54 deletions(-) diff --git a/backend/internal/certificate.js b/backend/internal/certificate.js index 8a4369bf..7ec2a4e0 100644 --- a/backend/internal/certificate.js +++ b/backend/internal/certificate.js @@ -869,7 +869,7 @@ const internalCertificate = { const credentialsLocation = '/etc/letsencrypt/credentials/credentials-' + certificate.id; const credentialsCmd = 'mkdir -p /etc/letsencrypt/credentials 2> /dev/null; echo \'' + certificate.meta.dns_provider_credentials.replace('\'', '\\\'') + '\' > \'' + credentialsLocation + '\' && chmod 600 \'' + credentialsLocation + '\''; - const prepareCmd = 'pip install ' + dns_plugin.package_name + '==' + dns_plugin.package_version + ' ' + dns_plugin.dependencies; + const prepareCmd = 'pip install ' + dns_plugin.package_name + (dns_plugin.version_requirement || '') + ' ' + dns_plugin.dependencies; // Whether the plugin has a ---credentials argument const hasConfigArg = certificate.meta.dns_provider !== 'route53'; diff --git a/backend/setup.js b/backend/setup.js index 4d614baf..41436c8f 100644 --- a/backend/setup.js +++ b/backend/setup.js @@ -175,7 +175,7 @@ const setupCertbotPlugins = () => { certificates.map(function (certificate) { if (certificate.meta && certificate.meta.dns_challenge === true) { const dns_plugin = dns_plugins[certificate.meta.dns_provider]; - const packages_to_install = `${dns_plugin.package_name}==${dns_plugin.package_version} ${dns_plugin.dependencies}`; + const packages_to_install = `${dns_plugin.package_name}${dns_plugin.version_requirement || ''} ${dns_plugin.dependencies}`; if (plugins.indexOf(packages_to_install) === -1) plugins.push(packages_to_install); diff --git a/global/certbot-dns-plugins.js b/global/certbot-dns-plugins.js index 85057073..e3bc9aac 100644 --- a/global/certbot-dns-plugins.js +++ b/global/certbot-dns-plugins.js @@ -9,7 +9,7 @@ * cloudflare: { * display_name: "Name displayed to the user", * package_name: "Package name in PyPi repo", - * package_version: "Package version in PyPi repo", + * version_requirement: "Optional package version requirements (e.g. ==1.3 or >=1.2,<2.0, see https://www.python.org/dev/peps/pep-0440/#version-specifiers)", * dependencies: "Additional dependencies, space separated (as you would pass it to pip install)", * credentials: `Template of the credentials file`, * full_plugin_name: "The full plugin name as used in the commandline with certbot, including prefixes, e.g. 'certbot-dns-njalla:dns-njalla'", @@ -24,7 +24,7 @@ module.exports = { acmedns: { display_name: 'ACME-DNS', package_name: 'certbot-dns-acmedns', - package_version: '0.1.0', + version_requirement: '~=0.1.0', dependencies: '', credentials: `certbot_dns_acmedns:dns_acmedns_api_url = http://acmedns-server/ certbot_dns_acmedns:dns_acmedns_registration_file = /data/acme-registration.json`, @@ -33,7 +33,7 @@ certbot_dns_acmedns:dns_acmedns_registration_file = /data/acme-registration.json aliyun: { display_name: 'Aliyun', package_name: 'certbot-dns-aliyun', - package_version: '0.38.1', + version_requirement: '~=0.38.1', dependencies: '', credentials: `certbot_dns_aliyun:dns_aliyun_access_key = 12345678 certbot_dns_aliyun:dns_aliyun_access_key_secret = 1234567890abcdef1234567890abcdef`, @@ -43,7 +43,7 @@ certbot_dns_aliyun:dns_aliyun_access_key_secret = 1234567890abcdef1234567890abcd azure: { display_name: 'Azure', package_name: 'certbot-dns-azure', - package_version: '1.2.0', + version_requirement: '~=1.2.0', dependencies: '', credentials: `# This plugin supported API authentication using either Service Principals or utilizing a Managed Identity assigned to the virtual machine. # Regardless which authentication method used, the identity will need the “DNS Zone Contributor” role assigned to it. @@ -69,7 +69,7 @@ dns_azure_zone2 = example.org:/subscriptions/99800903-fb14-4992-9aff-12eaf274462 cloudflare: { display_name: 'Cloudflare', package_name: 'certbot-dns-cloudflare', - package_version: '1.8.0', + // version_requirement: '', // Official plugin, no version requirement dependencies: 'cloudflare', credentials: `# Cloudflare API token dns_cloudflare_api_token = 0123456789abcdef0123456789abcdef01234567`, @@ -79,7 +79,7 @@ dns_cloudflare_api_token = 0123456789abcdef0123456789abcdef01234567`, cloudns: { display_name: 'ClouDNS', package_name: 'certbot-dns-cloudns', - package_version: '0.4.0', + version_requirement: '~=0.4.0', dependencies: '', credentials: `# Target user ID (see https://www.cloudns.net/api-settings/) dns_cloudns_auth_id=1234 @@ -95,7 +95,7 @@ dns_cloudflare_api_token = 0123456789abcdef0123456789abcdef01234567`, cloudxns: { display_name: 'CloudXNS', package_name: 'certbot-dns-cloudxns', - package_version: '1.8.0', + // version_requirement: '', // Official plugin, no version requirement dependencies: '', credentials: `dns_cloudxns_api_key = 1234567890abcdef1234567890abcdef dns_cloudxns_secret_key = 1122334455667788`, @@ -105,7 +105,7 @@ dns_cloudxns_secret_key = 1122334455667788`, corenetworks: { display_name: 'Core Networks', package_name: 'certbot-dns-corenetworks', - package_version: '0.1.4', + version_requirement: '~=0.1.4', dependencies: '', credentials: `certbot_dns_corenetworks:dns_corenetworks_username = asaHB12r certbot_dns_corenetworks:dns_corenetworks_password = secure_password`, @@ -115,7 +115,7 @@ certbot_dns_corenetworks:dns_corenetworks_password = secure_password`, cpanel: { display_name: 'cPanel', package_name: 'certbot-dns-cpanel', - package_version: '0.2.2', + version_requirement: '~=0.2.2', dependencies: '', credentials: `certbot_dns_cpanel:cpanel_url = https://cpanel.example.com:2083 certbot_dns_cpanel:cpanel_username = user @@ -123,10 +123,20 @@ certbot_dns_cpanel:cpanel_password = hunter2`, full_plugin_name: 'certbot-dns-cpanel:cpanel', }, //####################################################// + desec: { + display_name: 'deSEC', + package_name: 'certbot-dns-desec', + version_requirement: '~=0.3.0', + dependencies: '', + credentials: `certbot_dns_desec:dns_desec_token = YOUR_DESEC_API_TOKEN +certbot_dns_desec:dns_desec_endpoint = https://desec.io/api/v1/`, + full_plugin_name: 'certbot-dns-desec:dns-desec', + }, + //####################################################// duckdns: { display_name: 'DuckDNS', package_name: 'certbot-dns-duckdns', - package_version: '0.6', + version_requirement: '~=0.6', dependencies: '', credentials: 'dns_duckdns_token=your-duckdns-token', full_plugin_name: 'dns-duckdns', @@ -135,7 +145,7 @@ certbot_dns_cpanel:cpanel_password = hunter2`, digitalocean: { display_name: 'DigitalOcean', package_name: 'certbot-dns-digitalocean', - package_version: '1.8.0', + // version_requirement: '', // Official plugin, no version requirement dependencies: '', credentials: 'dns_digitalocean_token = 0000111122223333444455556666777788889999aaaabbbbccccddddeeeeffff', full_plugin_name: 'dns-digitalocean', @@ -144,18 +154,18 @@ certbot_dns_cpanel:cpanel_password = hunter2`, directadmin: { display_name: 'DirectAdmin', package_name: 'certbot-dns-directadmin', - package_version: '0.0.23', + version_requirement: '~=0.0.23', dependencies: '', credentials: `directadmin_url = https://my.directadminserver.com:2222 directadmin_username = username directadmin_password = aSuperStrongPassword`, - full_plugin_name: 'certbot-dns-directadmin:directadmin', + full_plugin_name: 'directadmin', }, //####################################################// dnsimple: { display_name: 'DNSimple', package_name: 'certbot-dns-dnsimple', - package_version: '1.8.0', + // version_requirement: '', // Official plugin, no version requirement dependencies: '', credentials: 'dns_dnsimple_token = MDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAw', full_plugin_name: 'dns-dnsimple', @@ -164,7 +174,7 @@ directadmin_password = aSuperStrongPassword`, dnsmadeeasy: { display_name: 'DNS Made Easy', package_name: 'certbot-dns-dnsmadeeasy', - package_version: '1.8.0', + // version_requirement: '', // Official plugin, no version requirement dependencies: '', credentials: `dns_dnsmadeeasy_api_key = 1c1a3c91-4770-4ce7-96f4-54c0eb0e457a dns_dnsmadeeasy_secret_key = c9b5625f-9834-4ff8-baba-4ed5f32cae55`, @@ -174,7 +184,7 @@ dns_dnsmadeeasy_secret_key = c9b5625f-9834-4ff8-baba-4ed5f32cae55`, dnspod: { display_name: 'DNSPod', package_name: 'certbot-dns-dnspod', - package_version: '0.1.0', + version_requirement: '~=0.1.0', dependencies: '', credentials: `certbot_dns_dnspod:dns_dnspod_email = "DNSPOD-API-REQUIRES-A-VALID-EMAIL" certbot_dns_dnspod:dns_dnspod_api_token = "DNSPOD-API-TOKEN"`, @@ -184,7 +194,7 @@ certbot_dns_dnspod:dns_dnspod_api_token = "DNSPOD-API-TOKEN"`, dynu: { display_name: 'Dynu', package_name: 'certbot-dns-dynu', - package_version: '0.0.1', + version_requirement: '~=0.0.1', dependencies: '', credentials: 'certbot_dns_dynu:dns_dynu_auth_token = YOUR_DYNU_AUTH_TOKEN', full_plugin_name: 'certbot-dns-dynu:dns-dynu', @@ -193,7 +203,7 @@ certbot_dns_dnspod:dns_dnspod_api_token = "DNSPOD-API-TOKEN"`, eurodns: { display_name: 'EuroDNS', package_name: 'certbot-dns-eurodns', - package_version: '0.0.4', + version_requirement: '~=0.0.4', dependencies: '', credentials: `dns_eurodns_applicationId = myuser dns_eurodns_apiKey = mysecretpassword @@ -204,7 +214,7 @@ dns_eurodns_endpoint = https://rest-api.eurodns.com/user-api-gateway/proxy`, gandi: { display_name: 'Gandi Live DNS', package_name: 'certbot_plugin_gandi', - package_version: '1.2.5', + version_requirement: '~=1.2.5', dependencies: '', credentials: 'certbot_plugin_gandi:dns_api_key = APIKEY', full_plugin_name: 'certbot-plugin-gandi:dns', @@ -213,7 +223,7 @@ dns_eurodns_endpoint = https://rest-api.eurodns.com/user-api-gateway/proxy`, godaddy: { display_name: 'GoDaddy', package_name: 'certbot-dns-godaddy', - package_version: '0.2.0', + version_requirement: '~=0.2.0', dependencies: '', credentials: `dns_godaddy_secret = 0123456789abcdef0123456789abcdef01234567 dns_godaddy_key = abcdef0123456789abcdef01234567abcdef0123`, @@ -223,7 +233,7 @@ dns_godaddy_key = abcdef0123456789abcdef01234567abcdef0123`, google: { display_name: 'Google', package_name: 'certbot-dns-google', - package_version: '1.8.0', + // version_requirement: '', // Official plugin, no version requirement dependencies: '', credentials: `{ "type": "service_account", @@ -235,7 +245,7 @@ dns_godaddy_key = abcdef0123456789abcdef01234567abcdef0123`, hetzner: { display_name: 'Hetzner', package_name: 'certbot-dns-hetzner', - package_version: '1.0.4', + version_requirement: '~=1.0.4', dependencies: '', credentials: 'certbot_dns_hetzner:dns_hetzner_api_token = 0123456789abcdef0123456789abcdef', full_plugin_name: 'certbot-dns-hetzner:dns-hetzner', @@ -244,7 +254,7 @@ dns_godaddy_key = abcdef0123456789abcdef01234567abcdef0123`, infomaniak: { display_name: 'Infomaniak', package_name: 'certbot-dns-infomaniak', - package_version: '0.1.12', + version_requirement: '~=0.1.12', dependencies: '', credentials: 'certbot_dns_infomaniak:dns_infomaniak_token = XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX', full_plugin_name: 'certbot-dns-infomaniak:dns-infomaniak', @@ -253,7 +263,7 @@ dns_godaddy_key = abcdef0123456789abcdef01234567abcdef0123`, inwx: { display_name: 'INWX', package_name: 'certbot-dns-inwx', - package_version: '2.1.2', + version_requirement: '~=2.1.2', dependencies: '', credentials: `certbot_dns_inwx:dns_inwx_url = https://api.domrobot.com/xmlrpc/ certbot_dns_inwx:dns_inwx_username = your_username @@ -265,7 +275,7 @@ certbot_dns_inwx:dns_inwx_shared_secret = your_shared_secret optional`, ionos: { display_name: 'IONOS', package_name: 'certbot-dns-ionos', - package_version: '0.0.7', + version_requirement: '~=0.0.7', dependencies: '', credentials: `certbot_dns_ionos:dns_ionos_prefix = myapikeyprefix certbot_dns_ionos:dns_ionos_secret = verysecureapikeysecret @@ -276,7 +286,7 @@ certbot_dns_ionos:dns_ionos_endpoint = https://api.hosting.ionos.com`, ispconfig: { display_name: 'ISPConfig', package_name: 'certbot-dns-ispconfig', - package_version: '0.2.0', + version_requirement: '~=0.2.0', dependencies: '', credentials: `certbot_dns_ispconfig:dns_ispconfig_username = myremoteuser certbot_dns_ispconfig:dns_ispconfig_password = verysecureremoteuserpassword @@ -287,7 +297,7 @@ certbot_dns_ispconfig:dns_ispconfig_endpoint = https://localhost:8080`, isset: { display_name: 'Isset', package_name: 'certbot-dns-isset', - package_version: '0.0.3', + version_requirement: '~=0.0.3', dependencies: '', credentials: `certbot_dns_isset:dns_isset_endpoint="https://customer.isset.net/api" certbot_dns_isset:dns_isset_token=""`, @@ -296,7 +306,7 @@ certbot_dns_isset:dns_isset_token=""`, joker: { display_name: 'Joker', package_name: 'certbot-dns-joker', - package_version: '1.1.0', + version_requirement: '~=1.1.0', dependencies: '', credentials: `certbot_dns_joker:dns_joker_username = certbot_dns_joker:dns_joker_password = @@ -307,7 +317,7 @@ certbot_dns_joker:dns_joker_domain = `, linode: { display_name: 'Linode', package_name: 'certbot-dns-linode', - package_version: '1.8.0', + // version_requirement: '', // Official plugin, no version requirement dependencies: '', credentials: `dns_linode_key = 0123456789abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ64 dns_linode_version = [|3|4]`, @@ -317,7 +327,7 @@ dns_linode_version = [|3|4]`, loopia: { display_name: 'Loopia', package_name: 'certbot-dns-loopia', - package_version: '1.0.0', + version_requirement: '~=1.0.0', dependencies: '', credentials: `dns_loopia_user = user@loopiaapi dns_loopia_password = abcdef0123456789abcdef01234567abcdef0123`, @@ -327,7 +337,7 @@ dns_loopia_password = abcdef0123456789abcdef01234567abcdef0123`, luadns: { display_name: 'LuaDNS', package_name: 'certbot-dns-luadns', - package_version: '1.8.0', + // version_requirement: '', // Official plugin, no version requirement dependencies: '', credentials: `dns_luadns_email = user@example.com dns_luadns_token = 0123456789abcdef0123456789abcdef`, @@ -337,7 +347,7 @@ dns_luadns_token = 0123456789abcdef0123456789abcdef`, netcup: { display_name: 'netcup', package_name: 'certbot-dns-netcup', - package_version: '1.0.0', + version_requirement: '~=1.0.0', dependencies: '', credentials: `certbot_dns_netcup:dns_netcup_customer_id = 123456 certbot_dns_netcup:dns_netcup_api_key = 0123456789abcdef0123456789abcdef01234567 @@ -348,7 +358,7 @@ certbot_dns_netcup:dns_netcup_api_password = abcdef0123456789abcdef01234567abcde njalla: { display_name: 'Njalla', package_name: 'certbot-dns-njalla', - package_version: '1.0.0', + version_requirement: '~=1.0.0', dependencies: '', credentials: 'certbot_dns_njalla:dns_njalla_token = 0123456789abcdef0123456789abcdef01234567', full_plugin_name: 'certbot-dns-njalla:dns-njalla', @@ -357,7 +367,7 @@ certbot_dns_netcup:dns_netcup_api_password = abcdef0123456789abcdef01234567abcde nsone: { display_name: 'NS1', package_name: 'certbot-dns-nsone', - package_version: '1.8.0', + // version_requirement: '', // Official plugin, no version requirement dependencies: '', credentials: 'dns_nsone_api_key = MDAwMDAwMDAwMDAwMDAw', full_plugin_name: 'dns-nsone', @@ -366,7 +376,7 @@ certbot_dns_netcup:dns_netcup_api_password = abcdef0123456789abcdef01234567abcde ovh: { display_name: 'OVH', package_name: 'certbot-dns-ovh', - package_version: '1.8.0', + // version_requirement: '', // Official plugin, no version requirement dependencies: '', credentials: `dns_ovh_endpoint = ovh-eu dns_ovh_application_key = MDAwMDAwMDAwMDAw @@ -378,7 +388,7 @@ dns_ovh_consumer_key = MDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAw`, porkbun: { display_name: 'Porkbun', package_name: 'certbot-dns-porkbun', - package_version: '0.2', + version_requirement: '~=0.2', dependencies: '', credentials: `dns_porkbun_key=your-porkbun-api-key dns_porkbun_secret=your-porkbun-api-secret`, @@ -388,7 +398,7 @@ dns_porkbun_secret=your-porkbun-api-secret`, powerdns: { display_name: 'PowerDNS', package_name: 'certbot-dns-powerdns', - package_version: '0.2.0', + version_requirement: '~=0.2.0', dependencies: '', credentials: `certbot_dns_powerdns:dns_powerdns_api_url = https://api.mypowerdns.example.org certbot_dns_powerdns:dns_powerdns_api_key = AbCbASsd!@34`, @@ -398,7 +408,7 @@ certbot_dns_powerdns:dns_powerdns_api_key = AbCbASsd!@34`, regru: { display_name: 'reg.ru', package_name: 'certbot-regru', - package_version: '1.0.2', + version_requirement: '~=1.0.2', dependencies: '', credentials: `certbot_regru:dns_username=username certbot_regru:dns_password=password`, @@ -408,7 +418,7 @@ certbot_regru:dns_password=password`, rfc2136: { display_name: 'RFC 2136', package_name: 'certbot-dns-rfc2136', - package_version: '1.8.0', + // version_requirement: '', // Official plugin, no version requirement dependencies: '', credentials: `# Target DNS server dns_rfc2136_server = 192.0.2.1 @@ -426,7 +436,7 @@ dns_rfc2136_algorithm = HMAC-SHA512`, route53: { display_name: 'Route 53 (Amazon)', package_name: 'certbot-dns-route53', - package_version: '1.8.0', + // version_requirement: '', // Official plugin, no version requirement dependencies: '', credentials: `[default] aws_access_key_id=AKIAIOSFODNN7EXAMPLE @@ -437,7 +447,7 @@ aws_secret_access_key=wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY`, transip: { display_name: 'TransIP', package_name: 'certbot-dns-transip', - package_version: '0.3.3', + version_requirement: '~=0.3.3', dependencies: '', credentials: `certbot_dns_transip:dns_transip_username = my_username certbot_dns_transip:dns_transip_key_file = /etc/letsencrypt/transip-rsa.key`, @@ -447,19 +457,9 @@ certbot_dns_transip:dns_transip_key_file = /etc/letsencrypt/transip-rsa.key`, vultr: { display_name: 'Vultr', package_name: 'certbot-dns-vultr', - package_version: '1.0.3', + version_requirement: '~=1.0.3', dependencies: '', credentials: 'certbot_dns_vultr:dns_vultr_key = YOUR_VULTR_API_KEY', full_plugin_name: 'certbot-dns-vultr:dns-vultr', }, - //####################################################// - desec: { - display_name: 'deSEC', - package_name: 'certbot-dns-desec', - package_version: '0.3.0', - dependencies: '', - credentials: `certbot_dns_desec:dns_desec_token = YOUR_DESEC_API_TOKEN -certbot_dns_desec:dns_desec_endpoint = https://desec.io/api/v1/`, - full_plugin_name: 'certbot-dns-desec:dns-desec', - }, };