[新增] 添加 ACME 和 DNS 账号管理功能,支持证书申请与续期

This commit is contained in:
ryan
2026-05-25 14:02:05 +08:00
parent c6a055d5d3
commit 7afe4e5d78
32 changed files with 1796 additions and 76 deletions
+28
View File
@@ -0,0 +1,28 @@
package job
import (
"github.com/robfig/cron/v3"
"log/slog"
)
var cronRunner *cron.Cron
func InitCronJobs() {
cronRunner = cron.New()
// Register SSL renew job
_, err := cronRunner.AddJob("0 0 * * *", &SSLRenewJob{})
if err != nil {
slog.Error("failed to register SSL renew cron job", "error", err)
} else {
slog.Info("registered SSL renew cron job")
}
cronRunner.Start()
}
func StopCronJobs() {
if cronRunner != nil {
cronRunner.Stop()
}
}
+43
View File
@@ -0,0 +1,43 @@
package job
import (
"log/slog"
"openflare/model"
"openflare/service"
"time"
)
type SSLRenewJob struct {
}
func (j *SSLRenewJob) Run() {
slog.Info("The scheduled certificate update task is currently in progress ...")
certificates, err := model.ListTLSCertificates()
if err != nil {
slog.Error("failed to list certificates in SSL renew job", "error", err)
return
}
now := time.Now()
for _, cert := range certificates {
if !cert.AutoRenew || cert.Provider != "acme" || cert.ApplyStatus == "applying" {
continue
}
sub := cert.NotAfter.Sub(now)
// Expiring in less than 7 days (7 * 24 hours)
if sub.Hours() < 168 {
slog.Info("Update the SSL certificate for the domain", "domain", cert.PrimaryDomain)
// Invoke renew process (async go-routine handles Lego inside)
_, err := service.RenewTLSCertificate(cert.ID)
if err != nil {
slog.Error("Failed to update the SSL certificate", "domain", cert.PrimaryDomain, "error", err)
continue
}
slog.Info("Triggered the SSL certificate renew for domain", "domain", cert.PrimaryDomain)
}
}
slog.Info("The scheduled certificate update task has completed")
}