Update README and rename cert renewal script

Expanded and reorganized the README for clarity, adding detailed sections on features, installation, customization, troubleshooting, and security. Renamed the certificate renewal script from cert-renew.sh to renew.sh in setup.sh and updated all references accordingly.
This commit is contained in:
xixu-me committed 2025-07-15 19:41:24 +08:00
1 parent 53debacae9
commit 4493c0ec4a
2 files changed
+104 -80

No files matched your search

+100 -76
View File
@@ -1,24 +1,34 @@
# Automated Web Deployment Script
A comprehensive automation script for deploying professional portfolio websites with SSL certificates and optimized web server configuration.
A bash script for automating the deployment of a professional portfolio website with SSL certificate management on Ubuntu/Debian servers.
## 🚀 Features
## Overview
- **Automated Web Server Setup**: Configures Nginx with optimized settings
- **SSL Certificate Management**: Automatic SSL certificate provisioning and renewal using acme.sh
- **Professional Portfolio Template**: Includes a beautiful, responsive portfolio website
- **System Optimization**: Configures BBR congestion control and other performance optimizations
- **Certificate Auto-Renewal**: Sets up automated certificate renewal via cron jobs
- **Security Headers**: Implements HSTS and other security best practices
This repository contains an automated deployment script that sets up a complete web server environment with:
## 📋 Prerequisites
- **Nginx web server** with optimized configuration
- **SSL certificate management** using acme.sh and Let's Encrypt
- **Professional portfolio website** with modern, responsive design
- **Automatic certificate renewal** via cron jobs
- **Security optimizations** and best practices
## Features
- 🚀 **One-command deployment** - Deploy everything with a single script
- 🔒 **Automatic SSL** - Generates and manages SSL certificates
- 📱 **Responsive design** - Mobile-friendly portfolio website
- 🔄 **Auto-renewal** - Certificates renew automatically
- ⚡ **Performance optimized** - BBR congestion control and optimized settings
- 🛡️ **Security hardened** - HTTPS redirects and security headers
## Prerequisites
- Ubuntu/Debian-based Linux server
- Root or sudo access
- Domain name pointing to your server's IP address
- Open ports 80 and 443
## 🛠️ Usage
## Usage
1. Log in as a non-root user and update your system:
@@ -53,97 +63,111 @@ A comprehensive automation script for deploying professional portfolio websites
### Example
```bash
./setup.sh john example.com 12345678-1234-1234-1234-123456789abc
curl -L https://github.com/xixu-me/automated-web-deployment/raw/main/setup.sh | bash -s john example.com 550e8400-e29b-41d4-a716-446655440000
```
## 🎨 Portfolio Features
## What Gets Installed
The included portfolio template features:
The script automatically installs and configures:
- **Responsive Design**: Works on all devices and screen sizes
- **Modern UI**: Clean, professional design with CSS Grid and Flexbox
- **Contact Form**: Ready-to-use contact form structure
- **Project Showcase**: Grid layout for displaying projects
- **Skills Section**: Tag-based skills display
- **SEO Optimized**: Proper HTML structure and meta tags
1. **System packages**: nginx, wget, unzip, openssl, cron
2. **Web server**: Nginx with optimized configuration
3. **SSL certificates**: Let's Encrypt certificates via acme.sh
4. **Portfolio website**: Professional HTML/CSS portfolio template
5. **Security settings**: System optimizations and security headers
### Customization
## Post-Installation
To customize the portfolio:
After the script completes:
1. Edit `/var/www/html/index.html` after installation
2. Modify the personal information, projects, and skills
3. Update the color scheme by changing CSS custom properties
- Your website will be accessible at `https://yourdomain.com`
- SSL certificates will auto-renew weekly
- The server will reboot automatically to apply all changes
## 🔧 What the Script Does
1. **Package Installation**: Installs required packages (cron, nginx)
2. **Web Server Configuration**: Sets up Nginx with optimized configuration
3. **SSL Certificate Setup**: Provisions SSL certificates using Let's Encrypt
4. **Portfolio Deployment**: Creates and deploys a professional portfolio website
5. **Auto-Renewal Setup**: Configures automatic certificate renewal
6. **System Optimization**: Applies performance optimizations
7. **Security Configuration**: Implements security headers and HTTPS redirect
## 📁 File Structure
## File Structure
```text
/var/www/html/ # Web root directory
├── index.html # Portfolio website
~/cert/ # SSL certificates directory
├── x.crt # SSL certificate
├── x.key # Private key
└── cert-renew.sh # Certificate renewal script
/var/www/html/ # Website files
~/cert/ # SSL certificates
~/cert/renew.sh # Certificate renewal script
```
## 🔒 Security Features
## Certificate Management
- **HTTPS Redirect**: Automatic HTTP to HTTPS redirection
- **HSTS Headers**: Strict Transport Security implementation
- **SSL Configuration**: Modern TLS protocols and cipher suites
- **Secure File Permissions**: Proper file ownership and permissions
- **Location**: `~/cert/x.crt` and `~/cert/x.key`
- **Renewal**: Automatic weekly check via cron
- **Logs**: Certificate renewal logs in `~/cert/renewal.log`
## 🔄 Maintenance
## Customization
### Certificate Renewal
To customize the portfolio website:
Certificates are automatically renewed monthly via cron job. To manually renew:
1. Edit `/var/www/html/index.html` after installation
2. Modify the content, styling, and information as needed
3. The website uses modern CSS with responsive design
```bash
bash ~/cert/cert-renew.sh
```
### Nginx Configuration
Main configuration file: `/etc/nginx/nginx.conf`
To reload Nginx after changes:
```bash
sudo systemctl reload nginx
```
## 🐛 Troubleshooting
## Troubleshooting
### Common Issues
1. **Domain not pointing to server**: Ensure DNS A record points to your server's IP
1. **Domain not pointing to server**: Ensure your domain's DNS A record points to your server's IP
2. **Firewall blocking ports**: Make sure ports 80 and 443 are open
3. **Permission errors**: Ensure script is run with appropriate privileges
3. **Permission errors**: Run the script as a non-root user with sudo access
### Log Files
### Service Status
- Nginx access logs: `/var/log/nginx/access.log`
- Nginx error logs: `/var/log/nginx/error.log`
- System logs: `journalctl -u nginx`
Check if services are running:
## 📝 License
```bash
sudo systemctl status nginx
```
### Certificate Status
Check certificate expiration:
```bash
openssl x509 -in ~/cert/x.crt -text -noout | grep -E "(Not Before|Not After)"
```
## Security Considerations
- The script implements security best practices including HTTPS redirects
- Uses modern TLS protocols (TLSv1.2 and TLSv1.3)
- Applies security headers and optimized configurations
- Regular certificate renewals prevent expiration
## License
This project is licensed under the GNU General Public License v3.0 - see the [LICENSE](LICENSE) file for details.
## ⚠️ Important Notes
## Disclaimer
- This script will reboot the server at the end of installation
- Backup any existing Nginx configuration before running
- The script is designed for fresh server installations
- Domain validation is required for SSL certificate issuance
⚠️ **Important Notice**
This script is provided for educational and legitimate web deployment purposes only. Users are responsible for:
- Ensuring compliance with all applicable laws and regulations
- Proper server security and maintenance
- Understanding the configurations being applied to their systems
- Regular security updates and monitoring
The authors and contributors of this project:
- Make no warranties about the security, reliability, or suitability of this script
- Are not responsible for any damage, data loss, or security breaches
- Recommend thorough testing in a development environment before production use
- Advise users to review and understand the script before execution
**Use at your own risk.** Always backup your data and test in a safe environment first.
## Support
For issues and questions:
- Review the troubleshooting section above
- Ensure you're using a supported operating system (Ubuntu/Debian)
---
**Note**: This script automatically reboots the server after installation to apply all system optimizations.
+4 -4
View File
@@ -295,7 +295,7 @@ mkdir ~/cert
chmod +r ~/cert/x.key
# Create certificate renewal script
cat >~/cert/cert-renew.sh <<EOF
cat >~/cert/renew.sh <<EOF
#!/bin/bash
# Certificate renewal script for $DOMAIN
@@ -337,10 +337,10 @@ else
fi
EOF
chmod +x ~/cert/cert-renew.sh
chmod +x ~/cert/renew.sh
# Setup cron jobs
(crontab -l 2>/dev/null; echo "0 2 * * 0 /home/$USERNAME/cert/cert-renew.sh >> /home/$USERNAME/cert/renewal.log 2>&1") | crontab -
(crontab -l 2>/dev/null; echo "0 2 * * 0 /home/$USERNAME/cert/renew.sh >> /home/$USERNAME/cert/renewal.log 2>&1") | crontab -
# Configure X
echo "Configuring X..."
@@ -499,7 +499,7 @@ echo "ID: $ID"
echo "Certificate location: ~/cert/"
echo "Nginx configuration: /etc/nginx/nginx.conf"
echo "X configuration: /usr/local/etc/xray/config.json"
echo "Certificate renewal script: ~/cert/cert-renew.sh"
echo "Certificate renewal script: ~/cert/renew.sh"
echo "Automatic renewal: Configured via cron (weekly check)"
echo "=============================================="
echo "The system will reboot in 10 seconds..."