refactor: add loop utility for batch operations

This commit is contained in:
Fu Diwei
2026-07-15 15:25:11 +08:00
committed by RHQYZ
parent eecd0ce769
commit 57706a3604
76 changed files with 588 additions and 1263 deletions
@@ -110,7 +110,7 @@ func (c *Certmgr) Upload(ctx context.Context, certPEM, privkeyPEM string) (*Uplo
}
// 对比证书序列号
// 注意阿里云 CAS 会在序列号前补零,需去除后再比较
// 注意,阿里云 CAS 会在序列号前补零,需去除后再比较
oldCertSN := strings.TrimPrefix(tea.StringValue(certItem.SerialNo), "0")
newCertSN := strings.TrimPrefix(certX509.SerialNumber.Text(16), "0")
if !strings.EqualFold(newCertSN, oldCertSN) {
@@ -144,8 +144,8 @@ func (c *Certmgr) Upload(ctx context.Context, certPEM, privkeyPEM string) (*Uplo
CertId: fmt.Sprintf("%d", tea.Int64Value(certItem.CertificateId)),
CertName: tea.StringValue(certItem.Name),
ExtendedData: map[string]any{
"InstanceId": tea.StringValue(getUserCertificateDetailResp.Body.InstanceId),
"CertIdentifier": tea.StringValue(getUserCertificateDetailResp.Body.CertIdentifier),
"InstanceId": tea.StringValue(getUserCertificateDetailResp.Body.InstanceId),
"CertIdWithRegion": tea.StringValue(getUserCertificateDetailResp.Body.CertIdentifier),
},
}, nil
}
@@ -190,8 +190,8 @@ func (c *Certmgr) Upload(ctx context.Context, certPEM, privkeyPEM string) (*Uplo
CertId: fmt.Sprintf("%d", tea.Int64Value(getUserCertificateDetailResp.Body.Id)),
CertName: certName,
ExtendedData: map[string]any{
"InstanceId": tea.StringValue(getUserCertificateDetailResp.Body.InstanceId),
"CertIdentifier": tea.StringValue(getUserCertificateDetailResp.Body.CertIdentifier),
"InstanceId": tea.StringValue(getUserCertificateDetailResp.Body.InstanceId),
"CertIdWithRegion": tea.StringValue(getUserCertificateDetailResp.Body.CertIdentifier),
},
}, nil
}
+10 -16
View File
@@ -4,7 +4,6 @@ import (
"cmp"
"context"
"crypto/tls"
"errors"
"fmt"
"log/slog"
"strconv"
@@ -15,6 +14,7 @@ import (
onepanelsdk "github.com/certimate-go/certimate/pkg/sdk3rd/1panel"
onepanelsdk2 "github.com/certimate-go/certimate/pkg/sdk3rd/1panel/v2"
xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname"
xloop "github.com/certimate-go/certimate/pkg/utils/loop"
xwait "github.com/certimate-go/certimate/pkg/utils/wait"
)
@@ -152,29 +152,23 @@ func (d *Deployer) deployToWebsite(ctx context.Context, certPEM, privkeyPEM stri
return fmt.Errorf("unsupported website match pattern: '%s'", d.config.WebsiteMatchPattern)
}
// 遍历更新网站证书
// 批量更新网站证书
if len(websiteIds) == 0 {
d.logger.Info("no websites to deploy")
} else {
d.logger.Info("found websites to deploy", slog.Any("websiteIds", websiteIds))
var errs []error
websiteSSLId, _ := strconv.ParseInt(upres.CertId, 10, 64)
for i, websiteId := range websiteIds {
select {
case <-ctx.Done():
return ctx.Err()
default:
if err := d.updateWebsiteCertificate(ctx, websiteId, websiteSSLId); err != nil {
errs = append(errs, err)
} else if i < len(websiteIds)-1 {
xwait.DelayWithContext(ctx, 5*time.Second)
if err := xloop.ForRangeAllWithContext(ctx, websiteIds, func(ctx context.Context, websiteId int64, i int) error {
if i > 0 {
if err := xwait.DelayWithContext(ctx, 3*time.Second); err != nil {
return err
}
}
}
if len(errs) > 0 {
return errors.Join(errs...)
certId, _ := strconv.ParseInt(upres.CertId, 10, 64)
return d.updateWebsiteCertificate(ctx, websiteId, certId)
}); err != nil {
return err
}
}
@@ -2,7 +2,6 @@ package aliyunalb
import (
"context"
"errors"
"fmt"
"log/slog"
"strconv"
@@ -20,6 +19,7 @@ import (
"github.com/certimate-go/certimate/pkg/core"
cmgrimpl "github.com/certimate-go/certimate/pkg/core/certmgr/providers/aliyun-cas"
xcert "github.com/certimate-go/certimate/pkg/utils/cert"
xloop "github.com/certimate-go/certimate/pkg/utils/loop"
xalibabacloud "github.com/certimate-go/certimate/pkg/utils/third-party/alibabacloud"
xwait "github.com/certimate-go/certimate/pkg/utils/wait"
)
@@ -121,12 +121,12 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*Dep
// 根据部署目标决定业务流程
switch d.config.DeployTarget {
case DEPLOY_TARGET_LOADBALANCER:
if err := d.deployToLoadbalancer(ctx, upres.ExtendedData["CertIdentifier"].(string), certX509.DNSNames); err != nil {
if err := d.deployToLoadbalancer(ctx, upres.ExtendedData["CertIdWithRegion"].(string), certX509.DNSNames); err != nil {
return nil, err
}
case DEPLOY_TARGET_LISTENER:
if err := d.deployToListener(ctx, upres.ExtendedData["CertIdentifier"].(string), certX509.DNSNames); err != nil {
if err := d.deployToListener(ctx, upres.ExtendedData["CertIdWithRegion"].(string), certX509.DNSNames); err != nil {
return nil, err
}
@@ -228,26 +228,16 @@ func (d *Deployer) deployToLoadbalancer(ctx context.Context, cloudCertId string,
listListenersToken = listListenersResp.Body.NextToken
}
// 遍历更新监听证书
// 批量更新监听证书
if len(listenerIds) == 0 {
d.logger.Info("no alb listeners to deploy")
} else {
var errs []error
d.logger.Info("found alb listeners to deploy", slog.Any("listenerIds", listenerIds))
for _, listenerId := range listenerIds {
select {
case <-ctx.Done():
return ctx.Err()
default:
if err := d.updateListenerCertificate(ctx, listenerId, cloudCertId, cloudCertSANs); err != nil {
errs = append(errs, err)
}
}
}
if len(errs) > 0 {
return errors.Join(errs...)
if err := xloop.ForRangeAllWithContext(ctx, listenerIds, func(ctx context.Context, listenerId string, _ int) error {
return d.updateListenerCertificate(ctx, listenerId, cloudCertId, cloudCertSANs)
}); err != nil {
return err
}
}
@@ -357,54 +347,56 @@ func (d *Deployer) updateListenerSniCertificate(ctx context.Context, cloudListen
certificateIdsToDissociate := make([]string, 0)
if len(listenerExtCertificates) > 0 {
d.logger.Info("found alb listener certificates in used", slog.Any("certificates", listenerExtCertificates))
var errs []error
certIdWithRegions := make([]string, 0)
for _, listenerCertificate := range listenerExtCertificates {
certIdWithRegion := tea.StringValue(listenerCertificate.CertificateId)
if certIdWithRegion == cloudCertId {
certificateIsAlreadyAssociated = true
break
}
certIdBare := strings.SplitN(certIdWithRegion, "-", 2)[0]
certIdBareAsInt64, err := strconv.ParseInt(certIdBare, 10, 64)
if err != nil {
errs = append(errs, err)
continue
}
certIdWithRegions = append(certIdWithRegions, certIdWithRegion)
}
if err := xloop.ForRangeAllWithContext(ctx, certIdWithRegions, func(ctx context.Context, certIdWithRegion string, _ int) error {
certIdBare := strings.SplitN(certIdWithRegion, "-", 2)[0]
certIdBareAsInt, err := strconv.ParseInt(certIdBare, 10, 64)
if err != nil {
return err
}
getCertificateDetailReq := &alicas.GetCertificateDetailRequest{
CertificateId: tea.Int64(certIdBareAsInt64),
CertificateId: tea.Int64(certIdBareAsInt),
}
getCertificateDetailResp, err := d.sdkClients.CAS.GetCertificateDetailWithContext(ctx, getCertificateDetailReq, &dara.RuntimeOptions{})
d.logger.Debug("sdk request 'cas.GetCertificateDetail'", slog.Any("request", getCertificateDetailReq), slog.Any("response", getCertificateDetailResp))
if err != nil {
if sdkErr, ok := err.(*tea.SDKError); ok {
if sdkErrCode := tea.StringValue(sdkErr.Code); strings.HasPrefix(sdkErrCode, "NotFound") {
continue
return nil
}
}
errs = append(errs, fmt.Errorf("failed to execute sdk request 'cas.GetCertificateDetail': %w", err))
continue
return fmt.Errorf("failed to execute sdk request 'cas.GetCertificateDetail': %w", err)
} else {
// 注意,虽然文档中存在 SubjectAlternativeNames 字段,但实际返回的数据结构中不包含
certSANMatched := lo.ElementsMatch(strings.Split(tea.StringValue(getCertificateDetailResp.Body.Domain), ","), cloudCertSANs)
if certSANMatched && lo.Contains(cloudCertSANs, d.config.Domain) { // 同域名证书需要删除
certificateIdsToDissociate = append(certificateIdsToDissociate, certIdWithRegion)
continue
return nil
}
certNotAfter := time.Unix(tea.Int64Value(getCertificateDetailResp.Body.NotAfter)/1000, 0)
if !certNotAfter.IsZero() && certNotAfter.Before(time.Now()) { // 过期证书需要删除。TODO: remove on v0.5
certificateIdsToDissociate = append(certificateIdsToDissociate, certIdWithRegion)
continue
return nil
}
}
}
if len(errs) > 0 {
return errors.Join(errs...)
return nil
}); err != nil {
return err
}
}
@@ -438,31 +430,30 @@ func (d *Deployer) updateListenerSniCertificate(ctx context.Context, cloudListen
if len(certificateIdsToDissociate) > 0 {
d.logger.Info("found alb listener certificates to dissociate", slog.Any("certificateIds", certificateIdsToDissociate))
const MAX_CERT_PER_REQUEST = 10
certIdChunks := lo.Chunk(certificateIdsToDissociate, MAX_CERT_PER_REQUEST)
for _, certIds := range certIdChunks {
select {
case <-ctx.Done():
return ctx.Err()
default:
if err := d.waitForListenerReady(ctx, cloudListenerId); err != nil {
return err
}
dissociateAdditionalCertificatesFromListenerReq := &alialb.DissociateAdditionalCertificatesFromListenerRequest{
ListenerId: tea.String(cloudListenerId),
Certificates: lo.Map(certIds, func(certId string, _ int) *alialb.DissociateAdditionalCertificatesFromListenerRequestCertificates {
return &alialb.DissociateAdditionalCertificatesFromListenerRequestCertificates{
CertificateId: tea.String(certId),
}
}),
}
dissociateAdditionalCertificatesFromListenerResp, err := d.sdkClients.ALB.DissociateAdditionalCertificatesFromListenerWithContext(ctx, dissociateAdditionalCertificatesFromListenerReq, &dara.RuntimeOptions{})
d.logger.Debug("sdk request 'alb.DissociateAdditionalCertificatesFromListener'", slog.Any("request", dissociateAdditionalCertificatesFromListenerReq), slog.Any("response", dissociateAdditionalCertificatesFromListenerResp))
if err != nil {
return fmt.Errorf("failed to execute sdk request 'alb.DissociateAdditionalCertificatesFromListener': %w", err)
}
const MAX_CERTS_PER_REQUEST = 10
certIdChunks := lo.Chunk(certificateIdsToDissociate, MAX_CERTS_PER_REQUEST)
if err := xloop.ForRangeAllWithContext(ctx, certIdChunks, func(ctx context.Context, certIds []string, _ int) error {
if err := d.waitForListenerReady(ctx, cloudListenerId); err != nil {
return err
}
dissociateAdditionalCertificatesFromListenerReq := &alialb.DissociateAdditionalCertificatesFromListenerRequest{
ListenerId: tea.String(cloudListenerId),
Certificates: lo.Map(certIds, func(certId string, _ int) *alialb.DissociateAdditionalCertificatesFromListenerRequestCertificates {
return &alialb.DissociateAdditionalCertificatesFromListenerRequestCertificates{
CertificateId: tea.String(certId),
}
}),
}
dissociateAdditionalCertificatesFromListenerResp, err := d.sdkClients.ALB.DissociateAdditionalCertificatesFromListenerWithContext(ctx, dissociateAdditionalCertificatesFromListenerReq, &dara.RuntimeOptions{})
d.logger.Debug("sdk request 'alb.DissociateAdditionalCertificatesFromListener'", slog.Any("request", dissociateAdditionalCertificatesFromListenerReq), slog.Any("response", dissociateAdditionalCertificatesFromListenerResp))
if err != nil {
return fmt.Errorf("failed to execute sdk request 'alb.DissociateAdditionalCertificatesFromListener': %w", err)
}
return nil
}); err != nil {
return err
}
}
@@ -2,7 +2,6 @@ package aliyunapigw
import (
"context"
"errors"
"fmt"
"log/slog"
"strings"
@@ -19,6 +18,7 @@ import (
"github.com/certimate-go/certimate/pkg/core"
cmgrimpl "github.com/certimate-go/certimate/pkg/core/certmgr/providers/aliyun-cas"
xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname"
xloop "github.com/certimate-go/certimate/pkg/utils/loop"
xalibabacloud "github.com/certimate-go/certimate/pkg/utils/third-party/alibabacloud"
)
@@ -181,26 +181,16 @@ func (d *Deployer) deployToTraditional(ctx context.Context, certPEM, privkeyPEM
return fmt.Errorf("unsupported domain match pattern: '%s'", d.config.DomainMatchPattern)
}
// 遍历更新域名证书
// 批量更新域名证书
if len(domains) == 0 {
d.logger.Info("no apigw domains to deploy")
} else {
d.logger.Info("found apigw domains to deploy", slog.Any("domains", domains))
var errs []error
for _, domain := range domains {
select {
case <-ctx.Done():
return ctx.Err()
default:
if err := d.updateTraditionalDomainCertificate(ctx, d.config.GroupId, domain, certPEM, privkeyPEM); err != nil {
errs = append(errs, err)
}
}
}
if len(errs) > 0 {
return errors.Join(errs...)
if err := xloop.ForRangeAllWithContext(ctx, domains, func(ctx context.Context, domain string, _ int) error {
return d.updateTraditionalDomainCertificate(ctx, d.config.GroupId, domain, certPEM, privkeyPEM)
}); err != nil {
return err
}
}
@@ -274,27 +264,17 @@ func (d *Deployer) deployToCloudNative(ctx context.Context, certPEM, privkeyPEM
return fmt.Errorf("unsupported domain match pattern: '%s'", d.config.DomainMatchPattern)
}
// 遍历更新域名证书
// 批量更新域名证书
if len(domains) == 0 {
d.logger.Info("no apigw domains to deploy")
} else {
d.logger.Info("found apigw domains to deploy", slog.Any("domains", domains))
var errs []error
for _, domain := range domains {
select {
case <-ctx.Done():
return ctx.Err()
default:
certId := upres.ExtendedData["CertIdentifier"].(string)
if err := d.updateCloudNativeDomainCertificate(ctx, d.config.GatewayId, domain, certId); err != nil {
errs = append(errs, err)
}
}
}
if len(errs) > 0 {
return errors.Join(errs...)
if err := xloop.ForRangeAllWithContext(ctx, domains, func(ctx context.Context, domain string, _ int) error {
certId := upres.ExtendedData["CertIdWithRegion"].(string)
return d.updateCloudNativeDomainCertificate(ctx, d.config.GatewayId, domain, certId)
}); err != nil {
return err
}
}
@@ -2,7 +2,6 @@ package aliyuncdn
import (
"context"
"errors"
"fmt"
"log/slog"
"strconv"
@@ -18,6 +17,7 @@ import (
"github.com/certimate-go/certimate/pkg/core"
cmgrimpl "github.com/certimate-go/certimate/pkg/core/certmgr/providers/aliyun-cas"
xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname"
xloop "github.com/certimate-go/certimate/pkg/utils/loop"
xalibabacloud "github.com/certimate-go/certimate/pkg/utils/third-party/alibabacloud"
)
@@ -153,34 +153,21 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*Dep
return nil, fmt.Errorf("unsupported domain match pattern: '%s'", d.config.DomainMatchPattern)
}
// 遍历更新域名证书
// 批量更新域名证书
if len(domains) == 0 {
d.logger.Info("no cdn domains to deploy")
} else {
d.logger.Info("found cdn domains to deploy", slog.Any("domains", domains))
var errs []error
certIdentifier := upres.ExtendedData["CertIdentifier"].(string)
certIdentifier := upres.ExtendedData["CertIdWithRegion"].(string)
certIdentifierSeps := strings.SplitN(certIdentifier, "-", 2)
if len(certIdentifierSeps) != 2 {
return nil, fmt.Errorf("received invalid certificate identifier: '%s'", certIdentifier)
}
certId, _ := strconv.ParseInt(certIdentifierSeps[0], 10, 64)
certRegion := certIdentifierSeps[1]
for _, domain := range domains {
select {
case <-ctx.Done():
return nil, ctx.Err()
default:
if err := d.updateDomainCertificate(ctx, domain, certId, certRegion); err != nil {
errs = append(errs, err)
}
}
}
if len(errs) > 0 {
return nil, errors.Join(errs...)
if err := xloop.ForRangeAllWithContext(ctx, domains, func(ctx context.Context, domain string, _ int) error {
return d.updateDomainCertificate(ctx, domain, certId, certRegion)
}); err != nil {
return nil, err
}
}
@@ -235,14 +222,14 @@ func (d *Deployer) getAllDomains(ctx context.Context) ([]string, error) {
return domains, nil
}
func (d *Deployer) updateDomainCertificate(ctx context.Context, domain string, cloudCertId int64, certRegion string) error {
func (d *Deployer) updateDomainCertificate(ctx context.Context, domain string, cloudCertId int64, cloudCertRegion string) error {
// 设置 CDN 域名域名证书
// REF: https://help.aliyun.com/zh/cdn/developer-reference/api-cdn-2018-05-10-setcdndomainsslcertificate
setCdnDomainSSLCertificateReq := &alicdn.SetCdnDomainSSLCertificateRequest{
DomainName: tea.String(domain),
CertType: tea.String("cas"),
CertId: tea.Int64(cloudCertId),
CertRegion: tea.String(certRegion),
CertRegion: tea.String(cloudCertRegion),
SSLProtocol: tea.String("on"),
}
setCdnDomainSSLCertificateResp, err := d.sdkClient.SetCdnDomainSSLCertificateWithContext(ctx, setCdnDomainSSLCertificateReq, &dara.RuntimeOptions{})
@@ -2,7 +2,6 @@ package aliyunclb
import (
"context"
"errors"
"fmt"
"log/slog"
@@ -14,6 +13,7 @@ import (
"github.com/certimate-go/certimate/pkg/core"
cmgrimpl "github.com/certimate-go/certimate/pkg/core/certmgr/providers/aliyun-slb"
xloop "github.com/certimate-go/certimate/pkg/utils/loop"
)
type (
@@ -174,26 +174,16 @@ func (d *Deployer) deployToLoadbalancer(ctx context.Context, cloudCertId string)
describeLoadBalancerListenersToken = describeLoadBalancerListenersResp.Body.NextToken
}
// 遍历更新监听证书
// 批量更新监听证书
if len(listenerPorts) == 0 {
d.logger.Info("no clb listeners to deploy")
} else {
d.logger.Info("found clb listeners to deploy", slog.Any("listenerPorts", listenerPorts))
var errs []error
for _, listenerPort := range listenerPorts {
select {
case <-ctx.Done():
return ctx.Err()
default:
if err := d.updateListenerCertificate(ctx, d.config.LoadbalancerId, listenerPort, cloudCertId); err != nil {
errs = append(errs, err)
}
}
}
if len(errs) > 0 {
return errors.Join(errs...)
if err := xloop.ForRangeAllWithContext(ctx, listenerPorts, func(ctx context.Context, listenerPort int32, _ int) error {
return d.updateListenerCertificate(ctx, d.config.LoadbalancerId, listenerPort, cloudCertId)
}); err != nil {
return err
}
}
@@ -274,36 +264,37 @@ func (d *Deployer) updateListenerSniCertificate(ctx context.Context, cloudLoadba
return fmt.Errorf("failed to execute sdk request 'slb.DescribeDomainExtensions': %w", err)
}
// 遍历修改扩展域名证书
// 修改扩展域名证书
// REF: https://help.aliyun.com/zh/slb/classic-load-balancer/developer-reference/api-slb-2014-05-15-setdomainextensionattribute
if describeDomainExtensionsResp.Body.DomainExtensions != nil && describeDomainExtensionsResp.Body.DomainExtensions.DomainExtension != nil {
var errs []error
domainExtensionIds := make([]string, 0)
for _, domainExtension := range describeDomainExtensionsResp.Body.DomainExtensions.DomainExtension {
if tea.StringValue(domainExtension.Domain) != d.config.Domain {
continue
}
if tea.StringValue(domainExtension.ServerCertificateId) == cloudCertId {
d.logger.Info("no need to deploy clb listener sni certificate")
continue
}
domainExtensionIds = append(domainExtensionIds, tea.StringValue(domainExtension.DomainExtensionId))
}
if err := xloop.ForRangeAllWithContext(ctx, domainExtensionIds, func(ctx context.Context, domainExtensionId string, _ int) error {
setDomainExtensionAttributeReq := &alislb.SetDomainExtensionAttributeRequest{
RegionId: tea.String(d.config.Region),
DomainExtensionId: domainExtension.DomainExtensionId,
DomainExtensionId: tea.String(domainExtensionId),
ServerCertificateId: tea.String(cloudCertId),
}
setDomainExtensionAttributeResp, err := d.sdkClient.SetDomainExtensionAttributeWithContext(ctx, setDomainExtensionAttributeReq, &dara.RuntimeOptions{})
d.logger.Debug("sdk request 'slb.SetDomainExtensionAttribute'", slog.Any("request", setDomainExtensionAttributeReq), slog.Any("response", setDomainExtensionAttributeResp))
if err != nil {
errs = append(errs, fmt.Errorf("failed to execute sdk request 'slb.SetDomainExtensionAttribute': %w", err))
continue
return fmt.Errorf("failed to execute sdk request 'slb.SetDomainExtensionAttribute': %w", err)
}
}
if len(errs) > 0 {
return errors.Join(errs...)
return nil
}); err != nil {
return err
}
}
@@ -2,7 +2,6 @@ package aliyundcdn
import (
"context"
"errors"
"fmt"
"log/slog"
"strconv"
@@ -18,6 +17,7 @@ import (
"github.com/certimate-go/certimate/pkg/core"
cmgrimpl "github.com/certimate-go/certimate/pkg/core/certmgr/providers/aliyun-cas"
xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname"
xloop "github.com/certimate-go/certimate/pkg/utils/loop"
xalibabacloud "github.com/certimate-go/certimate/pkg/utils/third-party/alibabacloud"
)
@@ -153,34 +153,21 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*Dep
return nil, fmt.Errorf("unsupported domain match pattern: '%s'", d.config.DomainMatchPattern)
}
// 遍历更新域名证书
// 批量更新域名证书
if len(domains) == 0 {
d.logger.Info("no dcdn domains to deploy")
} else {
d.logger.Info("found dcdn domains to deploy", slog.Any("domains", domains))
var errs []error
certIdentifier := upres.ExtendedData["CertIdentifier"].(string)
certIdentifier := upres.ExtendedData["CertIdWithRegion"].(string)
certIdentifierSeps := strings.SplitN(certIdentifier, "-", 2)
if len(certIdentifierSeps) != 2 {
return nil, fmt.Errorf("received invalid certificate identifier: '%s'", certIdentifier)
}
certId, _ := strconv.ParseInt(certIdentifierSeps[0], 10, 64)
certRegion := certIdentifierSeps[1]
for _, domain := range domains {
select {
case <-ctx.Done():
return nil, ctx.Err()
default:
if err := d.updateDomainCertificate(ctx, domain, certId, certRegion); err != nil {
errs = append(errs, err)
}
}
}
if len(errs) > 0 {
return nil, errors.Join(errs...)
if err := xloop.ForRangeAllWithContext(ctx, domains, func(ctx context.Context, domain string, _ int) error {
return d.updateDomainCertificate(ctx, domain, certId, certRegion)
}); err != nil {
return nil, err
}
}
@@ -236,14 +223,14 @@ func (d *Deployer) getAllDomains(ctx context.Context) ([]string, error) {
return domains, nil
}
func (d *Deployer) updateDomainCertificate(ctx context.Context, domain string, cloudCertId int64, certRegion string) error {
func (d *Deployer) updateDomainCertificate(ctx context.Context, domain string, cloudCertId int64, cloudCertRegion string) error {
// 配置域名证书
// REF: https://help.aliyun.com/zh/edge-security-acceleration/dcdn/developer-reference/api-dcdn-2018-01-15-setdcdndomainsslcertificate
setDcdnDomainSSLCertificateReq := &alidcdn.SetDcdnDomainSSLCertificateRequest{
DomainName: tea.String(domain),
CertType: tea.String("cas"),
CertId: tea.Int64(cloudCertId),
CertRegion: tea.String(certRegion),
CertRegion: tea.String(cloudCertRegion),
SSLProtocol: tea.String("on"),
}
setDcdnDomainSSLCertificateResp, err := d.sdkClient.SetDcdnDomainSSLCertificateWithContext(ctx, setDcdnDomainSSLCertificateReq, &dara.RuntimeOptions{})
@@ -2,7 +2,6 @@ package aliyunddospro
import (
"context"
"errors"
"fmt"
"log/slog"
"strings"
@@ -17,6 +16,7 @@ import (
"github.com/certimate-go/certimate/pkg/core"
cmgrimpl "github.com/certimate-go/certimate/pkg/core/certmgr/providers/aliyun-cas"
xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname"
xloop "github.com/certimate-go/certimate/pkg/utils/loop"
xalibabacloud "github.com/certimate-go/certimate/pkg/utils/third-party/alibabacloud"
)
@@ -151,27 +151,17 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*Dep
return nil, fmt.Errorf("unsupported domain match pattern: '%s'", d.config.DomainMatchPattern)
}
// 遍历更新域名证书
// 批量更新域名证书
if len(domains) == 0 {
d.logger.Info("no ddoscoo domains to deploy")
} else {
d.logger.Info("found ddoscoo domains to deploy", slog.Any("domains", domains))
var errs []error
for _, domain := range domains {
select {
case <-ctx.Done():
return nil, ctx.Err()
default:
certId := upres.ExtendedData["CertIdentifier"].(string)
if err := d.updateDomainCertificate(ctx, domain, certId); err != nil {
errs = append(errs, err)
}
}
}
if len(errs) > 0 {
return nil, errors.Join(errs...)
if err := xloop.ForRangeAllWithContext(ctx, domains, func(ctx context.Context, domain string, _ int) error {
certId := upres.ExtendedData["CertIdWithRegion"].(string)
return d.updateDomainCertificate(ctx, domain, certId)
}); err != nil {
return nil, err
}
}
@@ -2,7 +2,6 @@ package aliyunesasaas
import (
"context"
"errors"
"fmt"
"log/slog"
"strconv"
@@ -18,6 +17,7 @@ import (
"github.com/certimate-go/certimate/pkg/core"
cmgrimpl "github.com/certimate-go/certimate/pkg/core/certmgr/providers/aliyun-cas"
xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname"
xloop "github.com/certimate-go/certimate/pkg/utils/loop"
xalibabacloud "github.com/certimate-go/certimate/pkg/utils/third-party/alibabacloud"
)
@@ -178,34 +178,21 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*Dep
return nil, fmt.Errorf("unsupported domain match pattern: '%s'", d.config.DomainMatchPattern)
}
// 遍历更新域名证书
// 批量更新域名证书
if len(hostnameIds) == 0 {
d.logger.Info("no esa saas hostnames to deploy")
} else {
d.logger.Info("found esa saas hostnames to deploy", slog.Any("hostnameIds", hostnameIds))
var errs []error
certIdentifier := upres.ExtendedData["CertIdentifier"].(string)
certIdentifier := upres.ExtendedData["CertIdWithRegion"].(string)
certIdentifierSeps := strings.SplitN(certIdentifier, "-", 2)
if len(certIdentifierSeps) != 2 {
return nil, fmt.Errorf("received invalid certificate identifier: '%s'", certIdentifier)
}
certId, _ := strconv.ParseInt(certIdentifierSeps[0], 10, 64)
certRegion := certIdentifierSeps[1]
for _, hostnameId := range hostnameIds {
select {
case <-ctx.Done():
return nil, ctx.Err()
default:
if err := d.updateHostnameCertificate(ctx, hostnameId, certId, certRegion); err != nil {
errs = append(errs, err)
}
}
}
if len(errs) > 0 {
return nil, errors.Join(errs...)
if err := xloop.ForRangeAllWithContext(ctx, hostnameIds, func(ctx context.Context, hostnameId int64, _ int) error {
return d.updateHostnameCertificate(ctx, hostnameId, certId, certRegion)
}); err != nil {
return nil, err
}
}
@@ -98,12 +98,12 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*Dep
// 配置站点证书
// REF: https://help.aliyun.com/zh/edge-security-acceleration/esa/api-esa-2024-09-10-setcertificate
certId, _ := strconv.ParseInt(upres.CertId, 10, 64)
certIdAsInt, _ := strconv.ParseInt(upres.CertId, 10, 64)
setCertificateReq := &aliesa.SetCertificateRequest{
Region: tea.String(d.config.Region),
SiteId: tea.Int64(d.config.SiteId),
Type: tea.String("cas"),
CasId: tea.Int64(certId),
CasId: tea.Int64(certIdAsInt),
}
setCertificateResp, err := d.sdkClient.SetCertificateWithContext(ctx, setCertificateReq, &dara.RuntimeOptions{})
d.logger.Debug("sdk request 'esa.SetCertificate'", slog.Any("request", setCertificateReq), slog.Any("response", setCertificateResp))
@@ -2,7 +2,6 @@ package aliyunfc
import (
"context"
"errors"
"fmt"
"log/slog"
"strings"
@@ -18,6 +17,7 @@ import (
"github.com/certimate-go/certimate/pkg/core"
xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname"
xloop "github.com/certimate-go/certimate/pkg/utils/loop"
)
type (
@@ -156,26 +156,16 @@ func (d *Deployer) deployToFC3(ctx context.Context, certPEM, privkeyPEM string)
return fmt.Errorf("unsupported domain match pattern: '%s'", d.config.DomainMatchPattern)
}
// 遍历更新域名证书
// 批量更新域名证书
if len(domains) == 0 {
d.logger.Info("no fc domains to deploy")
} else {
d.logger.Info("found fc domains to deploy", slog.Any("domains", domains))
var errs []error
for _, domain := range domains {
select {
case <-ctx.Done():
return ctx.Err()
default:
if err := d.updateFC3DomainCertificate(ctx, domain, certPEM, privkeyPEM); err != nil {
errs = append(errs, err)
}
}
}
if len(errs) > 0 {
return errors.Join(errs...)
if err := xloop.ForRangeAllWithContext(ctx, domains, func(ctx context.Context, domain string, _ int) error {
return d.updateFC3DomainCertificate(ctx, domain, certPEM, privkeyPEM)
}); err != nil {
return err
}
}
@@ -237,26 +227,16 @@ func (d *Deployer) deployToFC2(ctx context.Context, certPEM, privkeyPEM string)
return fmt.Errorf("unsupported domain match pattern: '%s'", d.config.DomainMatchPattern)
}
// 遍历更新域名证书
// 批量更新域名证书
if len(domains) == 0 {
d.logger.Info("no fc domains to deploy")
} else {
d.logger.Info("found fc domains to deploy", slog.Any("domains", domains))
var errs []error
for _, domain := range domains {
select {
case <-ctx.Done():
return ctx.Err()
default:
if err := d.updateFC2DomainCertificate(ctx, domain, certPEM, privkeyPEM); err != nil {
errs = append(errs, err)
}
}
}
if len(errs) > 0 {
return errors.Join(errs...)
if err := xloop.ForRangeAllWithContext(ctx, domains, func(ctx context.Context, domain string, _ int) error {
return d.updateFC2DomainCertificate(ctx, domain, certPEM, privkeyPEM)
}); err != nil {
return err
}
}
@@ -2,7 +2,6 @@ package aliyunga
import (
"context"
"errors"
"fmt"
"log/slog"
"strings"
@@ -16,6 +15,7 @@ import (
"github.com/certimate-go/certimate/pkg/core"
cmgrimpl "github.com/certimate-go/certimate/pkg/core/certmgr/providers/aliyun-cas"
xloop "github.com/certimate-go/certimate/pkg/utils/loop"
)
type (
@@ -101,12 +101,12 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*Dep
// 根据部署目标决定业务流程
switch d.config.DeployTarget {
case DEPLOY_TARGET_ACCELERATOR:
if err := d.deployToAccelerator(ctx, upres.ExtendedData["CertIdentifier"].(string)); err != nil {
if err := d.deployToAccelerator(ctx, upres.ExtendedData["CertIdWithRegion"].(string)); err != nil {
return nil, err
}
case DEPLOY_TARGET_LISTENER:
if err := d.deployToListener(ctx, upres.ExtendedData["CertIdentifier"].(string)); err != nil {
if err := d.deployToListener(ctx, upres.ExtendedData["CertIdWithRegion"].(string)); err != nil {
return nil, err
}
@@ -163,26 +163,16 @@ func (d *Deployer) deployToAccelerator(ctx context.Context, cloudCertId string)
listListenersPageNumber++
}
// 遍历更新监听证书
// 批量更新监听证书
if len(listenerIds) == 0 {
d.logger.Info("no ga listeners to deploy")
} else {
var errs []error
d.logger.Info("found ga listeners to deploy", slog.Any("listenerIds", listenerIds))
for _, listenerId := range listenerIds {
select {
case <-ctx.Done():
return ctx.Err()
default:
if err := d.updateListenerCertificate(ctx, d.config.AcceleratorId, listenerId, cloudCertId); err != nil {
errs = append(errs, err)
}
}
}
if len(errs) > 0 {
return errors.Join(errs...)
if err := xloop.ForRangeAllWithContext(ctx, listenerIds, func(ctx context.Context, listenerId string, _ int) error {
return d.updateListenerCertificate(ctx, d.config.AcceleratorId, listenerId, cloudCertId)
}); err != nil {
return err
}
}
@@ -2,7 +2,6 @@ package aliyunlive
import (
"context"
"errors"
"fmt"
"log/slog"
"strings"
@@ -17,6 +16,7 @@ import (
"github.com/certimate-go/certimate/pkg/core"
xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname"
xloop "github.com/certimate-go/certimate/pkg/utils/loop"
)
type (
@@ -129,26 +129,16 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*Dep
return nil, fmt.Errorf("unsupported domain match pattern: '%s'", d.config.DomainMatchPattern)
}
// 遍历更新域名证书
// 批量更新域名证书
if len(domains) == 0 {
d.logger.Info("no live domains to deploy")
} else {
d.logger.Info("found live domains to deploy", slog.Any("domains", domains))
var errs []error
for _, domain := range domains {
select {
case <-ctx.Done():
return nil, ctx.Err()
default:
if err := d.updateDomainCertificate(ctx, domain, certPEM, privkeyPEM); err != nil {
errs = append(errs, err)
}
}
}
if len(errs) > 0 {
return nil, errors.Join(errs...)
if err := xloop.ForRangeAllWithContext(ctx, domains, func(ctx context.Context, domain string, _ int) error {
return d.updateDomainCertificate(ctx, domain, certPEM, privkeyPEM)
}); err != nil {
return nil, err
}
}
@@ -2,7 +2,6 @@ package aliyunnlb
import (
"context"
"errors"
"fmt"
"log/slog"
@@ -15,6 +14,7 @@ import (
"github.com/certimate-go/certimate/pkg/core"
cmgrimpl "github.com/certimate-go/certimate/pkg/core/certmgr/providers/aliyun-cas"
xloop "github.com/certimate-go/certimate/pkg/utils/loop"
xalibabacloud "github.com/certimate-go/certimate/pkg/utils/third-party/alibabacloud"
)
@@ -101,12 +101,12 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*Dep
// 根据部署目标决定业务流程
switch d.config.DeployTarget {
case DEPLOY_TARGET_LOADBALANCER:
if err := d.deployToLoadbalancer(ctx, upres.ExtendedData["CertIdentifier"].(string)); err != nil {
if err := d.deployToLoadbalancer(ctx, upres.ExtendedData["CertIdWithRegion"].(string)); err != nil {
return nil, err
}
case DEPLOY_TARGET_LISTENER:
if err := d.deployToListener(ctx, upres.ExtendedData["CertIdentifier"].(string)); err != nil {
if err := d.deployToListener(ctx, upres.ExtendedData["CertIdWithRegion"].(string)); err != nil {
return nil, err
}
@@ -171,26 +171,16 @@ func (d *Deployer) deployToLoadbalancer(ctx context.Context, cloudCertId string)
listListenersToken = listListenersResp.Body.NextToken
}
// 遍历更新监听证书
// 批量更新监听证书
if len(listenerIds) == 0 {
d.logger.Info("no nlb listeners to deploy")
} else {
d.logger.Info("found nlb listeners to deploy", slog.Any("listenerIds", listenerIds))
var errs []error
for _, listenerId := range listenerIds {
select {
case <-ctx.Done():
return ctx.Err()
default:
if err := d.updateListenerCertificate(ctx, listenerId, cloudCertId); err != nil {
errs = append(errs, err)
}
}
}
if len(errs) > 0 {
return errors.Join(errs...)
if err := xloop.ForRangeAllWithContext(ctx, listenerIds, func(ctx context.Context, listenerId string, _ int) error {
return d.updateListenerCertificate(ctx, listenerId, cloudCertId)
}); err != nil {
return err
}
}
@@ -103,7 +103,7 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*Dep
Cname: &osssdk.PutCnameRequestCname{
Domain: tea.String(d.config.Domain),
CertificateConfiguration: &osssdk.PutCnameRequestCnameCertificateConfiguration{
CertId: tea.String(upres.ExtendedData["CertIdentifier"].(string)),
CertId: tea.String(upres.ExtendedData["CertIdWithRegion"].(string)),
Certificate: tea.String(certPEM),
PrivateKey: tea.String(privkeyPEM),
Force: tea.Bool(true),
@@ -2,7 +2,6 @@ package aliyunvod
import (
"context"
"errors"
"fmt"
"log/slog"
"strconv"
@@ -18,6 +17,7 @@ import (
"github.com/certimate-go/certimate/pkg/core"
cmgrimpl "github.com/certimate-go/certimate/pkg/core/certmgr/providers/aliyun-cas"
xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname"
xloop "github.com/certimate-go/certimate/pkg/utils/loop"
xalibabacloud "github.com/certimate-go/certimate/pkg/utils/third-party/alibabacloud"
)
@@ -152,35 +152,22 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*Dep
return nil, fmt.Errorf("unsupported domain match pattern: '%s'", d.config.DomainMatchPattern)
}
// 遍历更新域名证书
// 批量更新域名证书
if len(domains) == 0 {
d.logger.Info("no vod domains to deploy")
} else {
d.logger.Info("found vod domains to deploy", slog.Any("domains", domains))
var errs []error
certIdentifier := upres.ExtendedData["CertIdentifier"].(string)
certIdentifier := upres.ExtendedData["CertIdWithRegion"].(string)
certIdentifierSeps := strings.SplitN(certIdentifier, "-", 2)
if len(certIdentifierSeps) != 2 {
return nil, fmt.Errorf("received invalid certificate identifier: '%s'", certIdentifier)
}
certId, _ := strconv.ParseInt(certIdentifierSeps[0], 10, 64)
certName := upres.CertName
certRegion := certIdentifierSeps[1]
for _, domain := range domains {
select {
case <-ctx.Done():
return nil, ctx.Err()
default:
if err := d.updateDomainCertificate(ctx, domain, certId, certName, certRegion); err != nil {
errs = append(errs, err)
}
}
}
if len(errs) > 0 {
return nil, errors.Join(errs...)
if err := xloop.ForRangeAllWithContext(ctx, domains, func(ctx context.Context, domain string, _ int) error {
return d.updateDomainCertificate(ctx, domain, certId, certName, certRegion)
}); err != nil {
return nil, err
}
}
@@ -130,13 +130,13 @@ func (d *Deployer) deployToWAF3(ctx context.Context, certPEM, privkeyPEM string)
// 根据接入方式决定部署方式
switch d.config.ServiceType {
case SERVICE_TYPE_CLOUDRESOURCE:
certId := upres.ExtendedData["CertIdentifier"].(string)
certId := upres.ExtendedData["CertIdWithRegion"].(string)
if err := d.deployToWAF3WithCloudResource(ctx, certId); err != nil {
return err
}
case SERVICE_TYPE_CNAME:
certId := upres.ExtendedData["CertIdentifier"].(string)
certId := upres.ExtendedData["CertIdWithRegion"].(string)
if err := d.deployToWAF3WithCNAME(ctx, certId); err != nil {
return err
}
@@ -2,7 +2,6 @@ package baiducloudappblb
import (
"context"
"errors"
"fmt"
"log/slog"
"strconv"
@@ -14,6 +13,7 @@ import (
"github.com/certimate-go/certimate/pkg/core"
cmgrimpl "github.com/certimate-go/certimate/pkg/core/certmgr/providers/baiducloud-cert"
xloop "github.com/certimate-go/certimate/pkg/utils/loop"
)
type (
@@ -128,10 +128,11 @@ func (d *Deployer) deployToLoadbalancer(ctx context.Context, cloudCertId string)
}
// 获取全部 HTTPS/SSL 监听端口
listeners := make([]struct {
type listenerEntry struct {
Type string
Port int32
}, 0)
}
listeners := make([]listenerEntry, 0)
for _, listener := range describeLoadBalancerDetailResp.Listener {
if listener.Type == "HTTPS" || listener.Type == "SSL" {
listenerPort, err := strconv.Atoi(listener.Port)
@@ -139,37 +140,23 @@ func (d *Deployer) deployToLoadbalancer(ctx context.Context, cloudCertId string)
continue
}
listeners = append(listeners, struct {
Type string
Port int32
}{
listeners = append(listeners, listenerEntry{
Type: listener.Type,
Port: int32(listenerPort),
})
}
}
// 遍历更新监听证书
// 批量更新监听证书
if len(listeners) == 0 {
d.logger.Info("no appblb listeners to deploy")
} else {
d.logger.Info("found appblb listeners to deploy", slog.Any("listeners", listeners))
var errs []error
for _, listener := range listeners {
select {
case <-ctx.Done():
return ctx.Err()
default:
if err := d.updateListenerCertificate(ctx, d.config.LoadbalancerId, listener.Type, listener.Port, cloudCertId); err != nil {
errs = append(errs, err)
}
}
}
if len(errs) > 0 {
return errors.Join(errs...)
if err := xloop.ForRangeAllWithContext(ctx, listeners, func(ctx context.Context, listener listenerEntry, _ int) error {
return d.updateListenerCertificate(ctx, d.config.LoadbalancerId, listener.Type, listener.Port, cloudCertId)
}); err != nil {
return err
}
}
@@ -196,44 +183,25 @@ func (d *Deployer) deployToListener(ctx context.Context, cloudCertId string) err
}
// 获取全部 HTTPS/SSL 监听端口
listeners := make([]struct {
type listenerEntry struct {
Type string
Port int32
}, 0)
}
listeners := make([]listenerEntry, 0)
for _, listener := range describeAppAllListenersResp.ListenerList {
if listener.ListenerType == "HTTPS" || listener.ListenerType == "SSL" {
listeners = append(listeners, struct {
Type string
Port int32
}{
listeners = append(listeners, listenerEntry{
Type: listener.ListenerType,
Port: int32(listener.ListenerPort),
})
}
}
// 遍历更新监听证书
if len(listeners) == 0 {
d.logger.Info("no blb listeners to deploy")
} else {
d.logger.Info("found appblb listeners to deploy", slog.Any("listeners", listeners))
var errs []error
for _, listener := range listeners {
select {
case <-ctx.Done():
return ctx.Err()
default:
if err := d.updateListenerCertificate(ctx, d.config.LoadbalancerId, listener.Type, listener.Port, cloudCertId); err != nil {
errs = append(errs, err)
}
}
}
if len(errs) > 0 {
return errors.Join(errs...)
}
// 更新监听证书
if err := xloop.ForRangeAllWithContext(ctx, listeners, func(ctx context.Context, listener listenerEntry, _ int) error {
return d.updateListenerCertificate(ctx, d.config.LoadbalancerId, listener.Type, listener.Port, cloudCertId)
}); err != nil {
return err
}
return nil
@@ -2,7 +2,6 @@ package baiducloudblb
import (
"context"
"errors"
"fmt"
"log/slog"
"strconv"
@@ -14,6 +13,7 @@ import (
"github.com/certimate-go/certimate/pkg/core"
cmgrimpl "github.com/certimate-go/certimate/pkg/core/certmgr/providers/baiducloud-cert"
xloop "github.com/certimate-go/certimate/pkg/utils/loop"
)
type (
@@ -128,10 +128,11 @@ func (d *Deployer) deployToLoadbalancer(ctx context.Context, cloudCertId string)
}
// 获取全部 HTTPS/SSL 监听端口
listeners := make([]struct {
type listenerEntry struct {
Type string
Port int32
}, 0)
}
listeners := make([]listenerEntry, 0)
for _, listener := range describeLoadBalancerDetailResp.Listener {
if listener.Type == "HTTPS" || listener.Type == "SSL" {
listenerPort, err := strconv.Atoi(listener.Port)
@@ -139,37 +140,23 @@ func (d *Deployer) deployToLoadbalancer(ctx context.Context, cloudCertId string)
continue
}
listeners = append(listeners, struct {
Type string
Port int32
}{
listeners = append(listeners, listenerEntry{
Type: listener.Type,
Port: int32(listenerPort),
})
}
}
// 遍历更新监听证书
// 批量更新监听证书
if len(listeners) == 0 {
d.logger.Info("no blb listeners to deploy")
} else {
d.logger.Info("found blb listeners to deploy", slog.Any("listeners", listeners))
var errs []error
for _, listener := range listeners {
select {
case <-ctx.Done():
return ctx.Err()
default:
if err := d.updateListenerCertificate(ctx, d.config.LoadbalancerId, listener.Type, listener.Port, cloudCertId); err != nil {
errs = append(errs, err)
}
}
}
if len(errs) > 0 {
return errors.Join(errs...)
if err := xloop.ForRangeAllWithContext(ctx, listeners, func(ctx context.Context, listener listenerEntry, _ int) error {
return d.updateListenerCertificate(ctx, d.config.LoadbalancerId, listener.Type, listener.Port, cloudCertId)
}); err != nil {
return err
}
}
@@ -196,44 +183,25 @@ func (d *Deployer) deployToListener(ctx context.Context, cloudCertId string) err
}
// 获取全部 HTTPS/SSL 监听端口
listeners := make([]struct {
type listenerEntry struct {
Type string
Port int32
}, 0)
}
listeners := make([]listenerEntry, 0)
for _, listener := range describeAllListenersResp.AllListenerList {
if listener.ListenerType == "HTTPS" || listener.ListenerType == "SSL" {
listeners = append(listeners, struct {
Type string
Port int32
}{
listeners = append(listeners, listenerEntry{
Type: listener.ListenerType,
Port: int32(listener.ListenerPort),
})
}
}
// 遍历更新监听证书
if len(listeners) == 0 {
d.logger.Info("no blb listeners to deploy")
} else {
d.logger.Info("found blb listeners to deploy", slog.Any("listeners", listeners))
var errs []error
for _, listener := range listeners {
select {
case <-ctx.Done():
return ctx.Err()
default:
if err := d.updateListenerCertificate(ctx, d.config.LoadbalancerId, listener.Type, listener.Port, cloudCertId); err != nil {
errs = append(errs, err)
}
}
}
if len(errs) > 0 {
return errors.Join(errs...)
}
// 更新监听证书
if err := xloop.ForRangeAllWithContext(ctx, listeners, func(ctx context.Context, listener listenerEntry, _ int) error {
return d.updateListenerCertificate(ctx, d.config.LoadbalancerId, listener.Type, listener.Port, cloudCertId)
}); err != nil {
return err
}
return nil
@@ -2,7 +2,6 @@ package baiducloudcdn
import (
"context"
"errors"
"fmt"
"log/slog"
"strings"
@@ -14,6 +13,7 @@ import (
"github.com/samber/lo"
xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname"
xloop "github.com/certimate-go/certimate/pkg/utils/loop"
)
type (
@@ -121,26 +121,16 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*Dep
return nil, fmt.Errorf("unsupported domain match pattern: '%s'", d.config.DomainMatchPattern)
}
// 遍历更新域名证书
// 批量更新域名证书
if len(domains) == 0 {
d.logger.Info("no cdn domains to deploy")
} else {
d.logger.Info("found cdn domains to deploy", slog.Any("domains", domains))
var errs []error
for _, domain := range domains {
select {
case <-ctx.Done():
return nil, ctx.Err()
default:
if err := d.updateDomainCertificate(ctx, domain, certPEM, privkeyPEM); err != nil {
errs = append(errs, err)
}
}
}
if len(errs) > 0 {
return nil, errors.Join(errs...)
if err := xloop.ForRangeAllWithContext(ctx, domains, func(ctx context.Context, domain string, _ int) error {
return d.updateDomainCertificate(ctx, domain, certPEM, privkeyPEM)
}); err != nil {
return nil, err
}
}
@@ -12,6 +12,7 @@ import (
"github.com/certimate-go/certimate/pkg/core"
btpanelsdk "github.com/certimate-go/certimate/pkg/sdk3rd/btpanel"
xloop "github.com/certimate-go/certimate/pkg/utils/loop"
xwait "github.com/certimate-go/certimate/pkg/utils/wait"
)
@@ -93,22 +94,17 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*Dep
}
}
// 遍历更新站点证书
var errs []error
for i, siteName := range d.config.SiteNames {
select {
case <-ctx.Done():
return nil, ctx.Err()
default:
if err := d.updateSiteCertificate(ctx, d.config.SiteType, siteName, certPEM, privkeyPEM); err != nil {
errs = append(errs, err)
} else if i < len(d.config.SiteNames)-1 {
xwait.DelayWithContext(ctx, 5*time.Second)
// 批量更新站点证书
if err := xloop.ForRangeAllWithContext(ctx, d.config.SiteNames, func(ctx context.Context, siteName string, i int) error {
if i > 0 {
if err := xwait.DelayWithContext(ctx, 3*time.Second); err != nil {
return err
}
}
}
if len(errs) > 0 {
return nil, errors.Join(errs...)
return d.updateSiteCertificate(ctx, d.config.SiteType, siteName, certPEM, privkeyPEM)
}); err != nil {
return nil, err
}
}
}
@@ -5,7 +5,6 @@ import (
"crypto/sha256"
"crypto/tls"
"encoding/hex"
"errors"
"fmt"
"log/slog"
"strings"
@@ -16,6 +15,7 @@ import (
"github.com/certimate-go/certimate/pkg/core"
btpanelgosdk "github.com/certimate-go/certimate/pkg/sdk3rd/btpanelgo"
xcert "github.com/certimate-go/certimate/pkg/utils/cert"
xloop "github.com/certimate-go/certimate/pkg/utils/loop"
xwait "github.com/certimate-go/certimate/pkg/utils/wait"
)
@@ -86,22 +86,17 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*Dep
}
}
// 遍历更新站点证书
var errs []error
for i, siteName := range d.config.SiteNames {
select {
case <-ctx.Done():
return nil, ctx.Err()
default:
if err := d.updateSiteCertificate(ctx, d.config.SiteType, siteName, certPEM, privkeyPEM); err != nil {
errs = append(errs, err)
} else if i < len(d.config.SiteNames)-1 {
xwait.DelayWithContext(ctx, 5*time.Second)
// 批量更新站点证书
if err := xloop.ForRangeAllWithContext(ctx, d.config.SiteNames, func(ctx context.Context, siteName string, i int) error {
if i > 0 {
if err := xwait.DelayWithContext(ctx, 3*time.Second); err != nil {
return err
}
}
}
if len(errs) > 0 {
return nil, errors.Join(errs...)
return d.updateSiteCertificate(ctx, d.config.SiteType, siteName, certPEM, privkeyPEM)
}); err != nil {
return nil, err
}
return &DeployResult{}, nil
@@ -3,7 +3,6 @@ package baotawaf
import (
"context"
"crypto/tls"
"errors"
"fmt"
"log/slog"
"time"
@@ -12,6 +11,7 @@ import (
"github.com/certimate-go/certimate/pkg/core"
btwafsdk "github.com/certimate-go/certimate/pkg/sdk3rd/btwaf"
xloop "github.com/certimate-go/certimate/pkg/utils/loop"
xwait "github.com/certimate-go/certimate/pkg/utils/wait"
)
@@ -72,22 +72,17 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*Dep
return nil, fmt.Errorf("config `siteNames` is required")
}
// 遍历更新站点证书
var errs []error
for i, siteName := range d.config.SiteNames {
select {
case <-ctx.Done():
return nil, ctx.Err()
default:
if err := d.updateSiteCertificate(ctx, siteName, d.config.SitePort, certPEM, privkeyPEM); err != nil {
errs = append(errs, err)
} else if i < len(d.config.SiteNames)-1 {
xwait.DelayWithContext(ctx, 5*time.Second)
// 批量更新站点证书
if err := xloop.ForRangeAllWithContext(ctx, d.config.SiteNames, func(ctx context.Context, siteName string, i int) error {
if i > 0 {
if err := xwait.DelayWithContext(ctx, 3*time.Second); err != nil {
return err
}
}
}
if len(errs) > 0 {
return nil, errors.Join(errs...)
return d.updateSiteCertificate(ctx, siteName, d.config.SitePort, certPEM, privkeyPEM)
}); err != nil {
return nil, err
}
return &DeployResult{}, nil
@@ -2,7 +2,6 @@ package byteplusalb
import (
"context"
"errors"
"fmt"
"log/slog"
@@ -14,6 +13,7 @@ import (
"github.com/certimate-go/certimate/pkg/core"
cmgrimpl "github.com/certimate-go/certimate/pkg/core/certmgr/providers/byteplus-certcenter"
xloop "github.com/certimate-go/certimate/pkg/utils/loop"
)
type (
@@ -168,26 +168,16 @@ func (d *Deployer) deployToLoadbalancer(ctx context.Context, cloudCertId string)
describeListenersPageNumber++
}
// 遍历更新监听证书
// 批量更新监听证书
if len(listenerIds) == 0 {
d.logger.Info("no alb listeners to deploy")
} else {
d.logger.Info("found alb listeners to deploy", slog.Any("listenerIds", listenerIds))
var errs []error
for _, listenerId := range listenerIds {
select {
case <-ctx.Done():
return ctx.Err()
default:
if err := d.updateListenerCertificate(ctx, listenerId, cloudCertId); err != nil {
errs = append(errs, err)
}
}
}
if len(errs) > 0 {
return errors.Join(errs...)
if err := xloop.ForRangeAllWithContext(ctx, listenerIds, func(ctx context.Context, listenerId string, _ int) error {
return d.updateListenerCertificate(ctx, listenerId, cloudCertId)
}); err != nil {
return err
}
}
@@ -2,7 +2,6 @@ package byteplusapig
import (
"context"
"errors"
"fmt"
"log/slog"
@@ -15,6 +14,7 @@ import (
"github.com/certimate-go/certimate/pkg/core"
cmgrimpl "github.com/certimate-go/certimate/pkg/core/certmgr/providers/byteplus-certcenter"
xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname"
xloop "github.com/certimate-go/certimate/pkg/utils/loop"
)
type (
@@ -166,26 +166,16 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*Dep
return nil, fmt.Errorf("unsupported domain match pattern: '%s'", d.config.DomainMatchPattern)
}
// 遍历更新域名证书
// 批量更新域名证书
if len(domainIds) == 0 {
d.logger.Info("no apig domains to deploy")
} else {
d.logger.Info("found apig domains to deploy", slog.Any("domainIds", domainIds))
var errs []error
for _, domainId := range domainIds {
select {
case <-ctx.Done():
return nil, ctx.Err()
default:
if err := d.updateDomainCertificate(ctx, domainId, upres.CertId); err != nil {
errs = append(errs, err)
}
}
}
if len(errs) > 0 {
return nil, errors.Join(errs...)
if err := xloop.ForRangeAllWithContext(ctx, domainIds, func(ctx context.Context, domainId string, _ int) error {
return d.updateDomainCertificate(ctx, domainId, upres.CertId)
}); err != nil {
return nil, err
}
}
@@ -2,7 +2,6 @@ package bytepluscdn
import (
"context"
"errors"
"fmt"
"log/slog"
"strings"
@@ -13,6 +12,7 @@ import (
"github.com/certimate-go/certimate/pkg/core"
cmgrimpl "github.com/certimate-go/certimate/pkg/core/certmgr/providers/byteplus-cdn"
xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname"
xloop "github.com/certimate-go/certimate/pkg/utils/loop"
)
type (
@@ -131,26 +131,16 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*Dep
return nil, fmt.Errorf("unsupported domain match pattern: '%s'", d.config.DomainMatchPattern)
}
// 遍历绑定证书
// 批量绑定证书
if len(domains) == 0 {
d.logger.Info("no cdn domains to deploy")
} else {
d.logger.Info("found cdn domains to deploy", slog.Any("domains", domains))
var errs []error
for _, domain := range domains {
select {
case <-ctx.Done():
return nil, ctx.Err()
default:
if err := d.updateDomainCertificate(ctx, domain, upres.CertId); err != nil {
errs = append(errs, err)
}
}
}
if len(errs) > 0 {
return nil, errors.Join(errs...)
if err := xloop.ForRangeAllWithContext(ctx, domains, func(ctx context.Context, domain string, _ int) error {
return d.updateDomainCertificate(ctx, domain, upres.CertId)
}); err != nil {
return nil, err
}
}
@@ -2,7 +2,6 @@ package byteplusclb
import (
"context"
"errors"
"fmt"
"log/slog"
@@ -13,6 +12,7 @@ import (
"github.com/certimate-go/certimate/pkg/core"
cmgrimpl "github.com/certimate-go/certimate/pkg/core/certmgr/providers/byteplus-certcenter"
xloop "github.com/certimate-go/certimate/pkg/utils/loop"
)
type (
@@ -165,26 +165,16 @@ func (d *Deployer) deployToLoadbalancer(ctx context.Context, cloudCertId string)
describeListenersPageNumber++
}
// 遍历更新监听证书
// 批量更新监听证书
if len(listenerIds) == 0 {
d.logger.Info("no clb listeners to deploy")
} else {
d.logger.Info("found clb listeners to deploy", slog.Any("listenerIds", listenerIds))
var errs []error
for _, listenerId := range listenerIds {
select {
case <-ctx.Done():
return ctx.Err()
default:
if err := d.updateListenerCertificate(ctx, listenerId, cloudCertId); err != nil {
errs = append(errs, err)
}
}
}
if len(errs) > 0 {
return errors.Join(errs...)
if err := xloop.ForRangeAllWithContext(ctx, listenerIds, func(ctx context.Context, listenerId string, _ int) error {
return d.updateListenerCertificate(ctx, listenerId, cloudCertId)
}); err != nil {
return err
}
}
@@ -2,7 +2,6 @@ package byteplusmedialive
import (
"context"
"errors"
"fmt"
"log/slog"
"strings"
@@ -14,6 +13,7 @@ import (
"github.com/certimate-go/certimate/pkg/core"
cmgrimpl "github.com/certimate-go/certimate/pkg/core/certmgr/providers/byteplus-medialive"
xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname"
xloop "github.com/certimate-go/certimate/pkg/utils/loop"
)
type (
@@ -143,26 +143,16 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*Dep
return nil, fmt.Errorf("unsupported domain match pattern: '%s'", d.config.DomainMatchPattern)
}
// 遍历绑定证书
// 批量绑定证书
if len(domains) == 0 {
d.logger.Info("no live domains to deploy")
} else {
d.logger.Info("found live domains to deploy", slog.Any("domains", domains))
var errs []error
for _, domain := range domains {
select {
case <-ctx.Done():
return nil, ctx.Err()
default:
if err := d.updateDomainCertificate(ctx, domain, upres.CertId); err != nil {
errs = append(errs, err)
}
}
}
if len(errs) > 0 {
return nil, errors.Join(errs...)
if err := xloop.ForRangeAllWithContext(ctx, domains, func(ctx context.Context, domain string, _ int) error {
return d.updateDomainCertificate(ctx, domain, upres.CertId)
}); err != nil {
return nil, err
}
}
@@ -2,7 +2,6 @@ package cmcccloudcdn
import (
"context"
"errors"
"fmt"
"log/slog"
"time"
@@ -16,6 +15,7 @@ import (
"github.com/certimate-go/certimate/pkg/core"
xcert "github.com/certimate-go/certimate/pkg/utils/cert"
xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname"
xloop "github.com/certimate-go/certimate/pkg/utils/loop"
)
type (
@@ -141,26 +141,16 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*Dep
return nil, fmt.Errorf("unsupported domain match pattern: '%s'", d.config.DomainMatchPattern)
}
// 遍历更新域名证书
// 批量更新域名证书
if len(domainIds) == 0 {
d.logger.Info("no cdn domains to deploy")
} else {
d.logger.Info("found cdn domains to deploy", slog.Any("domainIds", domainIds))
var errs []error
for _, domainId := range domainIds {
select {
case <-ctx.Done():
return nil, ctx.Err()
default:
if err := d.updateDomainCertificate(ctx, domainId, certPEM, privkeyPEM); err != nil {
errs = append(errs, err)
}
}
}
if len(errs) > 0 {
return nil, errors.Join(errs...)
if err := xloop.ForRangeAllWithContext(ctx, domainIds, func(ctx context.Context, domainId int32, _ int) error {
return d.updateDomainCertificate(ctx, domainId, certPEM, privkeyPEM)
}); err != nil {
return nil, err
}
}
@@ -2,7 +2,6 @@ package cmcccloudvlb
import (
"context"
"errors"
"fmt"
"log/slog"
@@ -14,6 +13,7 @@ import (
"github.com/certimate-go/certimate/pkg/core"
cmgrimpl "github.com/certimate-go/certimate/pkg/core/certmgr/providers/cmcccloud-vlb"
xloop "github.com/certimate-go/certimate/pkg/utils/loop"
)
type (
@@ -163,26 +163,16 @@ func (d *Deployer) deployToLoadbalancer(ctx context.Context, cloudCertId string)
listLoadBalanceHTTPSListenerPage++
}
// 遍历更新监听证书
// 批量更新监听证书
if len(listenerIds) == 0 {
d.logger.Info("no vlb listeners to deploy")
} else {
d.logger.Info("found vlb listeners to deploy", slog.Any("listenerIds", listenerIds))
var errs []error
for _, listenerId := range listenerIds {
select {
case <-ctx.Done():
return ctx.Err()
default:
if err := d.updateListenerCertificate(ctx, listenerId, cloudCertId); err != nil {
errs = append(errs, err)
}
}
}
if len(errs) > 0 {
return errors.Join(errs...)
if err := xloop.ForRangeAllWithContext(ctx, listenerIds, func(ctx context.Context, listenerId string, _ int) error {
return d.updateListenerCertificate(ctx, listenerId, cloudCertId)
}); err != nil {
return err
}
}
@@ -2,7 +2,6 @@ package ctcccloudao
import (
"context"
"errors"
"fmt"
"log/slog"
"strconv"
@@ -14,6 +13,7 @@ import (
cmgrimpl "github.com/certimate-go/certimate/pkg/core/certmgr/providers/ctcccloud-ao"
ctyunao "github.com/certimate-go/certimate/pkg/sdk3rd/ctyun/ao"
xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname"
xloop "github.com/certimate-go/certimate/pkg/utils/loop"
)
type (
@@ -141,26 +141,16 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*Dep
return nil, fmt.Errorf("unsupported domain match pattern: '%s'", d.config.DomainMatchPattern)
}
// 遍历更新域名证书
// 批量更新域名证书
if len(domains) == 0 {
d.logger.Info("no accessone domains to deploy")
} else {
d.logger.Info("found accessone domains to deploy", slog.Any("domains", domains))
var errs []error
for _, domain := range domains {
select {
case <-ctx.Done():
return nil, ctx.Err()
default:
if err := d.updateDomainCertificate(ctx, domain, upres.CertName); err != nil {
errs = append(errs, err)
}
}
}
if len(errs) > 0 {
return nil, errors.Join(errs...)
if err := xloop.ForRangeAllWithContext(ctx, domains, func(ctx context.Context, domain string, _ int) error {
return d.updateDomainCertificate(ctx, domain, upres.CertName)
}); err != nil {
return nil, err
}
}
@@ -2,7 +2,6 @@ package ctcccloudcdn
import (
"context"
"errors"
"fmt"
"log/slog"
"strings"
@@ -13,6 +12,7 @@ import (
cmgrimpl "github.com/certimate-go/certimate/pkg/core/certmgr/providers/ctcccloud-cdn"
ctyuncdn "github.com/certimate-go/certimate/pkg/sdk3rd/ctyun/cdn"
xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname"
xloop "github.com/certimate-go/certimate/pkg/utils/loop"
)
type (
@@ -140,26 +140,16 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*Dep
return nil, fmt.Errorf("unsupported domain match pattern: '%s'", d.config.DomainMatchPattern)
}
// 遍历更新域名证书
// 批量更新域名证书
if len(domains) == 0 {
d.logger.Info("no cdn domains to deploy")
} else {
d.logger.Info("found cdn domains to deploy", slog.Any("domains", domains))
var errs []error
for _, domain := range domains {
select {
case <-ctx.Done():
return nil, ctx.Err()
default:
if err := d.updateDomainCertificate(ctx, domain, upres.CertName); err != nil {
errs = append(errs, err)
}
}
}
if len(errs) > 0 {
return nil, errors.Join(errs...)
if err := xloop.ForRangeAllWithContext(ctx, domains, func(ctx context.Context, domain string, _ int) error {
return d.updateDomainCertificate(ctx, domain, upres.CertName)
}); err != nil {
return nil, err
}
}
@@ -2,7 +2,6 @@ package ctcccloudelb
import (
"context"
"errors"
"fmt"
"log/slog"
"strings"
@@ -12,6 +11,7 @@ import (
"github.com/certimate-go/certimate/pkg/core"
cmgrimpl "github.com/certimate-go/certimate/pkg/core/certmgr/providers/ctcccloud-elb"
ctyunelb "github.com/certimate-go/certimate/pkg/sdk3rd/ctyun/elb"
xloop "github.com/certimate-go/certimate/pkg/utils/loop"
)
type (
@@ -136,26 +136,16 @@ func (d *Deployer) deployToLoadbalancer(ctx context.Context, cloudCertId string)
}
}
// 遍历更新监听证书
// 批量更新监听证书
if len(listenerIds) == 0 {
d.logger.Info("no elb listeners to deploy")
} else {
d.logger.Info("found elb listeners to deploy", slog.Any("listenerIds", listenerIds))
var errs []error
for _, listenerId := range listenerIds {
select {
case <-ctx.Done():
return ctx.Err()
default:
if err := d.updateListenerCertificate(ctx, listenerId, cloudCertId); err != nil {
errs = append(errs, err)
}
}
}
if len(errs) > 0 {
return errors.Join(errs...)
if err := xloop.ForRangeAllWithContext(ctx, listenerIds, func(ctx context.Context, listenerId string, _ int) error {
return d.updateListenerCertificate(ctx, listenerId, cloudCertId)
}); err != nil {
return err
}
}
@@ -2,7 +2,6 @@ package ctcccloudicdn
import (
"context"
"errors"
"fmt"
"log/slog"
"strings"
@@ -13,6 +12,7 @@ import (
cmgrimpl "github.com/certimate-go/certimate/pkg/core/certmgr/providers/ctcccloud-icdn"
ctyunicdn "github.com/certimate-go/certimate/pkg/sdk3rd/ctyun/icdn"
xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname"
xloop "github.com/certimate-go/certimate/pkg/utils/loop"
)
type (
@@ -140,26 +140,16 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*Dep
return nil, fmt.Errorf("unsupported domain match pattern: '%s'", d.config.DomainMatchPattern)
}
// 遍历更新域名证书
// 批量更新域名证书
if len(domains) == 0 {
d.logger.Info("no icdn domains to deploy")
} else {
d.logger.Info("found icdn domains to deploy", slog.Any("domains", domains))
var errs []error
for _, domain := range domains {
select {
case <-ctx.Done():
return nil, ctx.Err()
default:
if err := d.updateDomainCertificate(ctx, domain, upres.CertName); err != nil {
errs = append(errs, err)
}
}
}
if len(errs) > 0 {
return nil, errors.Join(errs...)
if err := xloop.ForRangeAllWithContext(ctx, domains, func(ctx context.Context, domain string, _ int) error {
return d.updateDomainCertificate(ctx, domain, upres.CertName)
}); err != nil {
return nil, err
}
}
@@ -2,7 +2,6 @@ package ctcccloudlvdn
import (
"context"
"errors"
"fmt"
"log/slog"
@@ -12,6 +11,7 @@ import (
cmgrimpl "github.com/certimate-go/certimate/pkg/core/certmgr/providers/ctcccloud-lvdn"
ctyunlvdn "github.com/certimate-go/certimate/pkg/sdk3rd/ctyun/lvdn"
xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname"
xloop "github.com/certimate-go/certimate/pkg/utils/loop"
)
type (
@@ -116,26 +116,16 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*Dep
return nil, fmt.Errorf("unsupported domain match pattern: '%s'", d.config.DomainMatchPattern)
}
// 遍历更新域名证书
// 批量更新域名证书
if len(domains) == 0 {
d.logger.Info("no lvdn domains to deploy")
} else {
d.logger.Info("found lvdn domains to deploy", slog.Any("domains", domains))
var errs []error
for _, domain := range domains {
select {
case <-ctx.Done():
return nil, ctx.Err()
default:
if err := d.updateDomainCertificate(ctx, domain, upres.CertName); err != nil {
errs = append(errs, err)
}
}
}
if len(errs) > 0 {
return nil, errors.Join(errs...)
if err := xloop.ForRangeAllWithContext(ctx, domains, func(ctx context.Context, domain string, _ int) error {
return d.updateDomainCertificate(ctx, domain, upres.CertName)
}); err != nil {
return nil, err
}
}
@@ -2,7 +2,6 @@ package dogecloudcdn
import (
"context"
"errors"
"fmt"
"log/slog"
"strconv"
@@ -13,6 +12,7 @@ import (
cmgrimpl "github.com/certimate-go/certimate/pkg/core/certmgr/providers/dogecloud"
dogecloudsdk "github.com/certimate-go/certimate/pkg/sdk3rd/dogecloud"
xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname"
xloop "github.com/certimate-go/certimate/pkg/utils/loop"
)
type (
@@ -117,27 +117,17 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*Dep
return nil, fmt.Errorf("unsupported domain match pattern: '%s'", d.config.DomainMatchPattern)
}
// 遍历更新域名证书
// 批量更新域名证书
if len(domains) == 0 {
d.logger.Info("no cdn domains to deploy")
} else {
d.logger.Info("found cdn domains to deploy", slog.Any("domains", domains))
var errs []error
for _, domain := range domains {
select {
case <-ctx.Done():
return nil, ctx.Err()
default:
certId, _ := strconv.ParseInt(upres.CertId, 10, 64)
if err := d.updateDomainCertificate(ctx, domain, certId); err != nil {
errs = append(errs, err)
}
}
}
if len(errs) > 0 {
return nil, errors.Join(errs...)
if err := xloop.ForRangeAllWithContext(ctx, domains, func(ctx context.Context, domain string, _ int) error {
certId, _ := strconv.ParseInt(upres.CertId, 10, 64)
return d.updateDomainCertificate(ctx, domain, certId)
}); err != nil {
return nil, err
}
}
@@ -2,7 +2,6 @@ package huaweicloudaad
import (
"context"
"errors"
"fmt"
"log/slog"
"time"
@@ -18,6 +17,7 @@ import (
"github.com/certimate-go/certimate/pkg/core"
xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname"
xloop "github.com/certimate-go/certimate/pkg/utils/loop"
)
type (
@@ -158,26 +158,16 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*Dep
return nil, fmt.Errorf("unsupported domain match pattern: '%s'", d.config.DomainMatchPattern)
}
// 遍历更新域名证书
// 批量更新域名证书
if len(domainIds) == 0 {
d.logger.Info("no aad domains to deploy")
} else {
d.logger.Info("found aad domains to deploy", slog.Any("domainIds", domainIds))
var errs []error
for _, domainId := range domainIds {
select {
case <-ctx.Done():
return nil, ctx.Err()
default:
if err := d.updateDomainCertificate(ctx, domainId, certPEM, privkeyPEM); err != nil {
errs = append(errs, err)
}
}
}
if len(errs) > 0 {
return nil, errors.Join(errs...)
if err := xloop.ForRangeAllWithContext(ctx, domainIds, func(ctx context.Context, domainId string, _ int) error {
return d.updateDomainCertificate(ctx, domainId, certPEM, privkeyPEM)
}); err != nil {
return nil, err
}
}
@@ -2,7 +2,6 @@ package huaweicloudcdn
import (
"context"
"errors"
"fmt"
"log/slog"
"strings"
@@ -17,6 +16,7 @@ import (
"github.com/certimate-go/certimate/pkg/core"
cmgrimpl "github.com/certimate-go/certimate/pkg/core/certmgr/providers/huaweicloud-scm"
xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname"
xloop "github.com/certimate-go/certimate/pkg/utils/loop"
)
type (
@@ -153,28 +153,18 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*Dep
return nil, fmt.Errorf("unsupported domain match pattern: '%s'", d.config.DomainMatchPattern)
}
// 遍历更新域名证书
// 批量更新域名证书
if len(domains) == 0 {
d.logger.Info("no cdn domains to deploy")
} else {
d.logger.Info("found cdn domains to deploy", slog.Any("domains", domains))
var errs []error
const MAX_DOMAIN_PER_REQUEST = 50
domainChunks := lo.Chunk(domains, MAX_DOMAIN_PER_REQUEST)
for _, domains := range domainChunks {
select {
case <-ctx.Done():
return nil, ctx.Err()
default:
if err := d.updateDomainsCertificate(ctx, domains, upres.CertId, upres.CertName); err != nil {
errs = append(errs, err)
}
}
}
if len(errs) > 0 {
return nil, errors.Join(errs...)
const MAX_DOMAINS_PER_REQUEST = 50
domainChunks := lo.Chunk(domains, MAX_DOMAINS_PER_REQUEST)
if err := xloop.ForRangeAllWithContext(ctx, domainChunks, func(ctx context.Context, domains []string, _ int) error {
return d.updateDomainsCertificate(ctx, domains, upres.CertId, upres.CertName)
}); err != nil {
return nil, err
}
}
@@ -2,7 +2,6 @@ package huaweicloudelb
import (
"context"
"errors"
"fmt"
"log/slog"
"strings"
@@ -20,6 +19,7 @@ import (
"github.com/certimate-go/certimate/pkg/core"
cmgrimpl "github.com/certimate-go/certimate/pkg/core/certmgr/providers/huaweicloud-elb"
xloop "github.com/certimate-go/certimate/pkg/utils/loop"
)
type (
@@ -184,26 +184,16 @@ func (d *Deployer) deployToLoadbalancer(ctx context.Context, certPEM, privkeyPEM
d.logger.Info("ssl certificate uploaded", slog.Any("result", upres))
}
// 遍历更新监听器证书
// 批量更新监听器证书
if len(listenerIds) == 0 {
d.logger.Info("no elb listeners to deploy")
} else {
d.logger.Info("found elb listeners to deploy", slog.Any("listenerIds", listenerIds))
var errs []error
for _, listenerId := range listenerIds {
select {
case <-ctx.Done():
return ctx.Err()
default:
if err := d.updateListenerCertificate(ctx, listenerId, upres.CertId); err != nil {
errs = append(errs, err)
}
}
}
if len(errs) > 0 {
return errors.Join(errs...)
if err := xloop.ForRangeAllWithContext(ctx, listenerIds, func(ctx context.Context, listenerId string, _ int) error {
return d.updateListenerCertificate(ctx, listenerId, upres.CertId)
}); err != nil {
return err
}
}
@@ -2,7 +2,6 @@ package huaweicloudlive
import (
"context"
"errors"
"fmt"
"log/slog"
@@ -20,6 +19,7 @@ import (
"github.com/certimate-go/certimate/pkg/core"
cmgrimpl "github.com/certimate-go/certimate/pkg/core/certmgr/providers/huaweicloud-scm"
xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname"
xloop "github.com/certimate-go/certimate/pkg/utils/loop"
)
type (
@@ -133,26 +133,16 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*Dep
return nil, fmt.Errorf("unsupported domain match pattern: '%s'", d.config.DomainMatchPattern)
}
// 遍历更新域名证书
// 批量更新域名证书
if len(domains) == 0 {
d.logger.Info("no live domains to deploy")
} else {
d.logger.Info("found live domains to deploy", slog.Any("domains", domains))
var errs []error
for _, domain := range domains {
select {
case <-ctx.Done():
return nil, ctx.Err()
default:
if err := d.updateDomainsCertificate(ctx, domain, upres.CertId); err != nil {
errs = append(errs, err)
}
}
}
if len(errs) > 0 {
return nil, errors.Join(errs...)
if err := xloop.ForRangeAllWithContext(ctx, domains, func(ctx context.Context, domain string, _ int) error {
return d.updateDomainsCertificate(ctx, domain, upres.CertId)
}); err != nil {
return nil, err
}
}
@@ -2,7 +2,6 @@ package huaweicloudvod
import (
"context"
"errors"
"fmt"
"log/slog"
@@ -19,6 +18,7 @@ import (
"github.com/certimate-go/certimate/pkg/core"
cmgrimpl "github.com/certimate-go/certimate/pkg/core/certmgr/providers/huaweicloud-scm"
xloop "github.com/certimate-go/certimate/pkg/utils/loop"
)
type (
@@ -117,26 +117,16 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*Dep
return nil, fmt.Errorf("unsupported domain match pattern: '%s'", d.config.DomainMatchPattern)
}
// 遍历更新域名证书
// 批量更新域名证书
if len(domains) == 0 {
d.logger.Info("no vod domains to deploy")
} else {
d.logger.Info("found vod domains to deploy", slog.Any("domains", domains))
var errs []error
for _, domain := range domains {
select {
case <-ctx.Done():
return nil, ctx.Err()
default:
if err := d.updateDomainsCertificate(ctx, domain, upres.CertId); err != nil {
errs = append(errs, err)
}
}
}
if len(errs) > 0 {
return nil, errors.Join(errs...)
if err := xloop.ForRangeAllWithContext(ctx, domains, func(ctx context.Context, domain string, _ int) error {
return d.updateDomainsCertificate(ctx, domain, upres.CertId)
}); err != nil {
return nil, err
}
}
@@ -2,7 +2,6 @@ package jdcloudalb
import (
"context"
"errors"
"fmt"
"log/slog"
"strings"
@@ -17,6 +16,7 @@ import (
"github.com/certimate-go/certimate/pkg/core"
cmgrimpl "github.com/certimate-go/certimate/pkg/core/certmgr/providers/jdcloud-ssl"
xloop "github.com/certimate-go/certimate/pkg/utils/loop"
)
type (
@@ -169,27 +169,16 @@ func (d *Deployer) deployToLoadbalancer(ctx context.Context, cloudCertId string)
describeListenersPageNumber++
}
// 遍历更新监听器证书
// 批量更新监听器证书
if len(listenerIds) == 0 {
d.logger.Info("no alb listeners to deploy")
} else {
d.logger.Info("found alb listeners to deploy", slog.Any("listenerIds", listenerIds))
var errs []error
for _, listenerId := range listenerIds {
select {
case <-ctx.Done():
return ctx.Err()
default:
if err := d.updateListenerCertificate(ctx, listenerId, cloudCertId); err != nil {
errs = append(errs, err)
}
}
}
if len(errs) > 0 {
return errors.Join(errs...)
if err := xloop.ForRangeAllWithContext(ctx, listenerIds, func(ctx context.Context, listenerId string, _ int) error {
return d.updateListenerCertificate(ctx, listenerId, cloudCertId)
}); err != nil {
return err
}
}
@@ -2,7 +2,6 @@ package jdcloudcdn
import (
"context"
"errors"
"fmt"
"log/slog"
"strings"
@@ -16,6 +15,7 @@ import (
"github.com/certimate-go/certimate/pkg/core"
cmgrimpl "github.com/certimate-go/certimate/pkg/core/certmgr/providers/jdcloud-ssl"
xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname"
xloop "github.com/certimate-go/certimate/pkg/utils/loop"
)
type (
@@ -143,26 +143,16 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*Dep
return nil, fmt.Errorf("unsupported domain match pattern: '%s'", d.config.DomainMatchPattern)
}
// 遍历更新域名证书
// 批量更新域名证书
if len(domains) == 0 {
d.logger.Info("no cdn domains to deploy")
} else {
d.logger.Info("found cdn domains to deploy", slog.Any("domains", domains))
var errs []error
for _, domain := range domains {
select {
case <-ctx.Done():
return nil, ctx.Err()
default:
if err := d.updateDomainCertificate(ctx, domain, upres.CertId); err != nil {
errs = append(errs, err)
}
}
}
if len(errs) > 0 {
return nil, errors.Join(errs...)
if err := xloop.ForRangeAllWithContext(ctx, domains, func(ctx context.Context, domain string, _ int) error {
return d.updateDomainCertificate(ctx, domain, upres.CertId)
}); err != nil {
return nil, err
}
}
@@ -2,7 +2,6 @@ package jdcloudlive
import (
"context"
"errors"
"fmt"
"log/slog"
@@ -14,6 +13,7 @@ import (
"github.com/certimate-go/certimate/pkg/core"
xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname"
xloop "github.com/certimate-go/certimate/pkg/utils/loop"
)
type (
@@ -98,26 +98,16 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*Dep
return nil, fmt.Errorf("unsupported domain match pattern: '%s'", d.config.DomainMatchPattern)
}
// 遍历更新域名证书
// 批量更新域名证书
if len(domains) == 0 {
d.logger.Info("no live domains to deploy")
} else {
d.logger.Info("found live domains to deploy", slog.Any("domains", domains))
var errs []error
for _, domain := range domains {
select {
case <-ctx.Done():
return nil, ctx.Err()
default:
if err := d.updateDomainCertificate(ctx, domain, certPEM, privkeyPEM); err != nil {
errs = append(errs, err)
}
}
}
if len(errs) > 0 {
return nil, errors.Join(errs...)
if err := xloop.ForRangeAllWithContext(ctx, domains, func(ctx context.Context, domain string, _ int) error {
return d.updateDomainCertificate(ctx, domain, certPEM, privkeyPEM)
}); err != nil {
return nil, err
}
}
@@ -2,7 +2,6 @@ package jdcloudvod
import (
"context"
"errors"
"fmt"
"log/slog"
"strconv"
@@ -16,6 +15,7 @@ import (
"github.com/certimate-go/certimate/pkg/core"
xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname"
xloop "github.com/certimate-go/certimate/pkg/utils/loop"
)
type (
@@ -100,26 +100,16 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*Dep
return nil, fmt.Errorf("unsupported domain match pattern: '%s'", d.config.DomainMatchPattern)
}
// 遍历更新域名证书
// 批量更新域名证书
if len(domains) == 0 {
d.logger.Info("no vod domains to deploy")
} else {
d.logger.Info("found vod domains to deploy", slog.Any("domains", domains))
var errs []error
for _, domain := range domains {
select {
case <-ctx.Done():
return nil, ctx.Err()
default:
if err := d.updateDomainCertificate(ctx, domain, certPEM, privkeyPEM); err != nil {
errs = append(errs, err)
}
}
}
if len(errs) > 0 {
return nil, errors.Join(errs...)
if err := xloop.ForRangeAllWithContext(ctx, domains, func(ctx context.Context, domain string, _ int) error {
return d.updateDomainCertificate(ctx, domain, certPEM, privkeyPEM)
}); err != nil {
return nil, err
}
}
@@ -2,7 +2,6 @@ package ksyuncdn
import (
"context"
"errors"
"fmt"
"log/slog"
"time"
@@ -12,6 +11,7 @@ import (
"github.com/certimate-go/certimate/pkg/core"
ksyuncdnsdk "github.com/certimate-go/certimate/pkg/sdk3rd/ksyun/cdn"
xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname"
xloop "github.com/certimate-go/certimate/pkg/utils/loop"
)
type (
@@ -168,26 +168,16 @@ func (d *Deployer) deployToDomain(ctx context.Context, certPEM, privkeyPEM strin
return fmt.Errorf("unsupported domain match pattern: '%s'", d.config.DomainMatchPattern)
}
// 遍历更新域名证书
// 批量更新域名证书
if len(domainIds) == 0 {
d.logger.Info("no cdn domains to deploy")
} else {
d.logger.Info("found cdn domains to deploy", slog.Any("domainIds", domainIds))
var errs []error
for _, domainId := range domainIds {
select {
case <-ctx.Done():
return ctx.Err()
default:
if err := d.updateDomainCertificate(ctx, domainId, certPEM, privkeyPEM); err != nil {
errs = append(errs, err)
}
}
}
if len(errs) > 0 {
return errors.Join(errs...)
if err := xloop.ForRangeAllWithContext(ctx, domainIds, func(ctx context.Context, domainId string, _ int) error {
return d.updateDomainCertificate(ctx, domainId, certPEM, privkeyPEM)
}); err != nil {
return err
}
}
@@ -13,8 +13,8 @@ var (
fTestKeyPath string
fUsername string
fApiPassword string
fHostID string
fDomainID string
fHostId string
fDomainId int64
)
func init() {
@@ -22,8 +22,8 @@ func init() {
fp.DefineString(&fTestKeyPath, "TESTKEYPATH")
fp.DefineString(&fUsername, "USERNAME")
fp.DefineString(&fApiPassword, "APIPASSWORD")
fp.DefineString(&fHostID, "HOSTID")
fp.DefineString(&fDomainID, "DOMAINID")
fp.DefineString(&fHostId, "HOSTID")
fp.DefineInt64(&fDomainId, "DOMAINID")
}
/*
@@ -44,8 +44,8 @@ func TestProvider(t *testing.T) {
provider, err := impl.NewDeployer(&impl.DeployerConfig{
Username: fUsername,
ApiPassword: fApiPassword,
HostId: fHostID,
DomainId: fDomainID,
HostId: fHostId,
DomainId: fDomainId,
})
if err != nil {
t.Errorf("err: %+v", err)
@@ -3,7 +3,6 @@ package nginxproxymanager
import (
"context"
"crypto/tls"
"errors"
"fmt"
"log/slog"
"strconv"
@@ -15,6 +14,7 @@ import (
cmgrimpl "github.com/certimate-go/certimate/pkg/core/certmgr/providers/nginxproxymanager"
npmsdk "github.com/certimate-go/certimate/pkg/sdk3rd/nginxproxymanager"
xcert "github.com/certimate-go/certimate/pkg/utils/cert"
xloop "github.com/certimate-go/certimate/pkg/utils/loop"
xwait "github.com/certimate-go/certimate/pkg/utils/wait"
)
@@ -179,41 +179,36 @@ func (d *Deployer) deployToHost(ctx context.Context, certPEM, privkeyPEM string)
return fmt.Errorf("unsupported host match pattern: '%s'", d.config.HostMatchPattern)
}
// 遍历更新主机证书
// 批量更新主机证书
if len(hostIds) == 0 {
d.logger.Info("no hosts to deploy")
} else {
d.logger.Info("found hosts to deploy", slog.Any("hostIds", hostIds))
// 跳过已部署过的主机
certId, _ := strconv.ParseInt(upres.CertId, 10, 64)
hostIds = lo.Filter(hostIds, func(hostId int64, _ int) bool {
hostInfo, _ := lo.Find(hostsByType, func(hostItem *npmsdk.Host) bool {
return hostId == hostItem.Id
})
if hostInfo != nil {
certId, _ := strconv.ParseInt(upres.CertId, 10, 64)
return hostInfo.CertificateId != certId
}
return true
})
var errs []error
for i, hostId := range hostIds {
select {
case <-ctx.Done():
return ctx.Err()
default:
if err := d.updateHostCertificate(ctx, d.config.HostType, hostId, certId); err != nil {
errs = append(errs, err)
} else if i < len(hostIds)-1 {
xwait.DelayWithContext(ctx, 5*time.Second)
if err := xloop.ForRangeAllWithContext(ctx, hostIds, func(ctx context.Context, hostId int64, i int) error {
if i > 0 {
if err := xwait.DelayWithContext(ctx, 3*time.Second); err != nil {
return err
}
}
}
if len(errs) > 0 {
return errors.Join(errs...)
certId, _ := strconv.ParseInt(upres.CertId, 10, 64)
return d.updateHostCertificate(ctx, d.config.HostType, hostId, certId)
}); err != nil {
return err
}
}
@@ -2,7 +2,6 @@ package qingcloudlb
import (
"context"
"errors"
"fmt"
"log/slog"
"strings"
@@ -13,6 +12,7 @@ import (
"github.com/certimate-go/certimate/pkg/core"
cmgrimpl "github.com/certimate-go/certimate/pkg/core/certmgr/providers/qingcloud-lb"
qclbsdk "github.com/certimate-go/certimate/pkg/sdk3rd/qingcloud/lb"
xloop "github.com/certimate-go/certimate/pkg/utils/loop"
)
type (
@@ -154,26 +154,16 @@ func (d *Deployer) deployToLoadbalancer(ctx context.Context, certPEM, privkeyPEM
d.logger.Info("ssl certificate uploaded", slog.Any("result", upres))
}
// 遍历更新监听器证书
// 批量更新监听器证书
if len(listenerIds) == 0 {
d.logger.Info("no lb listeners to deploy")
} else {
d.logger.Info("found lb listeners to deploy", slog.Any("listenerIds", listenerIds))
var errs []error
for _, listenerId := range listenerIds {
select {
case <-ctx.Done():
return ctx.Err()
default:
if err := d.updateListenerCertificate(ctx, listenerId, upres.CertId); err != nil {
errs = append(errs, err)
}
}
}
if len(errs) > 0 {
return errors.Join(errs...)
if err := xloop.ForRangeAllWithContext(ctx, listenerIds, func(ctx context.Context, listenerId string, _ int) error {
return d.updateListenerCertificate(ctx, listenerId, upres.CertId)
}); err != nil {
return err
}
}
@@ -2,7 +2,6 @@ package qiniucdn
import (
"context"
"errors"
"fmt"
"log/slog"
"strings"
@@ -14,6 +13,7 @@ import (
cmgrimpl "github.com/certimate-go/certimate/pkg/core/certmgr/providers/qiniu-sslcert"
qiniusdk "github.com/certimate-go/certimate/pkg/sdk3rd/qiniu"
xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname"
xloop "github.com/certimate-go/certimate/pkg/utils/loop"
)
type (
@@ -139,26 +139,16 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*Dep
return nil, fmt.Errorf("unsupported domain match pattern: '%s'", d.config.DomainMatchPattern)
}
// 遍历更新域名证书
// 批量更新域名证书
if len(domains) == 0 {
d.logger.Info("no cdn domains to deploy")
} else {
d.logger.Info("found cdn domains to deploy", slog.Any("domains", domains))
var errs []error
for _, domain := range domains {
select {
case <-ctx.Done():
return nil, ctx.Err()
default:
if err := d.updateDomainCertificate(ctx, domain, upres.CertId); err != nil {
errs = append(errs, err)
}
}
}
if len(errs) > 0 {
return nil, errors.Join(errs...)
if err := xloop.ForRangeAllWithContext(ctx, domains, func(ctx context.Context, domain string, _ int) error {
return d.updateDomainCertificate(ctx, domain, upres.CertId)
}); err != nil {
return nil, err
}
}
@@ -2,7 +2,6 @@ package qiniupili
import (
"context"
"errors"
"fmt"
"log/slog"
@@ -12,6 +11,7 @@ import (
"github.com/certimate-go/certimate/pkg/core"
cmgrimpl "github.com/certimate-go/certimate/pkg/core/certmgr/providers/qiniu-sslcert"
xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname"
xloop "github.com/certimate-go/certimate/pkg/utils/loop"
)
type (
@@ -119,26 +119,16 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*Dep
return nil, fmt.Errorf("unsupported domain match pattern: '%s'", d.config.DomainMatchPattern)
}
// 遍历更新域名证书
// 批量更新域名证书
if len(domains) == 0 {
d.logger.Info("no pili domains to deploy")
} else {
d.logger.Info("found pili domains to deploy", slog.Any("domains", domains))
var errs []error
for _, domain := range domains {
select {
case <-ctx.Done():
return nil, ctx.Err()
default:
if err := d.updateDomainCertificate(ctx, d.config.Hub, domain, upres.CertName); err != nil {
errs = append(errs, err)
}
}
}
if len(errs) > 0 {
return nil, errors.Join(errs...)
if err := xloop.ForRangeAllWithContext(ctx, domains, func(ctx context.Context, domain string, _ int) error {
return d.updateDomainCertificate(ctx, d.config.Hub, domain, upres.CertName)
}); err != nil {
return nil, err
}
}
@@ -90,9 +90,9 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*Dep
// RCDN SSL 绑定域名
// REF: https://api.rainyun.com/#/paths/product-rcdn-instance-:id-ssl_bind/post
certId, _ := strconv.ParseInt(upres.CertId, 10, 64)
certIdAsInt, _ := strconv.ParseInt(upres.CertId, 10, 64)
rcdnInstanceSslBindReq := &rainyunsdk.RcdnInstanceSslBindRequest{
CertId: certId,
CertId: certIdAsInt,
Domains: []string{d.config.Domain},
}
rcdnInstanceSslBindResp, err := d.sdkClient.RcdnInstanceSslBindWithContext(ctx, d.config.InstanceId, rcdnInstanceSslBindReq)
@@ -3,13 +3,15 @@ package ratpanel
import (
"context"
"crypto/tls"
"errors"
"fmt"
"log/slog"
"time"
"github.com/certimate-go/certimate/pkg/core"
ratpanelsdk "github.com/certimate-go/certimate/pkg/sdk3rd/ratpanel"
xcert "github.com/certimate-go/certimate/pkg/utils/cert"
xloop "github.com/certimate-go/certimate/pkg/utils/loop"
xwait "github.com/certimate-go/certimate/pkg/utils/wait"
)
type (
@@ -94,20 +96,17 @@ func (d *Deployer) deployToWebsite(ctx context.Context, certPEM, privkeyPEM stri
return fmt.Errorf("config `siteNames` is required")
}
// 遍历更新站点证书
var errs []error
for _, siteName := range d.config.SiteNames {
select {
case <-ctx.Done():
return ctx.Err()
default:
if err := d.updateSiteCertificate(ctx, siteName, certPEM, privkeyPEM); err != nil {
errs = append(errs, err)
// 批量更新站点证书
if err := xloop.ForRangeAllWithContext(ctx, d.config.SiteNames, func(ctx context.Context, siteName string, i int) error {
if i > 0 {
if err := xwait.DelayWithContext(ctx, 3*time.Second); err != nil {
return err
}
}
}
if len(errs) > 0 {
return errors.Join(errs...)
return d.updateSiteCertificate(ctx, siteName, certPEM, privkeyPEM)
}); err != nil {
return err
}
return nil
@@ -2,7 +2,6 @@ package tencentcloudcdn
import (
"context"
"errors"
"fmt"
"log/slog"
"strings"
@@ -16,6 +15,7 @@ import (
"github.com/certimate-go/certimate/pkg/core"
cmgrimpl "github.com/certimate-go/certimate/pkg/core/certmgr/providers/tencentcloud-ssl"
xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname"
xloop "github.com/certimate-go/certimate/pkg/utils/loop"
xtencentcloud "github.com/certimate-go/certimate/pkg/utils/third-party/tencentcloud"
)
@@ -140,26 +140,16 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*Dep
return nil, fmt.Errorf("unsupported domain match pattern: '%s'", d.config.DomainMatchPattern)
}
// 遍历更新域名证书
// 批量更新域名证书
if len(domains) == 0 {
d.logger.Info("no cdn domains to deploy")
} else {
d.logger.Info("found cdn domains to deploy", slog.Any("domains", domains))
var errs []error
for _, domain := range domains {
select {
case <-ctx.Done():
return nil, ctx.Err()
default:
if err := d.updateDomainCertificate(ctx, domain, upres.CertId); err != nil {
errs = append(errs, err)
}
}
}
if len(errs) > 0 {
return nil, errors.Join(errs...)
if err := xloop.ForRangeAllWithContext(ctx, domains, func(ctx context.Context, domain string, _ int) error {
return d.updateDomainCertificate(ctx, domain, upres.CertId)
}); err != nil {
return nil, err
}
}
@@ -2,7 +2,6 @@ package tencentcloudclb
import (
"context"
"errors"
"fmt"
"log/slog"
"time"
@@ -15,6 +14,7 @@ import (
"github.com/certimate-go/certimate/pkg/core"
cmgrimpl "github.com/certimate-go/certimate/pkg/core/certmgr/providers/tencentcloud-ssl"
xloop "github.com/certimate-go/certimate/pkg/utils/loop"
xtencentcloud "github.com/certimate-go/certimate/pkg/utils/third-party/tencentcloud"
xwait "github.com/certimate-go/certimate/pkg/utils/wait"
)
@@ -154,26 +154,16 @@ func (d *Deployer) deployToLoadbalancer(ctx context.Context, cloudCertId string)
}
}
// 遍历更新监听器证书
// 批量更新监听器证书
if len(listenerIds) == 0 {
d.logger.Info("no clb listeners to deploy")
} else {
d.logger.Info("found clb listeners to deploy", slog.Any("listenerIds", listenerIds))
var errs []error
for _, listenerId := range listenerIds {
select {
case <-ctx.Done():
return ctx.Err()
default:
if err := d.updateListenerCertificate(ctx, d.config.LoadbalancerId, listenerId, cloudCertId); err != nil {
errs = append(errs, err)
}
}
}
if len(errs) > 0 {
return errors.Join(errs...)
if err := xloop.ForRangeAllWithContext(ctx, listenerIds, func(ctx context.Context, listenerId string, _ int) error {
return d.updateListenerCertificate(ctx, d.config.LoadbalancerId, listenerId, cloudCertId)
}); err != nil {
return err
}
}
@@ -2,7 +2,6 @@ package tencentcloudecdn
import (
"context"
"errors"
"fmt"
"log/slog"
"strings"
@@ -16,6 +15,7 @@ import (
"github.com/certimate-go/certimate/pkg/core"
cmgrimpl "github.com/certimate-go/certimate/pkg/core/certmgr/providers/tencentcloud-ssl"
xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname"
xloop "github.com/certimate-go/certimate/pkg/utils/loop"
xtencentcloud "github.com/certimate-go/certimate/pkg/utils/third-party/tencentcloud"
)
@@ -140,26 +140,16 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*Dep
return nil, fmt.Errorf("unsupported domain match pattern: '%s'", d.config.DomainMatchPattern)
}
// 遍历更新域名证书
// 批量更新域名证书
if len(domains) == 0 {
d.logger.Info("no ecdn domains to deploy")
} else {
d.logger.Info("found ecdn domains to deploy", slog.Any("domains", domains))
var errs []error
for _, domain := range domains {
select {
case <-ctx.Done():
return nil, ctx.Err()
default:
if err := d.updateDomainCertificate(ctx, domain, upres.CertId); err != nil {
errs = append(errs, err)
}
}
}
if len(errs) > 0 {
return nil, errors.Join(errs...)
if err := xloop.ForRangeAllWithContext(ctx, domains, func(ctx context.Context, domain string, _ int) error {
return d.updateDomainCertificate(ctx, domain, upres.CertId)
}); err != nil {
return nil, err
}
}
@@ -3,7 +3,6 @@ package tencentcloudeo
import (
"context"
"crypto/x509"
"errors"
"fmt"
"log/slog"
"strings"
@@ -20,6 +19,7 @@ import (
xcert "github.com/certimate-go/certimate/pkg/utils/cert"
xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname"
xcertkey "github.com/certimate-go/certimate/pkg/utils/cert/key"
xloop "github.com/certimate-go/certimate/pkg/utils/loop"
xtencentcloud "github.com/certimate-go/certimate/pkg/utils/third-party/tencentcloud"
)
@@ -189,8 +189,7 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*Dep
// 配置域名证书
// REF: https://cloud.tencent.com/document/api/1552/80764
modifyHostsCertificateReqs := make([]*tceo.ModifyHostsCertificateRequest, 0)
requests := make([]*tceo.ModifyHostsCertificateRequest, 0)
if d.config.EnableMultipleSSL {
const algRSA = "RSA"
const algECC = "ECC"
@@ -238,7 +237,7 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*Dep
}
}
modifyHostsCertificateReqs = append(modifyHostsCertificateReqs, modifyHostsCertificateReq)
requests = append(requests, modifyHostsCertificateReq)
}
} else {
modifyHostsCertificateReq := tceo.NewModifyHostsCertificateRequest()
@@ -247,25 +246,19 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*Dep
modifyHostsCertificateReq.Hosts = common.StringPtrs(domains)
modifyHostsCertificateReq.ServerCertInfo = []*tceo.ServerCertInfo{{CertId: common.StringPtr(upres.CertId)}}
modifyHostsCertificateReqs = append(modifyHostsCertificateReqs, modifyHostsCertificateReq)
requests = append(requests, modifyHostsCertificateReq)
}
var errs []error
for _, modifyHostsCertificateReq := range modifyHostsCertificateReqs {
select {
case <-ctx.Done():
return nil, ctx.Err()
default:
modifyHostsCertificateResp, err := d.sdkClient.ModifyHostsCertificateWithContext(ctx, modifyHostsCertificateReq)
d.logger.Debug("sdk request 'teo.ModifyHostsCertificate'", slog.Any("request", modifyHostsCertificateReq), slog.Any("response", modifyHostsCertificateResp))
if err != nil {
err = fmt.Errorf("failed to execute sdk request 'teo.ModifyHostsCertificate': %w", err)
errs = append(errs, err)
}
if err := xloop.ForRangeAllWithContext(ctx, requests, func(ctx context.Context, modifyHostsCertificateReq *tceo.ModifyHostsCertificateRequest, _ int) error {
modifyHostsCertificateResp, err := d.sdkClient.ModifyHostsCertificateWithContext(ctx, modifyHostsCertificateReq)
d.logger.Debug("sdk request 'teo.ModifyHostsCertificate'", slog.Any("request", modifyHostsCertificateReq), slog.Any("response", modifyHostsCertificateResp))
if err != nil {
return fmt.Errorf("failed to execute sdk request 'teo.ModifyHostsCertificate': %w", err)
}
}
if len(errs) > 0 {
return nil, errors.Join(errs...)
return nil
}); err != nil {
return nil, err
}
}
@@ -3,7 +3,6 @@ package tencentcloudeomakers
import (
"context"
"crypto/x509"
"errors"
"fmt"
"log/slog"
"strings"
@@ -21,6 +20,7 @@ import (
xcert "github.com/certimate-go/certimate/pkg/utils/cert"
xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname"
xcertkey "github.com/certimate-go/certimate/pkg/utils/cert/key"
xloop "github.com/certimate-go/certimate/pkg/utils/loop"
xtencentcloud "github.com/certimate-go/certimate/pkg/utils/third-party/tencentcloud"
)
@@ -212,8 +212,7 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*Dep
// 配置域名证书
// REF: https://cloud.tencent.com/document/api/1552/80764
modifyHostsCertificateReqs := make([]*tceo.ModifyHostsCertificateRequest, 0)
requests := make([]*tceo.ModifyHostsCertificateRequest, 0)
if d.config.EnableMultipleSSL {
const algRSA = "RSA"
const algECC = "ECC"
@@ -267,7 +266,7 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*Dep
}
}
modifyHostsCertificateReqs = append(modifyHostsCertificateReqs, modifyHostsCertificateReq)
requests = append(requests, modifyHostsCertificateReq)
}
} else {
modifyHostsCertificateReq := tceo.NewModifyHostsCertificateRequest()
@@ -276,25 +275,19 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*Dep
modifyHostsCertificateReq.Hosts = common.StringPtrs(domains)
modifyHostsCertificateReq.ServerCertInfo = []*tceo.ServerCertInfo{{CertId: common.StringPtr(upres.CertId)}}
modifyHostsCertificateReqs = append(modifyHostsCertificateReqs, modifyHostsCertificateReq)
requests = append(requests, modifyHostsCertificateReq)
}
var errs []error
for _, modifyHostsCertificateReq := range modifyHostsCertificateReqs {
select {
case <-ctx.Done():
return nil, ctx.Err()
default:
modifyHostsCertificateResp, err := d.sdkClients.TEO.ModifyHostsCertificateWithContext(ctx, modifyHostsCertificateReq)
d.logger.Debug("sdk request 'teo.ModifyHostsCertificate'", slog.Any("request", modifyHostsCertificateReq), slog.Any("response", modifyHostsCertificateResp))
if err != nil {
err = fmt.Errorf("failed to execute sdk request 'teo.ModifyHostsCertificate': %w", err)
errs = append(errs, err)
}
if err := xloop.ForRangeAllWithContext(ctx, requests, func(ctx context.Context, modifyHostsCertificateReq *tceo.ModifyHostsCertificateRequest, _ int) error {
modifyHostsCertificateResp, err := d.sdkClients.TEO.ModifyHostsCertificateWithContext(ctx, modifyHostsCertificateReq)
d.logger.Debug("sdk request 'teo.ModifyHostsCertificate'", slog.Any("request", modifyHostsCertificateReq), slog.Any("response", modifyHostsCertificateResp))
if err != nil {
return fmt.Errorf("failed to execute sdk request 'teo.ModifyHostsCertificate': %w", err)
}
}
if len(errs) > 0 {
return nil, errors.Join(errs...)
return nil
}); err != nil {
return nil, err
}
}
@@ -2,7 +2,6 @@ package tencentcloudscf
import (
"context"
"errors"
"fmt"
"log/slog"
@@ -15,6 +14,7 @@ import (
"github.com/certimate-go/certimate/pkg/core"
cmgrimpl "github.com/certimate-go/certimate/pkg/core/certmgr/providers/tencentcloud-ssl"
xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname"
xloop "github.com/certimate-go/certimate/pkg/utils/loop"
xtencentcloud "github.com/certimate-go/certimate/pkg/utils/third-party/tencentcloud"
)
@@ -128,26 +128,16 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*Dep
return nil, fmt.Errorf("unsupported domain match pattern: '%s'", d.config.DomainMatchPattern)
}
// 遍历更新域名证书
// 批量更新域名证书
if len(domains) == 0 {
d.logger.Info("no scf domains to deploy")
} else {
d.logger.Info("found scf domains to deploy", slog.Any("domains", domains))
var errs []error
for _, domain := range domains {
select {
case <-ctx.Done():
return nil, ctx.Err()
default:
if err := d.updateDomainCertificate(ctx, domain, upres.CertId); err != nil {
errs = append(errs, err)
}
}
}
if len(errs) > 0 {
return nil, errors.Join(errs...)
if err := xloop.ForRangeAllWithContext(ctx, domains, func(ctx context.Context, domain string, _ int) error {
return d.updateDomainCertificate(ctx, domain, upres.CertId)
}); err != nil {
return nil, err
}
}
@@ -2,7 +2,6 @@ package tencentcloudvod
import (
"context"
"errors"
"fmt"
"log/slog"
@@ -14,6 +13,7 @@ import (
"github.com/certimate-go/certimate/pkg/core"
cmgrimpl "github.com/certimate-go/certimate/pkg/core/certmgr/providers/tencentcloud-ssl"
xloop "github.com/certimate-go/certimate/pkg/utils/loop"
xtencentcloud "github.com/certimate-go/certimate/pkg/utils/third-party/tencentcloud"
)
@@ -122,26 +122,16 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*Dep
return nil, fmt.Errorf("unsupported domain match pattern: '%s'", d.config.DomainMatchPattern)
}
// 遍历更新域名证书
// 批量更新域名证书
if len(domains) == 0 {
d.logger.Info("no vod domains to deploy")
} else {
d.logger.Info("found vod domains to deploy", slog.Any("domains", domains))
var errs []error
for _, domain := range domains {
select {
case <-ctx.Done():
return nil, ctx.Err()
default:
if err := d.updateDomainCertificate(ctx, domain, upres.CertId); err != nil {
errs = append(errs, err)
}
}
}
if len(errs) > 0 {
return nil, errors.Join(errs...)
if err := xloop.ForRangeAllWithContext(ctx, domains, func(ctx context.Context, domain string, _ int) error {
return d.updateDomainCertificate(ctx, domain, upres.CertId)
}); err != nil {
return nil, err
}
}
@@ -2,7 +2,6 @@ package ucloudualb
import (
"context"
"errors"
"fmt"
"log/slog"
"time"
@@ -15,6 +14,7 @@ import (
"github.com/certimate-go/certimate/pkg/core"
cmgrimpl "github.com/certimate-go/certimate/pkg/core/certmgr/providers/ucloud-ulb"
ucloudsdk "github.com/certimate-go/certimate/pkg/sdk3rd/ucloud/ulb"
xloop "github.com/certimate-go/certimate/pkg/utils/loop"
)
type (
@@ -159,26 +159,16 @@ func (d *Deployer) deployToLoadbalancer(ctx context.Context, cloudCertId string)
describeListenersOffset += describeListenersLimit
}
// 遍历更新 Listener 证书
// 批量更新 Listener 证书
if len(listenerIds) == 0 {
d.logger.Info("no alb listeners to deploy")
} else {
d.logger.Info("found alb listeners to deploy", slog.Any("listenerIds", listenerIds))
var errs []error
for _, listenerId := range listenerIds {
select {
case <-ctx.Done():
return ctx.Err()
default:
if err := d.updateListenerCertificate(ctx, d.config.LoadbalancerId, listenerId, cloudCertId); err != nil {
errs = append(errs, err)
}
}
}
if len(errs) > 0 {
return errors.Join(errs...)
if err := xloop.ForRangeAllWithContext(ctx, listenerIds, func(ctx context.Context, listenerId string, _ int) error {
return d.updateListenerCertificate(ctx, d.config.LoadbalancerId, listenerId, cloudCertId)
}); err != nil {
return err
}
}
@@ -2,7 +2,6 @@ package uclouduclb
import (
"context"
"errors"
"fmt"
"log/slog"
"sync"
@@ -15,6 +14,7 @@ import (
"github.com/certimate-go/certimate/pkg/core"
cmgrimpl "github.com/certimate-go/certimate/pkg/core/certmgr/providers/ucloud-ulb"
ucloudsdk "github.com/certimate-go/certimate/pkg/sdk3rd/ucloud/ulb"
xloop "github.com/certimate-go/certimate/pkg/utils/loop"
)
type (
@@ -166,26 +166,16 @@ func (d *Deployer) deployToLoadbalancer(ctx context.Context, cloudCertId string)
describeVServerOffset += describeVServerLimit
}
// 遍历更新 VServer 证书
// 批量更新 VServer 证书
if len(vserverIds) == 0 {
d.logger.Info("no clb vservers to deploy")
} else {
d.logger.Info("found clb vservers to deploy", slog.Any("vserverIds", vserverIds))
var errs []error
for _, vserverId := range vserverIds {
select {
case <-ctx.Done():
return ctx.Err()
default:
if err := d.updateVServerCertificate(ctx, d.config.LoadbalancerId, vserverId, cloudCertId); err != nil {
errs = append(errs, err)
}
}
}
if len(errs) > 0 {
return errors.Join(errs...)
if err := xloop.ForRangeAllWithContext(ctx, vserverIds, func(ctx context.Context, vserverId string, _ int) error {
return d.updateVServerCertificate(ctx, d.config.LoadbalancerId, vserverId, cloudCertId)
}); err != nil {
return err
}
}
@@ -2,7 +2,6 @@ package upyuncdn
import (
"context"
"errors"
"fmt"
"log/slog"
"strings"
@@ -13,6 +12,7 @@ import (
cmgrimpl "github.com/certimate-go/certimate/pkg/core/certmgr/providers/upyun-ssl"
upyunsdk "github.com/certimate-go/certimate/pkg/sdk3rd/upyun/console"
xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname"
xloop "github.com/certimate-go/certimate/pkg/utils/loop"
)
type (
@@ -140,26 +140,16 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*Dep
return nil, fmt.Errorf("unsupported domain match pattern: '%s'", d.config.DomainMatchPattern)
}
// 遍历更新域名证书
// 批量更新域名证书
if len(domains) == 0 {
d.logger.Info("no cdn domains to deploy")
} else {
d.logger.Info("found cdn domains to deploy", slog.Any("domains", domains))
var errs []error
for _, domain := range domains {
select {
case <-ctx.Done():
return nil, ctx.Err()
default:
if err := d.updateDomainCertificate(ctx, domain, upres.CertId); err != nil {
errs = append(errs, err)
}
}
}
if len(errs) > 0 {
return nil, errors.Join(errs...)
if err := xloop.ForRangeAllWithContext(ctx, domains, func(ctx context.Context, domain string, _ int) error {
return d.updateDomainCertificate(ctx, domain, upres.CertId)
}); err != nil {
return nil, err
}
}
@@ -2,7 +2,6 @@ package volcenginealb
import (
"context"
"errors"
"fmt"
"log/slog"
@@ -14,6 +13,7 @@ import (
"github.com/certimate-go/certimate/pkg/core"
cmgrimpl "github.com/certimate-go/certimate/pkg/core/certmgr/providers/volcengine-certcenter"
xloop "github.com/certimate-go/certimate/pkg/utils/loop"
)
type (
@@ -170,26 +170,16 @@ func (d *Deployer) deployToLoadbalancer(ctx context.Context, cloudCertId string)
describeListenersPageNumber++
}
// 遍历更新监听证书
// 批量更新监听证书
if len(listenerIds) == 0 {
d.logger.Info("no alb listeners to deploy")
} else {
d.logger.Info("found alb listeners to deploy", slog.Any("listenerIds", listenerIds))
var errs []error
for _, listenerId := range listenerIds {
select {
case <-ctx.Done():
return ctx.Err()
default:
if err := d.updateListenerCertificate(ctx, listenerId, cloudCertId); err != nil {
errs = append(errs, err)
}
}
}
if len(errs) > 0 {
return errors.Join(errs...)
if err := xloop.ForRangeAllWithContext(ctx, listenerIds, func(ctx context.Context, listenerId string, _ int) error {
return d.updateListenerCertificate(ctx, listenerId, cloudCertId)
}); err != nil {
return err
}
}
@@ -2,7 +2,6 @@ package volcengineapig
import (
"context"
"errors"
"fmt"
"log/slog"
@@ -15,6 +14,7 @@ import (
"github.com/certimate-go/certimate/pkg/core"
cmgrimpl "github.com/certimate-go/certimate/pkg/core/certmgr/providers/volcengine-certcenter"
xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname"
xloop "github.com/certimate-go/certimate/pkg/utils/loop"
)
type (
@@ -166,26 +166,16 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*Dep
return nil, fmt.Errorf("unsupported domain match pattern: '%s'", d.config.DomainMatchPattern)
}
// 遍历更新域名证书
// 批量更新域名证书
if len(domainIds) == 0 {
d.logger.Info("no apig domains to deploy")
} else {
d.logger.Info("found apig domains to deploy", slog.Any("domainIds", domainIds))
var errs []error
for _, domainId := range domainIds {
select {
case <-ctx.Done():
return nil, ctx.Err()
default:
if err := d.updateDomainCertificate(ctx, domainId, upres.CertId); err != nil {
errs = append(errs, err)
}
}
}
if len(errs) > 0 {
return nil, errors.Join(errs...)
if err := xloop.ForRangeAllWithContext(ctx, domainIds, func(ctx context.Context, domainId string, _ int) error {
return d.updateDomainCertificate(ctx, domainId, upres.CertId)
}); err != nil {
return nil, err
}
}
@@ -2,7 +2,6 @@ package volcenginecdn
import (
"context"
"errors"
"fmt"
"log/slog"
"strings"
@@ -16,6 +15,7 @@ import (
"github.com/certimate-go/certimate/pkg/core"
cmgrimpl "github.com/certimate-go/certimate/pkg/core/certmgr/providers/volcengine-cdn"
xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname"
xloop "github.com/certimate-go/certimate/pkg/utils/loop"
)
type (
@@ -136,26 +136,16 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*Dep
return nil, fmt.Errorf("unsupported domain match pattern: '%s'", d.config.DomainMatchPattern)
}
// 遍历绑定证书
// 批量绑定证书
if len(domains) == 0 {
d.logger.Info("no cdn domains to deploy")
} else {
d.logger.Info("found cdn domains to deploy", slog.Any("domains", domains))
var errs []error
for _, domain := range domains {
select {
case <-ctx.Done():
return nil, ctx.Err()
default:
if err := d.updateDomainCertificate(ctx, domain, upres.CertId); err != nil {
errs = append(errs, err)
}
}
}
if len(errs) > 0 {
return nil, errors.Join(errs...)
if err := xloop.ForRangeAllWithContext(ctx, domains, func(ctx context.Context, domain string, _ int) error {
return d.updateDomainCertificate(ctx, domain, upres.CertId)
}); err != nil {
return nil, err
}
}
@@ -2,7 +2,6 @@ package volcengineclb
import (
"context"
"errors"
"fmt"
"log/slog"
@@ -13,6 +12,7 @@ import (
"github.com/certimate-go/certimate/pkg/core"
cmgrimpl "github.com/certimate-go/certimate/pkg/core/certmgr/providers/volcengine-certcenter"
xloop "github.com/certimate-go/certimate/pkg/utils/loop"
)
type (
@@ -165,26 +165,16 @@ func (d *Deployer) deployToLoadbalancer(ctx context.Context, cloudCertId string)
describeListenersPageNumber++
}
// 遍历更新监听证书
// 批量更新监听证书
if len(listenerIds) == 0 {
d.logger.Info("no clb listeners to deploy")
} else {
d.logger.Info("found clb listeners to deploy", slog.Any("listenerIds", listenerIds))
var errs []error
for _, listenerId := range listenerIds {
select {
case <-ctx.Done():
return ctx.Err()
default:
if err := d.updateListenerCertificate(ctx, listenerId, cloudCertId); err != nil {
errs = append(errs, err)
}
}
}
if len(errs) > 0 {
return errors.Join(errs...)
if err := xloop.ForRangeAllWithContext(ctx, listenerIds, func(ctx context.Context, listenerId string, _ int) error {
return d.updateListenerCertificate(ctx, listenerId, cloudCertId)
}); err != nil {
return err
}
}
@@ -2,7 +2,6 @@ package volcenginelive
import (
"context"
"errors"
"fmt"
"log/slog"
"strings"
@@ -14,6 +13,7 @@ import (
"github.com/certimate-go/certimate/pkg/core"
cmgrimpl "github.com/certimate-go/certimate/pkg/core/certmgr/providers/volcengine-live"
xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname"
xloop "github.com/certimate-go/certimate/pkg/utils/loop"
)
type (
@@ -143,26 +143,16 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*Dep
return nil, fmt.Errorf("unsupported domain match pattern: '%s'", d.config.DomainMatchPattern)
}
// 遍历绑定证书
// 批量绑定证书
if len(domains) == 0 {
d.logger.Info("no live domains to deploy")
} else {
d.logger.Info("found live domains to deploy", slog.Any("domains", domains))
var errs []error
for _, domain := range domains {
select {
case <-ctx.Done():
return nil, ctx.Err()
default:
if err := d.updateDomainCertificate(ctx, domain, upres.CertId); err != nil {
errs = append(errs, err)
}
}
}
if len(errs) > 0 {
return nil, errors.Join(errs...)
if err := xloop.ForRangeAllWithContext(ctx, domains, func(ctx context.Context, domain string, _ int) error {
return d.updateDomainCertificate(ctx, domain, upres.CertId)
}); err != nil {
return nil, err
}
}
@@ -2,7 +2,6 @@ package volcenginevod
import (
"context"
"errors"
"fmt"
"log/slog"
"strings"
@@ -16,6 +15,7 @@ import (
"github.com/certimate-go/certimate/pkg/core"
cmgrimpl "github.com/certimate-go/certimate/pkg/core/certmgr/providers/volcengine-certcenter"
xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname"
xloop "github.com/certimate-go/certimate/pkg/utils/loop"
)
type (
@@ -150,26 +150,16 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*Dep
return nil, fmt.Errorf("unsupported domain match pattern: '%s'", d.config.DomainMatchPattern)
}
// 遍历更新域名证书
// 批量更新域名证书
if len(domains) == 0 {
d.logger.Info("no vod domains to deploy")
} else {
d.logger.Info("found vod domains to deploy", slog.Any("domains", domains))
var errs []error
for _, domain := range domains {
select {
case <-ctx.Done():
return nil, ctx.Err()
default:
if err := d.updateDomainCertificate(ctx, domain, upres.CertId); err != nil {
errs = append(errs, err)
}
}
}
if len(errs) > 0 {
return nil, errors.Join(errs...)
if err := xloop.ForRangeAllWithContext(ctx, domains, func(ctx context.Context, domain string, _ int) error {
return d.updateDomainCertificate(ctx, domain, upres.CertId)
}); err != nil {
return nil, err
}
}
@@ -105,9 +105,9 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*Dep
// 批量修改域名证书配置
// REF: https://www.wangsu.com/document/api-doc/37447
certId, _ := strconv.ParseInt(upres.CertId, 10, 64)
certIdAsInt, _ := strconv.ParseInt(upres.CertId, 10, 64)
batchUpdateCertificateConfigReq := &wangsucdn.BatchUpdateCertificateConfigRequest{
CertificateId: certId,
CertificateId: certIdAsInt,
DomainNames: domains,
}
batchUpdateCertificateConfigResp, err := d.sdkClient.BatchUpdateCertificateConfigWithContext(ctx, batchUpdateCertificateConfigReq)
@@ -2,7 +2,6 @@ package zenlayercdn
import (
"context"
"errors"
"fmt"
"log/slog"
"time"
@@ -14,6 +13,7 @@ import (
cmgrimpl "github.com/certimate-go/certimate/pkg/core/certmgr/providers/zenlayer-cdn"
zcdnsdk "github.com/certimate-go/certimate/pkg/sdk3rd/zenlayer/cdn"
xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname"
xloop "github.com/certimate-go/certimate/pkg/utils/loop"
xwait "github.com/certimate-go/certimate/pkg/utils/wait"
)
@@ -195,26 +195,16 @@ func (d *Deployer) deployToDomain(ctx context.Context, certPEM, privkeyPEM strin
return fmt.Errorf("unsupported domain match pattern: '%s'", d.config.DomainMatchPattern)
}
// 遍历绑定证书
// 批量绑定证书
if len(domainIds) == 0 {
d.logger.Info("no cdn domains to deploy")
} else {
d.logger.Info("found cdn domains to deploy", slog.Any("domainIds", domainIds))
var errs []error
for _, domainId := range domainIds {
select {
case <-ctx.Done():
return ctx.Err()
default:
if err := d.updateDomainCertificate(ctx, domainId, upres.CertId); err != nil {
errs = append(errs, err)
}
}
}
if len(errs) > 0 {
return errors.Join(errs...)
if err := xloop.ForRangeAllWithContext(ctx, domainIds, func(ctx context.Context, domainId string, _ int) error {
return d.updateDomainCertificate(ctx, domainId, upres.CertId)
}); err != nil {
return err
}
}
+12 -12
View File
@@ -6,18 +6,6 @@ import (
"path/filepath"
)
// 与 [Write] 类似,但写入的是字符串内容。
//
// 入参:
// - path: 文件路径。
// - content: 文件内容。
//
// 出参:
// - 错误。
func WriteString(path string, content string) error {
return Write(path, []byte(content))
}
// 将数据写入指定路径的文件。
// 如果目录不存在,将会递归创建目录。
// 如果文件不存在,将会创建该文件;如果文件已存在,将会覆盖原有内容。
@@ -49,3 +37,15 @@ func Write(path string, data []byte) error {
return nil
}
// 与 [Write] 类似,但写入的是字符串内容。
//
// 入参:
// - path: 文件路径。
// - content: 文件内容。
//
// 出参:
// - 错误。
func WriteString(path string, content string) error {
return Write(path, []byte(content))
}
@@ -20,7 +20,7 @@ func ForRange[T any](collection []T, iter func(item T, index int) error) error {
return ForRangeWithContext(context.Background(), collection, iterWithContext)
}
// 遍历集合并执行迭代函数,或上下文被取消。
// 遍历集合并执行迭代函数,支持传入 context.Context 上下文。
//
// 入参:
// - ctx: 上下文。
@@ -37,7 +37,7 @@ func ForRangeWithContext[T any](ctx context.Context, collection []T, iter func(c
default:
if err := iter(ctx, item, i); err != nil {
return nil
return err
}
}
}
+18 -18
View File
@@ -13,24 +13,6 @@ import (
xfilepath "github.com/certimate-go/certimate/pkg/utils/filepath"
)
// 与 [WriteRemote] 类似,但写入的是字符串内容。
//
// 入参:
// - sshCli: SSH 客户端。
// - path: 文件远程路径。
// - data: 文件数据字节数组。
// - useSCP: 是否使用 SCP 进行传输,否则使用 SFTP。
//
// 出参:
// - 错误。
func WriteRemoteString(sshCli *ssh.Client, path string, content string, useSCP bool) error {
if useSCP {
return writeRemoteStringWithSCP(sshCli, path, content)
}
return writeRemoteStringWithSFTP(sshCli, path, content)
}
// 将数据写入指定远程路径的文件。
// 如果目录不存在,将会递归创建目录。
// 如果文件不存在,将会创建该文件;如果文件已存在,将会覆盖原有内容。
@@ -51,6 +33,24 @@ func WriteRemote(sshCli *ssh.Client, path string, data []byte, useSCP bool) erro
return writeRemoteWithSFTP(sshCli, path, data)
}
// 与 [WriteRemote] 类似,但写入的是字符串内容。
//
// 入参:
// - sshCli: SSH 客户端。
// - path: 文件远程路径。
// - data: 文件数据字节数组。
// - useSCP: 是否使用 SCP 进行传输,否则使用 SFTP。
//
// 出参:
// - 错误。
func WriteRemoteString(sshCli *ssh.Client, path string, content string, useSCP bool) error {
if useSCP {
return writeRemoteStringWithSCP(sshCli, path, content)
}
return writeRemoteStringWithSFTP(sshCli, path, content)
}
// 删除指定远程路径的文件。
//
// 入参:
+1 -1
View File
@@ -16,7 +16,7 @@ func Delay(wait time.Duration) error {
return DelayWithContext(context.Background(), wait)
}
// 等待一段时间,或上下文被取消。
// 等待一段时间,支持传入 context.Context 上下文。
//
// 入参:
// - ctx: 上下文。
+2 -2
View File
@@ -21,7 +21,7 @@ func Until(condition func(index int) (bool, error), interval time.Duration) (boo
return UntilWithContext(context.Background(), conditionWithContext, interval)
}
// 等待直到条件满足,或上下文被取消。
// 等待直到条件满足,支持传入 context.Context 上下文。
//
// 入参:
// - ctx: 上下文。
@@ -68,7 +68,7 @@ func UntilTimeout(condition func(index int) (bool, error), timeout time.Duration
return UntilTimeoutWithContext(context.Background(), conditionWithContext, timeout, interval)
}
// 等待直到条件满足或超时,或上下文被取消。
// 等待直到条件满足或超时,支持传入 context.Context 上下文。
//
// 入参:
// - ctx: 上下文。