Compare commits
64 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 08a5c823d5 | |||
| eafba0d67d | |||
| e25bd9fb4d | |||
| bff59f5c1f | |||
| 539b80e4ec | |||
| 58520b3567 | |||
| 51bd6160f3 | |||
| 8d3489ba00 | |||
| 3b97d112ad | |||
| 1506d77ee9 | |||
| e4e967e227 | |||
| aebf8042e3 | |||
| 02e3e8d391 | |||
| 95682314de | |||
| 5bc3e7d587 | |||
| fca36ac119 | |||
| 2b0128d0c1 | |||
| c792ec8a0a | |||
| 1732de343d | |||
| 51b2b455a2 | |||
| f8f3bf1539 | |||
| f8908d7830 | |||
| 8a5a72e15a | |||
| 1da49b06db | |||
| 1336c8e63b | |||
| 450733a8d5 | |||
| 92e69d1b85 | |||
| 00ea88780d | |||
| d9aa8973a3 | |||
| ec75cffbf1 | |||
| b8fb744623 | |||
| d0b2c781bf | |||
| c4d28d1f8c | |||
| f085838781 | |||
| 4a6c339a07 | |||
| c94f12e976 | |||
| 5443612381 | |||
| df144a5211 | |||
| 04811805c3 | |||
| aa446c00e6 | |||
| 56a5ad59fe | |||
| ce1ab86d22 | |||
| cae57ccf6b | |||
| 0fcd0d9c13 | |||
| e411a35b93 | |||
| 0e787be456 | |||
| 17c33d237f | |||
| 5b55ac95a3 | |||
| f4dc8f44b1 | |||
| 3792881529 | |||
| c1f54a619c | |||
| 4c997a6b7d | |||
| 1824d9f139 | |||
| 50b4cf105f | |||
| 1e3b545a23 | |||
| 380509c966 | |||
| 71da487aa8 | |||
| 3be6eaee0c | |||
| 5c6c8ec4ea | |||
| c7297a512c | |||
| fddb406717 | |||
| 4ec190af47 | |||
| 57ce2d1ac3 | |||
| 1ffd374a4f |
@@ -55,6 +55,23 @@
|
||||
*.bat text eol=crlf
|
||||
*.cmd text eol=crlf
|
||||
|
||||
# web frontend stack -- force LF so SRI hashes are always correct
|
||||
*.html text eol=lf
|
||||
*.htm text eol=lf
|
||||
*.css text eol=lf
|
||||
*.min.css text eol=lf
|
||||
*.js text eol=lf
|
||||
*.min.js text eol=lf
|
||||
*.php text eol=lf
|
||||
|
||||
# Visual Studio projects (Rider also)
|
||||
*.cs diff=csharp
|
||||
*.sln merge=union
|
||||
*.csproj merge=union
|
||||
*.vbproj merge=union
|
||||
*.fsproj merge=union
|
||||
*.dbproj merge=union
|
||||
|
||||
# Serialisation
|
||||
*.json text
|
||||
*.toml text
|
||||
@@ -79,3 +96,5 @@
|
||||
.gitattributes export-ignore
|
||||
.gitignore export-ignore
|
||||
.gitkeep export-ignore
|
||||
.idea export-ignore
|
||||
.vscode export-ignore
|
||||
|
||||
+34
@@ -1 +1,35 @@
|
||||
#
|
||||
# JetBrains exclusions
|
||||
#
|
||||
|
||||
riderModule.iml
|
||||
/_ReSharper.Caches/
|
||||
|
||||
# User-specific stuff
|
||||
.idea/**/workspace.xml
|
||||
.idea/**/tasks.xml
|
||||
.idea/**/usage.statistics.xml
|
||||
.idea/**/dictionaries
|
||||
.idea/**/shelf
|
||||
|
||||
# Generated files
|
||||
.idea/**/contentModel.xml
|
||||
.idea/**/GitCommitMessageStorage.xml
|
||||
|
||||
# Sensitive or high-churn files
|
||||
.idea/**/dataSources/
|
||||
.idea/**/dataSources.ids
|
||||
.idea/**/dataSources.local.xml
|
||||
.idea/**/sqlDataSources.xml
|
||||
.idea/**/dynamic.xml
|
||||
.idea/**/uiDesigner.xml
|
||||
.idea/**/dbnavigator.xml
|
||||
|
||||
# modules
|
||||
.idea_modules/
|
||||
|
||||
# Editor-based Rest Client
|
||||
.idea/httpRequests
|
||||
|
||||
# project-specific exclusions
|
||||
*.log
|
||||
|
||||
Generated
+6
@@ -0,0 +1,6 @@
|
||||
<?xml version="1.0" encoding="UTF-8"?>
|
||||
<project version="4">
|
||||
<component name="DeveloperToolsToolWindowSettingsV1" lastSelectedContentNodeId="base64-encoder-decoder" pluginVersion="9.0.0">
|
||||
<developerToolsConfigurations />
|
||||
</component>
|
||||
</project>
|
||||
Generated
+15
@@ -0,0 +1,15 @@
|
||||
<?xml version="1.0" encoding="UTF-8"?>
|
||||
<project version="4">
|
||||
<component name="GitToolBoxProjectSettings">
|
||||
<option name="commitMessageIssueKeyValidationOverride">
|
||||
<BoolValueOverride>
|
||||
<option name="enabled" value="true" />
|
||||
</BoolValueOverride>
|
||||
</option>
|
||||
<option name="commitMessageValidationEnabledOverride">
|
||||
<BoolValueOverride>
|
||||
<option name="enabled" value="true" />
|
||||
</BoolValueOverride>
|
||||
</option>
|
||||
</component>
|
||||
</project>
|
||||
Generated
+8
@@ -0,0 +1,8 @@
|
||||
<?xml version="1.0" encoding="UTF-8"?>
|
||||
<project version="4">
|
||||
<component name="UserContentModel">
|
||||
<attachedFolders />
|
||||
<explicitIncludes />
|
||||
<explicitExcludes />
|
||||
</component>
|
||||
</project>
|
||||
Generated
+8
@@ -0,0 +1,8 @@
|
||||
<?xml version="1.0" encoding="UTF-8"?>
|
||||
<project version="4">
|
||||
<component name="com.itcodebox.notebooks.projectservice.ProjectUIState">
|
||||
<option name="selectedNotebookId" value="1" />
|
||||
<option name="selectedChapterId" value="1" />
|
||||
<option name="selectedNoteId" value="1" />
|
||||
</component>
|
||||
</project>
|
||||
Generated
+8
@@ -0,0 +1,8 @@
|
||||
<?xml version="1.0" encoding="UTF-8"?>
|
||||
<project version="4">
|
||||
<component name="RiderProjectSettingsUpdater">
|
||||
<option name="singleClickDiffPreview" value="1" />
|
||||
<option name="unhandledExceptionsIgnoreList" value="1" />
|
||||
<option name="vcsConfiguration" value="3" />
|
||||
</component>
|
||||
</project>
|
||||
Generated
+6
@@ -0,0 +1,6 @@
|
||||
<?xml version="1.0" encoding="UTF-8"?>
|
||||
<project version="4">
|
||||
<component name="VcsDirectoryMappings">
|
||||
<mapping directory="" vcs="Git" />
|
||||
</component>
|
||||
</project>
|
||||
@@ -0,0 +1,4 @@
|
||||
<wpf:ResourceDictionary xml:space="preserve" xmlns:x="http://schemas.microsoft.com/winfx/2006/xaml" xmlns:s="clr-namespace:System;assembly=mscorlib" xmlns:ss="urn:shemas-jetbrains-com:settings-storage-xaml" xmlns:wpf="http://schemas.microsoft.com/winfx/2006/xaml/presentation">
|
||||
<s:Boolean x:Key="/Default/UserDictionary/Words/=cfddns/@EntryIndexedValue">True</s:Boolean>
|
||||
<s:Boolean x:Key="/Default/UserDictionary/Words/=mydomain/@EntryIndexedValue">True</s:Boolean>
|
||||
<s:Boolean x:Key="/Default/UserDictionary/Words/=myserver/@EntryIndexedValue">True</s:Boolean></wpf:ResourceDictionary>
|
||||
@@ -7,7 +7,7 @@ Update your *existing* Cloudflare DNS records with your current (dynamic) IP add
|
||||
<!-- toc -->
|
||||
|
||||
- [Prerequisites](#prerequisites)
|
||||
- [cfddns.sh](#cfddns%2346sh)
|
||||
- [cfddns script](#cfddns-script)
|
||||
* [Installation](#installation)
|
||||
* [Usage](#usage)
|
||||
+ [Parameters](#parameters)
|
||||
@@ -15,10 +15,10 @@ Update your *existing* Cloudflare DNS records with your current (dynamic) IP add
|
||||
* [File structure](#file-structure)
|
||||
* [Bearer token](#bearer-token)
|
||||
* [Zone ID](#zone-id)
|
||||
- [cfddns.service](#cfddnsservice)
|
||||
* [IP4 and/or IP6](#ip4-andor-ip6)
|
||||
- [cfddns systemd service unit](#cfddns-systemd-service-unit)
|
||||
* [IP4 or IP6](#ip4-or-ip6)
|
||||
+ [Examples](#examples)
|
||||
- [cfddns.timer](#cfddnstimer)
|
||||
- [cfddns systemd timer unit](#cfddns-systemd-timer-unit)
|
||||
* [Activation](#activation)
|
||||
- [Logging](#logging)
|
||||
* [Using Logwatch to monitor this script](#using-logwatch-to-monitor-this-script)
|
||||
@@ -37,7 +37,7 @@ apt install -y curl jq
|
||||
|
||||
While the script does *not* require root privileges, you will need sudo/root access to install the *systemd* service and timer.
|
||||
|
||||
## cfddns.sh
|
||||
## cfddns script
|
||||
|
||||
### Installation
|
||||
|
||||
@@ -56,7 +56,7 @@ I recommend putting this script in your */usr/local/bin* directory or somewhere
|
||||
sudo chmod +x /usr/local/bin/cfddns.sh
|
||||
```
|
||||
|
||||
> Note: You can rename *cfddns.sh* to anything you want, the script will auto-update itself. However, you **must** manually update the systemd service file (*cfddns.service*) `ExecStart` line as [explained below](#cfddns.service).
|
||||
> Note: You can rename *cfddns.sh* to anything you want, the script will auto-update itself. However, you **must** manually update the systemd service file (*cfddns.service*) `ExecStart` line as [explained below](#cfddns-script).
|
||||
|
||||
### Usage
|
||||
|
||||
@@ -111,6 +111,13 @@ cfZoneId=83d564234134513245311b23412331dd
|
||||
|
||||
You can save the file as anything you like and anywhere you’d like as long as you inform the script of its location using the `--credentials` parameter. By default, the script will look for a file named *cloudflare.credentials* in the same path as the script.
|
||||
|
||||
Please remember that this file basically contains a password! As a result, it should be protected and access limited to the root account:
|
||||
|
||||
```bash
|
||||
chown root:root /path/to/cloudflare.credentials
|
||||
chmod 600 /path/to/cloudflare.credentials
|
||||
```
|
||||
|
||||
### Bearer token
|
||||
|
||||
I chose to use an API bearer token instead of a username/password or Global API token for security reasons. Your username/password and Global API token provide unfettered access to your account so if anyone gets hold of them, they can do anything to your account. An API bearer token, by contrast, can only do what you authorize it to do and you can revoke it at any time. Therefore, I suggest making a bearer token that is based on the “Edit zone DNS” template and restricted to the specific domain/zone you wish to update. Cloudflare provides an [excellent article](https://support.cloudflare.com/hc/en-us/articles/200167836-Managing-API-Tokens-and-Keys) on how to generate this token.
|
||||
@@ -124,7 +131,7 @@ This is required by the Cloudflare API so it knows which zone you are editing an
|
||||
To get your Zone ID, log into your Cloudflare account and open the domain in question. On the overview page, scroll down a bit and look to the right. You will see your Zone ID listed there. Copy that string into your configuration file.
|
||||
|
||||
|
||||
## cfddns.service
|
||||
## cfddns systemd service unit
|
||||
|
||||
This file **must** be copied to your */etc/systemd/system* directory (or equivalent directory if you're not running Debian/Ubuntu). If you change the name of the cfddns.sh file, you must update the filename in the `ExecStart` line as shown below:
|
||||
|
||||
@@ -136,13 +143,7 @@ ExecStart=/full/path/to/your/renamed.file -parameter1 -parameter2 -parameter...
|
||||
...
|
||||
````
|
||||
|
||||
Don’t forget to reload systemd after copying this file so it is recognized by the system! On most systems you can do this by running the following as root or via sudo:
|
||||
|
||||
```bash
|
||||
systemctl daemon-reload
|
||||
```
|
||||
|
||||
### IP4 and/or IP6
|
||||
### IP4 or IP6
|
||||
|
||||
The cfddns.service file includes two *ExecStart* lines, one without a specified IP-protocol parameter (default IP4) and the other with the -6 (IP6) parameter. The service will run the cfddns.sh script in default (IP4) mode with specified parameters first and then will run the script again in IP6 mode with specified parameters.
|
||||
|
||||
@@ -183,9 +184,9 @@ The cfddns.service file includes two *ExecStart* lines, one without a specified
|
||||
...
|
||||
```
|
||||
|
||||
## cfddns.timer
|
||||
## cfddns systemd timer unit
|
||||
|
||||
This is the timer file that tells your system how often to call the *cfddns.service* file which runs the *cfddns.sh* script. By default, the timer is set for 5 minutes after the system boots up (to allow for other processes to initialize even on slower systems like a RasPi) and is then run every 15 minutes thereafter. Remember when setting your timer that Cloudflare limits API calls to 1200 every 5 minutes.
|
||||
Just like the service file unit, this file **must** be copied to your */etc/systemd/system* directory (or equivalent directory if you're not running Debian/Ubuntu). This timer file unit tells your system how often to call the *cfddns.service* file which runs the *cfddns.sh* script. By default, the timer is set for 5 minutes after the system boots up (to allow for other processes to initialize even on slower systems like a RasPi) and is then run every 15 minutes thereafter. Remember when setting your timer that Cloudflare limits API calls to 1200 every 5 minutes.
|
||||
|
||||
You can change the timer by modifying the relevant section of the *cfddns.timer* file:
|
||||
|
||||
@@ -198,6 +199,12 @@ OnUnitActiveSec=15min
|
||||
*OnBootSec* is how long to wait after the system boots up before executing the *cfddns.service*. *OnUnitActiveSec* will then wait the specified time from that first (after boot) call or after the timer is explicitly started before calling *cfddns.service* again. I recommend setting OnUnitActiveSec to a low value (like 2 minutes) for testing then setting it to a more reasonable time (like 15
|
||||
minutes) after everything is working.
|
||||
|
||||
After you’ve copied both the systemd unit and this timer unit, don’t forget to reload the systemd daemon so they are recognized by the system! On most systems you can do this by running the following as root or via sudo:
|
||||
|
||||
```bash
|
||||
systemctl daemon-reload
|
||||
```
|
||||
|
||||
### Activation
|
||||
|
||||
You can start the timer system immediately via *systemctl*
|
||||
@@ -220,6 +227,8 @@ systemctl status cfddns.timer
|
||||
|
||||
It is NOT necessary to enable/start the *cfddns.service*, only the timer needs to be active.
|
||||
|
||||
Also remember that if you make changes to settings like `OnUnitActiveSec` while testing or after testing is complete you *must* reload the systemd daemon! It will restart the appropriate units for you and your new settings will take effect immediately.
|
||||
|
||||
## Logging
|
||||
|
||||
The script logs every major action it takes and provides details on any errors it encounters in the log file (see the [parameters section](#parameters) for details about setting log location and name). If errors are encountered, they are colour coded red and an explanation of the error code is provided.
|
||||
|
||||
@@ -3,11 +3,13 @@
|
||||
#
|
||||
# update Cloudflare DNS records with current (dynamic) IP address
|
||||
# Script by Asif Bacchus <asif@bacchus.cloud>
|
||||
# Last modified: May 7, 2021
|
||||
# Last modified: July 19, 2026
|
||||
# Version 3.0
|
||||
#
|
||||
|
||||
### text formatting presets using tput
|
||||
if command -v tput >/dev/null; then
|
||||
[ -z "$TERM" ] && export TERM=xterm
|
||||
bold=$(tput bold)
|
||||
cyan=$(tput setaf 6)
|
||||
err=$(tput bold)$(tput setaf 1)
|
||||
@@ -29,81 +31,137 @@ else
|
||||
width=80
|
||||
fi
|
||||
|
||||
### functions
|
||||
badParam() {
|
||||
if [ "$1" = "null" ]; then
|
||||
printf "\n%sERROR: '%s' cannot have a NULL (empty) value.\n" "$err" "$2"
|
||||
printf "%sPlease use '--help' for assistance.%s\n\n" "$cyan" "$norm"
|
||||
([ "$logToConsole" -eq 0 ]) && writeLog \
|
||||
"${2} cannot have a NULL (empty) value" "critical" "fail" "preexec" 1
|
||||
exit 1
|
||||
elif [ "$1" = "dne" ]; then
|
||||
printf "\n%sERROR: '%s %s'\n" "$err" "$2" "$3"
|
||||
printf "file or directory does not exist or is empty.%s\n\n" "$norm"
|
||||
([ "$logToConsole" -eq 0 ]) && writeLog \
|
||||
"${3}: file or directory does not exist or is empty" "critical" "fail" "preexec" 1
|
||||
exit 1
|
||||
elif [ "$1" = "errMsg" ]; then
|
||||
printf "\n%sERROR: %s%s\n\n" "$err" "$2" "$norm"
|
||||
([ "$logToConsole" -eq 0 ]) && writeLog \
|
||||
"${2%%\Exit*}" "fatal" "fail" "preexec" 1
|
||||
exit 1
|
||||
fi
|
||||
}
|
||||
|
||||
exitError() {
|
||||
case "$1" in
|
||||
3)
|
||||
errMsg="Unable to connect to Cloudflare servers. This is probably a temporary networking issue. Please try again later."
|
||||
;;
|
||||
10)
|
||||
errMsg="Unable to auto-detect IP address. Try again later or supply the IP address to be used."
|
||||
;;
|
||||
20)
|
||||
errMsg="Cloudflare authorized email address (cfEmail) is either null or undefined. Please check your Cloudflare credentials file."
|
||||
;;
|
||||
21)
|
||||
errMsg="Cloudflare authorized API key (cfKey) is either null or undefined. Please check your Cloudflare credentials file."
|
||||
;;
|
||||
22)
|
||||
errMsg="Cloudflare zone id (cfZoneId) is either null or undefined. Please check your Cloudflare credentials file."
|
||||
;;
|
||||
25)
|
||||
errMsg="Cloudflare API error. Please review any 'CF-ERR:' lines in this log for details."
|
||||
;;
|
||||
26)
|
||||
errMsg="${failedHostCount} host update(s) failed. Any 'CF-ERR:' lines noted in this log may help determine what went wrong."
|
||||
;;
|
||||
*)
|
||||
writeLog error "An unspecified error occurred. (code: 99)"
|
||||
printf "%s[%s] -- Cloudflare DDNS update-script: completed with error(s) --%s\n" "$err" "$(stamp)" "$norm" >>"$logFile"
|
||||
exit 99
|
||||
;;
|
||||
esac
|
||||
writeLog error "$errMsg" "$1"
|
||||
printf "%s[%s] -- Cloudflare DDNS update-script: completed with error(s) --%s\n" "$err" "$(stamp)" "$norm" >>"$logFile"
|
||||
exit "$1"
|
||||
getHostname() {
|
||||
(hostname -s)
|
||||
}
|
||||
|
||||
exitOK() {
|
||||
printf "%s[%s] -- Cloudflare DDNS update-script: completed successfully --%s\n" "$ok" "$(stamp)" "$norm" >>"$logFile"
|
||||
exit 0
|
||||
getTimeStamp() {
|
||||
(date -u +"%Y-%m-%dT%H:%M:%SZ")
|
||||
}
|
||||
|
||||
lowercase() {
|
||||
echo "$1" | tr '[:upper:]' '[:lower:]'
|
||||
}
|
||||
|
||||
uppercase() {
|
||||
echo "$1" | tr '[:lower:]' '[:upper:]'
|
||||
}
|
||||
|
||||
# 1: cloudflare error object, 2: operation identifier
|
||||
listCFErrors() {
|
||||
# extract error codes and messages in separate variables, replace newlines with underscores
|
||||
codes="$(printf "%s" "$1" | jq -r '.errors | .[] | .code' | tr '\n' '_')"
|
||||
messages="$(printf "%s" "$1" | jq -r '.errors | .[] | .message' | tr '\n' '_')"
|
||||
|
||||
# iterate codes and messages and assemble into coherent messages in log
|
||||
# iterate codes and messages, assemble into a coherent log message
|
||||
while [ -n "$codes" ] && [ -n "$messages" ]; do
|
||||
# get first code and message in respective sets
|
||||
# get the first code and message in respective sets
|
||||
code="${codes%%_*}"
|
||||
message="${messages%%_*}"
|
||||
|
||||
# update codes and messages sets by removing first item in each set
|
||||
# update sets of codes and messages by removing the first item (above) in each set
|
||||
codes="${codes#*_}"
|
||||
messages="${messages#*_}"
|
||||
|
||||
# output to log
|
||||
writeLog cf "$message" "$code"
|
||||
writeLog "${message}" "err" "fail" "$2:CF-ERR" "$code"
|
||||
done
|
||||
}
|
||||
|
||||
standardizeLogLevels() {
|
||||
LEVEL_TO_STANDARDIZE="$(lowercase "$1")"
|
||||
case "$LEVEL_TO_STANDARDIZE" in
|
||||
"critical" | "crit" | "fatal")
|
||||
echo "CRIT"
|
||||
;;
|
||||
"error" | "err")
|
||||
echo "ERR"
|
||||
;;
|
||||
"warning" | "warn")
|
||||
echo "WARN"
|
||||
;;
|
||||
"information" | "info")
|
||||
echo "INFO"
|
||||
;;
|
||||
"debug" | "verbose")
|
||||
echo "DEBUG"
|
||||
;;
|
||||
*)
|
||||
echo "INFO"
|
||||
;;
|
||||
esac
|
||||
}
|
||||
|
||||
# $1: message, $2: level, $3: status, [$4: operation], [$5: code]
|
||||
writeJsonLog() {
|
||||
# not enough information to generate a meaningful log message
|
||||
if [ -z "$1" ] || [ $# -lt 3 ]; then
|
||||
return
|
||||
fi
|
||||
|
||||
JSON_PROPS="$(
|
||||
jq --null-input -c \
|
||||
--arg timestamp "$(getTimeStamp)" \
|
||||
--arg hostname "$(getHostname)" \
|
||||
--arg pName "$LOG_PROGRAM_NAME" \
|
||||
--arg pid "$$" \
|
||||
--arg level "$(standardizeLogLevels "$2")" \
|
||||
--arg status "$(uppercase "$3")" \
|
||||
--arg message "$1" \
|
||||
--arg operation "${4:-UNSPECIFIED}" \
|
||||
--arg code "${5:-0}" \
|
||||
'{"@t":$timestamp, "@m":$message, "@l":$level, "hostname":$hostname, "programName":$pName, "pid":$pid, "status":$status, "operation":$operation, "code":$code}' \
|
||||
)"
|
||||
|
||||
printf "%s\n" "$JSON_PROPS" >>"$logFile"
|
||||
return
|
||||
}
|
||||
|
||||
# modified syslog fmt: <ISO-8601 timestamp> <hostname> <tag>[pid]: [LEVEL:$2] [STATUS:$3] <MESSAGE:$1> (<OPERATION:$4>:<CODE:$5>)
|
||||
writePlainTextLog() {
|
||||
# not enough information to generate a meaningful log message
|
||||
if [ -z "$1" ] || [ $# -lt 3 ]; then
|
||||
return
|
||||
fi
|
||||
|
||||
printf "%s %s %s[%s]: [%s] [%s] %s (%s:%s)\n" \
|
||||
"$(getTimeStamp)" "$(getHostname)" "$LOG_PROGRAM_NAME" "$$" \
|
||||
"$(standardizeLogLevels "$2")" "$(uppercase "$3")" "$1" "${4:-UNSPECIFIED}" "${5:-0}" \
|
||||
>>"$logFile"
|
||||
}
|
||||
|
||||
writeLog() {
|
||||
([ "$logToNone" -eq 1 ]) && return
|
||||
|
||||
PT_LOG_LEVEL="$(standardizeLogLevels "$2")"
|
||||
([ "$logDebug" -eq 0 ] && [ "$PT_LOG_LEVEL" = "DEBUG" ]) && return
|
||||
|
||||
([ "$logToJournal" -eq 1 ]) && return # TODO: replace this with function when implemented
|
||||
([ "$useJsonLogFmt" -eq 1 ]) && writeJsonLog "$@"
|
||||
([ "$useSyslogLogFmt" -eq 1 ]) && writePlainTextLog "$@"
|
||||
}
|
||||
|
||||
scriptExamples() {
|
||||
newline
|
||||
printf "Update Cloudflare DNS host A/AAAA records with current IP address.\n"
|
||||
@@ -137,30 +195,42 @@ scriptHelp() {
|
||||
textBlock "The only required parameter is '--records' which is a comma-delimited list of hostnames to update. However, there are several other options which may be useful to implement."
|
||||
textBlock "Parameters are listed below and followed by a description of their effect. If a default value exists, it will be listed on the following line in (parentheses)."
|
||||
newline
|
||||
textBlock "${magenta}--- script related parameters ---${norm}"
|
||||
textBlock "${magenta}--- script-related parameters ---${norm}"
|
||||
newline
|
||||
textBlockSwitches "-c | --cred | --creds | --credentials | -f (deprecated, backward-compatibility)"
|
||||
textBlock "Path to file containing your Cloudflare *token* credentials. Please refer to the repo README for more information on format, etc."
|
||||
textBlock "Path to the file containing your Cloudflare *token* credentials. Please refer to the repo README for more information on format, etc."
|
||||
textBlockDefaults "(${accountFile})"
|
||||
newline
|
||||
textBlockSwitches "-l | --log"
|
||||
textBlock "Path where the log file should be written."
|
||||
textBlockSwitches "--log-file"
|
||||
textBlock "Path where the log file should be written. Script will use file-based logging."
|
||||
textBlockDefaults "(${logFile})"
|
||||
newline
|
||||
textBlockSwitches "--nc | --no-color | --no-colour"
|
||||
textBlock "Switch value. Disables ANSI colours in the log. Useful if you review the logs using a reader that does not parse ANSI colour codes."
|
||||
textBlockDefaults "(disabled: print logs in colour)"
|
||||
newline
|
||||
textBlockSwitches "--log-console"
|
||||
textBlock "Switch value. Output log to console (stdout) instead of a log file. Can be combined with --nc if desired."
|
||||
textBlockDefaults "(disabled: output to log file)"
|
||||
textBlock "Switch value. Script will use console-based (stdout) logging."
|
||||
textBlockDefaults "(disabled: use file-based logging)"
|
||||
newline
|
||||
textBlockSwitches "--no-log"
|
||||
textBlock "Switch value. Do not create a log (i.e. no console, no file). You will not have *any* output from the script if you choose this option, so you will not know if updates succeeded or failed."
|
||||
textBlockDefaults "(disabled: output to log file)"
|
||||
textBlockSwitches "--log-journal"
|
||||
textBlock "Switch value. Script will use journald-based logging."
|
||||
textBlockDefaults "(disabled: use file-based logging)"
|
||||
newline
|
||||
textBlockSwitches "--log-none"
|
||||
textBlock "Switch value. Script will not log anything. You will not have *any* output from the script if you choose this option, so you will not know if updates succeed or fail."
|
||||
textBlockDefaults "(disabled: use file-based logging)"
|
||||
newline
|
||||
textBlockSwitches "--log-debug"
|
||||
textBlock "Switch value. Log 'debug' level messages. This should normally remain disabled."
|
||||
textBlockDefaults "(disabled: do not log 'debug' messages)"
|
||||
newline
|
||||
textBlockSwitches "--fmt-json"
|
||||
textBlock "Switch value. Use JSON formatted key-value pair structured logging format. Best when using a log parsing tool or log management system to read your log files. Does not apply when using '--log-journal'."
|
||||
textBlockDefaults "(enabled)"
|
||||
newline
|
||||
textBlockSwitches "--fmt-syslog"
|
||||
textBlock "Switch value. Use a modified syslog (plain-text) format for log messages. Ideal when logging to the console. Does not apply when using '--log-journal'."
|
||||
textBlockDefaults "(disabled: use structured JSON logging)"
|
||||
newline
|
||||
textBlockSwitches "-h | --help | -?"
|
||||
textBlock "Display this help screen."
|
||||
textBlock "Display this information screen."
|
||||
newline
|
||||
textBlockSwitches "--examples"
|
||||
textBlock "Show some usage examples."
|
||||
@@ -171,7 +241,7 @@ scriptHelp() {
|
||||
textBlock "Comma-delimited list of hostnames for which IP addresses should be updated in Cloudflare DNS. This parameter is REQUIRED. Note that this script will only *update* records, it will not create new ones. If you supply hostnames that are not already defined in DNS, the script will log a warning and will skip those hostnames."
|
||||
newline
|
||||
textBlockSwitches "-i | --ip | --ip-address | -a | --address"
|
||||
textBlock "New IP address for DNS host records. If you omit this, the script will attempt to auto-detect your public IP address and use that."
|
||||
textBlock "New IP address for DNS host records. If you omit this, the script will attempt to auto-detect your public IP address and use that. N.B. IP addresses are *not* parsed for correctness."
|
||||
newline
|
||||
textBlockSwitches "-4 | --ip4 | --ipv4"
|
||||
textBlock "Switch value. Update Host 'A' records (IP4) only. Note that this script can only update either A *or* AAAA records. If you need to update both, you'll have to run the script once in IP4 mode and again in IP6 mode. If you specify both this switch and the IP6 switch, the last one specified will take effect."
|
||||
@@ -186,10 +256,6 @@ scriptHelp() {
|
||||
exit 0
|
||||
}
|
||||
|
||||
stamp() {
|
||||
(date +%F" "%T)
|
||||
}
|
||||
|
||||
newline() {
|
||||
printf "\n"
|
||||
}
|
||||
@@ -206,60 +272,25 @@ textBlockSwitches() {
|
||||
printf "%s%s%s\n" "$cyan" "$1" "$norm"
|
||||
}
|
||||
|
||||
writeLog() {
|
||||
case "$1" in
|
||||
cf)
|
||||
printf "[%s] CF-ERR: %s (code: %s)\n" "$(stamp)" "$2" "$3" >>"$logFile"
|
||||
;;
|
||||
err)
|
||||
printf "%s[%s] ERR: %s%s\n" "$err" "$(stamp)" "$2" "$norm" >>"$logFile"
|
||||
;;
|
||||
error)
|
||||
printf "%s[%s] ERROR: %s (code: %s)%s\n" "$err" "$(stamp)" "$2" "$3" "$norm" >>"$logFile"
|
||||
;;
|
||||
process)
|
||||
printf "%s[%s] %s... %s" "$cyan" "$(stamp)" "$2" "$norm" >>"$logFile"
|
||||
;;
|
||||
process-done)
|
||||
printf "%s%s%s\n" "$cyan" "$2" "$norm" >>"$logFile"
|
||||
;;
|
||||
process-error)
|
||||
printf "%sERROR%s\n" "$err" "$norm" >>"$logFile"
|
||||
;;
|
||||
process-warning)
|
||||
printf "%s%s%s\n" "$warn" "$2" "$norm" >>"$logFile"
|
||||
;;
|
||||
stamped)
|
||||
printf "[%s] %s\n" "$(stamp)" "$2" >>"$logFile"
|
||||
;;
|
||||
success)
|
||||
printf "%s[%s] SUCCESS: %s%s\n" "$ok" "$(stamp)" "$2" "$norm" >>"$logFile"
|
||||
;;
|
||||
warn)
|
||||
printf "%s[%s] WARN: %s%s\n" "$warn" "$(stamp)" "$2" "$norm" >>"$logFile"
|
||||
;;
|
||||
warning)
|
||||
printf "%s[%s] WARNING: %s%s\n" "$warn" "$(stamp)" "$2" "$norm" >>"$logFile"
|
||||
;;
|
||||
*)
|
||||
printf "%s\n" "$2" >>"$logFile"
|
||||
;;
|
||||
esac
|
||||
}
|
||||
|
||||
### default variable values
|
||||
LOG_PROGRAM_NAME="CFDDNS"
|
||||
scriptPath="$(CDPATH='' \cd -- "$(dirname -- "$0")" && pwd -P)"
|
||||
scriptName="$(basename "$0")"
|
||||
logFile="$scriptPath/${scriptName%.*}.log"
|
||||
logToJournal=0
|
||||
logToConsole=0
|
||||
logToNone=0
|
||||
logDebug=0
|
||||
useJsonLogFmt=1
|
||||
useSyslogLogFmt=0
|
||||
accountFile="$scriptPath/cloudflare.credentials"
|
||||
colourizeLogFile=1
|
||||
dnsRecords=""
|
||||
dnsSeparator=","
|
||||
ipAddress=""
|
||||
ip4=1
|
||||
ip6=0
|
||||
ip4DetectionSvc="http://ipv4.icanhazip.com"
|
||||
ip6DetectionSvc="http://ipv6.icanhazip.com"
|
||||
ip4DetectionSvc="https://ipv4.icanhazip.com"
|
||||
ip6DetectionSvc="https://ipv6.icanhazip.com"
|
||||
invalidDomainCount=0
|
||||
failedHostCount=0
|
||||
|
||||
@@ -277,8 +308,8 @@ while [ $# -gt 0 ]; do
|
||||
# display sample commands
|
||||
scriptExamples
|
||||
;;
|
||||
-l | --log)
|
||||
# set log file location
|
||||
--log-file)
|
||||
# use file-based logging at the specified location
|
||||
if [ -n "$2" ]; then
|
||||
logFile="${2%/}"
|
||||
shift
|
||||
@@ -287,19 +318,35 @@ while [ $# -gt 0 ]; do
|
||||
fi
|
||||
;;
|
||||
--log-console)
|
||||
# log to the console instead of a file
|
||||
# use console-based logging
|
||||
logFile="/dev/stdout"
|
||||
logToConsole=1
|
||||
;;
|
||||
--no-log)
|
||||
--log-journal)
|
||||
# use journald-based logging
|
||||
logToJournal=1
|
||||
;;
|
||||
--log-none)
|
||||
# do not log anything
|
||||
logFile="/dev/null"
|
||||
logToNone=1
|
||||
;;
|
||||
--nc | --no-color | --no-colour)
|
||||
# do not colourize log file
|
||||
colourizeLogFile=0
|
||||
--log-debug)
|
||||
# log debugging messages
|
||||
logDebug=1
|
||||
;;
|
||||
--fmt-json)
|
||||
# use JSON log formatting
|
||||
useJsonLogFmt=1
|
||||
useSyslogLogFmt=0
|
||||
;;
|
||||
--fmt-syslog)
|
||||
# use modified syslog plain-text log formatting
|
||||
useSyslogLogFmt=1
|
||||
useJsonLogFmt=0
|
||||
;;
|
||||
-c | --cred* | -f)
|
||||
# path to Cloudflare credentials file
|
||||
# path to the Cloudflare credentials file
|
||||
if [ -n "$2" ]; then
|
||||
if [ -f "$2" ] && [ -s "$2" ]; then
|
||||
accountFile="${2%/}"
|
||||
@@ -342,6 +389,8 @@ while [ $# -gt 0 ]; do
|
||||
*)
|
||||
printf "\n%sUnknown option: %s\n" "$err" "$1"
|
||||
printf "%sUse '--help' for valid options.%s\n\n" "$cyan" "$norm"
|
||||
([ "$logToConsole" -eq 0 ]) && writeLog \
|
||||
"Unknown script parameter: '${1}'" "critical" "fail" "preexec" 1
|
||||
exit 1
|
||||
;;
|
||||
esac
|
||||
@@ -350,99 +399,94 @@ done
|
||||
|
||||
### pre-flight checks
|
||||
if ! command -v curl >/dev/null; then
|
||||
printf "\n%sThis script requires 'curl' be installed and accessible. Exiting.%s\n\n" "$err" "$norm"
|
||||
printf "\n%sThis script requires that 'curl' is installed and accessible. Exiting.%s\n\n" "$err" "$norm"
|
||||
([ "$logToConsole" -eq 0 ]) && writeLog "'curl' must be installed and accessible" "fatal" "fail" "preexec" 2
|
||||
exit 2
|
||||
fi
|
||||
if ! command -v jq >/dev/null; then
|
||||
printf "\n%sThis script requires 'jq' be installed and accessible. Exiting.%s\n\n" "$err" "$norm"
|
||||
printf "\n%sThis script requires that 'jq' is installed and accessible. Exiting.%s\n\n" "$err" "$norm"
|
||||
([ "$logToConsole" -eq 0 ]) && writeLog "'jq' must be installed and accessible" "fatal" "fail" "preexec" 2
|
||||
exit 2
|
||||
fi
|
||||
[ -z "$dnsRecords" ] && badParam errMsg "You must specify at least one DNS record to update. Exiting."
|
||||
# verify credentials file exists and is not empty (default check)
|
||||
if [ ! -f "$accountFile" ] || [ ! -s "$accountFile" ]; then
|
||||
badParam errMsg "Cannot find Cloudflare credentials file (${accountFile}). Exiting."
|
||||
if [ -z "$dnsRecords" ]; then
|
||||
badParam errMsg "You must specify at least one DNS record to update. Exiting."
|
||||
fi
|
||||
# turn off log file colourization if parameter is set
|
||||
if [ "$colourizeLogFile" -eq 0 ]; then
|
||||
bold=""
|
||||
cyan=""
|
||||
err=""
|
||||
magenta=""
|
||||
norm=""
|
||||
ok=""
|
||||
warn=""
|
||||
yellow=""
|
||||
# verify the credentials file exists and is not empty (default check)
|
||||
if [ ! -f "$accountFile" ] || [ ! -s "$accountFile" ]; then
|
||||
badParam errMsg "Cannot find the Cloudflare credentials file (${accountFile}) or it is empty. Exiting."
|
||||
fi
|
||||
if [ "$logToJournal" -eq 1 ] && ! command -v logger >/dev/null 2>&1; then
|
||||
printf "\n%sThis script requires that 'logger' is installed to write journald entries. Exiting.%s\n\n" "$err" "$norm"
|
||||
exit 2
|
||||
fi
|
||||
|
||||
### initial log entries
|
||||
{
|
||||
printf "%s[%s] -- Cloudflare DDNS update-script: starting --%s\n" "$ok" "$(stamp)" "$norm"
|
||||
printf "Parameters:\n"
|
||||
printf "script path: %s\n" "$scriptPath/$scriptName"
|
||||
printf "credentials file: %s\n" "$accountFile"
|
||||
writeLog "starting '${scriptName}'" "info" "ok" "script"
|
||||
writeLog "script path: ${scriptPath}/${scriptName}" "debug" "ok" "startup"
|
||||
writeLog "credentials file: ${accountFile}" "debug" "ok" "startup"
|
||||
|
||||
if [ "$ip4" -eq 1 ]; then
|
||||
printf "mode: IP4\n"
|
||||
elif [ "$ip6" -eq 1 ]; then
|
||||
printf "mode: IP6\n"
|
||||
fi
|
||||
if [ "$ip4" -eq 1 ]; then
|
||||
writeLog "mode: IPv4" "debug" "ok" "startup"
|
||||
elif [ "$ip6" -eq 1 ]; then
|
||||
writeLog "mode: IPv6" "debug" "ok" "startup"
|
||||
fi
|
||||
|
||||
# detect and report IP address
|
||||
if [ -z "$ipAddress" ]; then
|
||||
# detect and report IP address
|
||||
if [ -z "$ipAddress" ]; then
|
||||
# detect public ip address
|
||||
if [ "$ip4" -eq 1 ]; then
|
||||
if ! ipAddress="$(curl -s $ip4DetectionSvc)"; then
|
||||
printf "ddns ip address:%s ERROR%s\n" "$err" "$norm"
|
||||
exitError 10
|
||||
writeLog \
|
||||
"Unable to auto-detect this machine's public IP address; try again later or supply the IP address to be used" "err" "fail" "detectip" 10
|
||||
exit 10
|
||||
fi
|
||||
fi
|
||||
if [ "$ip6" -eq 1 ]; then
|
||||
if ! ipAddress="$(curl -s $ip6DetectionSvc)"; then
|
||||
printf "ddns ip address:%s ERROR%s\n" "$err" "$norm"
|
||||
exitError 10
|
||||
writeLog \
|
||||
"Unable to auto-detect this machine's public IP address; try again later or supply the IP address to be used" "err" "fail" "detectip" 10
|
||||
exit 10
|
||||
fi
|
||||
fi
|
||||
printf "ddns ip address (detected): %s\n" "$ipAddress"
|
||||
else
|
||||
printf "ddns ip address (supplied): %s\n" "$ipAddress"
|
||||
fi
|
||||
writeLog "DDNS IP address (detected): $ipAddress" "info" "ok" "startup"
|
||||
else
|
||||
writeLog "DDNS IP address (supplied): $ipAddress" "info" "ok" "startup"
|
||||
fi
|
||||
|
||||
# iterate DNS records to update
|
||||
dnsRecordsToUpdate="$(printf '%s' "${dnsRecords}" | sed "s/${dnsSeparator}*$//")$dnsSeparator"
|
||||
while [ -n "$dnsRecordsToUpdate" ] && [ "$dnsRecordsToUpdate" != "$dnsSeparator" ]; do
|
||||
# iterate DNS records to update
|
||||
dnsRecordsToUpdate="$(printf '%s' "${dnsRecords}" | sed "s/${dnsSeparator}*$//")$dnsSeparator"
|
||||
while [ -n "$dnsRecordsToUpdate" ] && [ "$dnsRecordsToUpdate" != "$dnsSeparator" ]; do
|
||||
record="${dnsRecordsToUpdate%%${dnsSeparator}*}"
|
||||
dnsRecordsToUpdate="${dnsRecordsToUpdate#*${dnsSeparator}}"
|
||||
|
||||
if [ -z "$record" ]; then continue; fi
|
||||
printf "updating record: %s\n" "$record"
|
||||
done
|
||||
|
||||
printf "(end of parameter list)\n"
|
||||
} >>"$logFile"
|
||||
if [ -z "$record" ]; then
|
||||
continue
|
||||
fi
|
||||
writeLog "DNS host record '${record}' queued for update" "info" "ok" "startup"
|
||||
done
|
||||
|
||||
### read Cloudflare credentials
|
||||
writeLog process "Reading Cloudflare credentials"
|
||||
case "$accountFile" in
|
||||
/*)
|
||||
# absolute path, use as-is
|
||||
# shellcheck source=./cloudflare.credentials
|
||||
# absolute path, use as-is
|
||||
# shellcheck source=./cloudflare.credentials
|
||||
. "$accountFile"
|
||||
;;
|
||||
*)
|
||||
# relative path, rewrite
|
||||
# shellcheck source=./cloudflare.credentials
|
||||
# relative path, rewrite
|
||||
# shellcheck source=./cloudflare.credentials
|
||||
. "./$accountFile"
|
||||
;;
|
||||
esac
|
||||
if [ -z "$cfKey" ]; then
|
||||
writeLog process-error
|
||||
exitError 21
|
||||
writeLog "Cloudflare authorized API key (cfKey) is either null or undefined; please check your Cloudflare credentials file" "err" "fail" "creds" 21
|
||||
exit 21
|
||||
fi
|
||||
if [ -z "$cfZoneId" ]; then
|
||||
writeLog process-error
|
||||
exitError 22
|
||||
writeLog "Cloudflare zone id (cfZoneId) is either null or undefined; please check your Cloudflare credentials file" "err" "fail" "creds" 22
|
||||
exit 22
|
||||
fi
|
||||
writeLog process-done "DONE"
|
||||
writeLog "Cloudflare credentials file read successfully" "debug" "ok" "creds"
|
||||
|
||||
### connect to Cloudflare and do what needs to be done!
|
||||
dnsRecordsToUpdate="$dnsRecords$dnsSeparator"
|
||||
@@ -457,70 +501,69 @@ while [ -n "$dnsRecordsToUpdate" ] && [ "$dnsRecordsToUpdate" != "$dnsSeparator"
|
||||
record="${dnsRecordsToUpdate%%${dnsSeparator}*}"
|
||||
dnsRecordsToUpdate="${dnsRecordsToUpdate#*${dnsSeparator}}"
|
||||
|
||||
if [ -z "$record" ]; then continue; fi
|
||||
writeLog process "Processing ${record}"
|
||||
|
||||
# exit if curl/network error
|
||||
if ! cfLookup="$(curl -s -X GET "https://api.cloudflare.com/client/v4/zones/${cfZoneId}/dns_records?name=${record}&type=${recordType}" \
|
||||
-H "Authorization: Bearer ${cfKey}" \
|
||||
-H "Content-Type: application/json")"; then
|
||||
writeLog process-error
|
||||
exitError 3
|
||||
if [ -z "$record" ]; then
|
||||
continue
|
||||
fi
|
||||
|
||||
# exit if API error
|
||||
# exit here since API errors on GET request probably indicates authentication error which would affect all remaining operations
|
||||
# no reason to continue processing other hosts and pile-up errors which might look like a DoS attempt
|
||||
# exit if curl/network error
|
||||
if ! cfLookup="$(
|
||||
curl -s -X GET "https://api.cloudflare.com/client/v4/zones/${cfZoneId}/dns_records?name=${record}&type=${recordType}" \
|
||||
-H "Authorization: Bearer ${cfKey}" \
|
||||
-H "Content-Type: application/json"
|
||||
)"; then
|
||||
writeLog "Unable to connect to Cloudflare servers; please try again later." "err" "fail" "cflogin" 3
|
||||
exit 3
|
||||
fi
|
||||
|
||||
# an API error on this GET request likely indicates an authentication error that would affect all remaining operations
|
||||
# no reason to continue processing other dns records and pile-up errors which might look like a DoS attempt
|
||||
cfSuccess="$(printf "%s" "$cfLookup" | jq -r '.success')"
|
||||
if [ "$cfSuccess" = "false" ]; then
|
||||
writeLog process-error
|
||||
listCFErrors "$cfLookup"
|
||||
exitError 25
|
||||
listCFErrors "$cfLookup" "cflogin"
|
||||
writeLog "Cloudflare API error; review any previously logged 'CF-ERR:' lines for details." "err" "fail" "cflogin" 25
|
||||
exit 25
|
||||
fi
|
||||
|
||||
resultCount="$(printf "%s" "$cfLookup" | jq '.result_info.count')"
|
||||
|
||||
# skip to next host if cannot find existing host record (this script *updates* only, does not create!)
|
||||
# skip to the next host if an existing host record cannot be found (this script *updates* only, does not create!)
|
||||
if [ "$resultCount" = "0" ]; then
|
||||
# warn if record of host not found
|
||||
writeLog process-warning "NOT FOUND"
|
||||
writeLog warn "Cannot find existing record to update for DNS entry: ${record}"
|
||||
writeLog "Cannot find an existing record matching '${record}' to update" "warn" "warn" "ddns"
|
||||
invalidDomainCount=$((invalidDomainCount + 1))
|
||||
continue
|
||||
fi
|
||||
|
||||
objectId=$(printf "%s" "$cfLookup" | jq -r '.result | .[] | .id')
|
||||
currentIpAddr=$(printf "%s" "$cfLookup" | jq -r '.result | .[] | .content')
|
||||
writeLog process-done "FOUND: IP = ${currentIpAddr}"
|
||||
writeLog "The current IP address for '${record}' is ${currentIpAddr}" "debug" "ok" "ddns"
|
||||
|
||||
# skip to next hostname if record already up-to-date
|
||||
# skip to next hostname if record already up to date
|
||||
if [ "$currentIpAddr" = "$ipAddress" ]; then
|
||||
writeLog stamped "IP address for ${record} is already up-to-date"
|
||||
writeLog "The IP address for '${record}' is already up to date" "info" "ok" "ddns"
|
||||
continue
|
||||
fi
|
||||
|
||||
# update record
|
||||
writeLog process "Updating IP address for ${record}"
|
||||
updateJSON="$(jq -n --arg key0 content --arg value0 "${ipAddress}" '{($key0):$value0}')"
|
||||
|
||||
# exit if curl/network error
|
||||
if ! cfResult="$(curl -s -X PATCH "https://api.cloudflare.com/client/v4/zones/${cfZoneId}/dns_records/${objectId}" \
|
||||
if ! cfResult="$(
|
||||
curl -s -X PATCH "https://api.cloudflare.com/client/v4/zones/${cfZoneId}/dns_records/${objectId}" \
|
||||
-H "Authorization: Bearer ${cfKey}" \
|
||||
-H "Content-Type: application/json" \
|
||||
--data "${updateJSON}")"; then
|
||||
writeLog process-error
|
||||
exitError 3
|
||||
--data "${updateJSON}"
|
||||
)"; then
|
||||
writeLog "Unable to connect to Cloudflare servers; please try again later." "err" "fail" "ddns" 3
|
||||
exit 3
|
||||
fi
|
||||
|
||||
# note update success or failure
|
||||
cfSuccess="$(printf "%s" "$cfResult" | jq '.success')"
|
||||
if [ "$cfSuccess" = "true" ]; then
|
||||
writeLog process-done "DONE"
|
||||
writeLog success "IP address for ${record} updated."
|
||||
writeLog "The IP address for '${record}' successfully updated" "info" "ok" "ddns"
|
||||
else
|
||||
writeLog process-error
|
||||
listCFErrors "$cfResult"
|
||||
writeLog err "Unable to update IP address for ${record}"
|
||||
listCFErrors "$cfResult" "ddns"
|
||||
writeLog "Unable to update the IP address for '${record}'" "err" "fail" "ddns"
|
||||
# do not exit with error, API error here is probably an update issue specific to this host
|
||||
# increment counter and note it after all processing finished
|
||||
failedHostCount=$((failedHostCount + 1))
|
||||
@@ -529,12 +572,14 @@ done
|
||||
|
||||
# exit
|
||||
if [ "$invalidDomainCount" -ne 0 ]; then
|
||||
writeLog warning "${invalidDomainCount} invalid host(s) supplied for updating."
|
||||
writeLog "${invalidDomainCount} invalid host(s) were supplied for updating" "warn" "warn" "ddns"
|
||||
fi
|
||||
if [ "$failedHostCount" -ne 0 ]; then
|
||||
exitError 26
|
||||
writeLog \
|
||||
"${failedHostCount} host update(s) failed; review 'CF-ERR:' lines in this log to help determine what may have gone wrong" "err" "fail" "ddns" 26
|
||||
exit 26
|
||||
else
|
||||
exitOK
|
||||
writeLog "${scriptName} completed successfully" "info" "ok" "script"
|
||||
fi
|
||||
|
||||
### exit return codes
|
||||
|
||||
+16
-8
@@ -15,17 +15,17 @@ If you need help getting logwatch installed and set-up, please [check out my blo
|
||||
|
||||
<!-- toc -->
|
||||
|
||||
- [LogFile Group file (/etc/logwatch/conf/logfiles/cfddns.conf)](#logfile-group-file-etclogwatchconflogfilescfddnsconf)
|
||||
- [LogFile Group file](#logfile-group-file)
|
||||
* [Log file location](#log-file-location)
|
||||
* [Archive location and name format](#archive-location-and-name-format)
|
||||
* [External script for timestamp processing](#external-script-for-timestamp-processing)
|
||||
- [Service definition file (/etc/logwatch/conf/services/cfddns.conf)](#service-definition-file-etclogwatchconfservicescfddnsconf)
|
||||
- [Service definition file](#service-definition-file)
|
||||
* [LogFile Group file definition](#logfile-group-file-definition)
|
||||
* [Report title](#report-title)
|
||||
* [Detail level](#detail-level)
|
||||
- [Service script (/etc/logwatch/scripts/services/cfddns)](#service-script-etclogwatchscriptsservicescfddns)
|
||||
- [Service script](#service-script)
|
||||
* [Detail levels](#detail-levels)
|
||||
- [Timestamp processing script (/etc/logwatch/scripts/shared/sqfullstampanywhere)](#timestamp-processing-script-etclogwatchscriptssharedsqfullstampanywhere)
|
||||
- [Timestamp processing script](#timestamp-processing-script)
|
||||
* [The time format specification](#the-time-format-specification)
|
||||
* [The search REGEX](#the-search-regex)
|
||||
- [Testing](#testing)
|
||||
@@ -33,7 +33,9 @@ If you need help getting logwatch installed and set-up, please [check out my blo
|
||||
|
||||
<!-- tocstop -->
|
||||
|
||||
## LogFile Group file (/etc/logwatch/conf/logfiles/cfddns.conf)
|
||||
## LogFile Group file
|
||||
|
||||
> This file is located within the repo at */etc/logwatch/conf/logfiles/cfddns.conf*
|
||||
|
||||
### Log file location
|
||||
|
||||
@@ -79,7 +81,9 @@ The script file is called with an asterisk (*\**) before the filename.
|
||||
|
||||
If you change the name of this file, you will have to change this line. Remember that whatever you type here as a name is converted to all-lowercase so your filename should be all lowercase also.
|
||||
|
||||
## Service definition file (/etc/logwatch/conf/services/cfddns.conf)
|
||||
## Service definition file
|
||||
|
||||
> This file is located within the repo at */etc/logwatch/conf/services/cfddns.conf*
|
||||
|
||||
### LogFile Group file definition
|
||||
|
||||
@@ -119,7 +123,9 @@ Simply change it to the value you want enforced. For example, here I'm setting
|
||||
Detail = 5
|
||||
```
|
||||
|
||||
## Service script (/etc/logwatch/scripts/services/cfddns)
|
||||
## Service script
|
||||
|
||||
> This file is located within the repo at */etc/logwatch/scripts/services/cfddns*
|
||||
|
||||
Logwatch calls any script with a name that **matches the service name**. You'll notice that I just named everything *cfddns* to keep things simple. You can change this to whatever you want. If you changed the service name to *"cloudflare*.conf", for example, you would have to rename this script file to "*cloudflare*" with no extension. Note: The script is a PERL file (note the
|
||||
shebang) but it can be written in any language.
|
||||
@@ -160,7 +166,9 @@ The script supports four (4) detail levels as follows:
|
||||
- **Use this detail level only when you need to see the entire log file and cannot otherwise access the log file.**
|
||||
- Depending on how your logwatch treats this log dump, you may see gibberish control codes like *\e[0m;]*. If this is the case, run the script with the `--no-colour` or `--nc` option to remove ANSI colour formatting.
|
||||
|
||||
## Timestamp processing script (/etc/logwatch/scripts/shared/sqfullstampanywhere)
|
||||
## Timestamp processing script
|
||||
|
||||
> This file is located within the repo at */etc/logwatch/scripts/shared/sqfullstampanywhere*
|
||||
|
||||
This is basically a modified version of the '*applyeurodate*' script that comes with Logwatch. It had to be modified to search within [square brackets] and to accept characters coming before the stamp (i.e. ANSI colour codes). If you change the '**stamp**' variable in the updater script to update the timestamp to your liking (which to totally fine!) then you'll probably have to update this file. There are two lines you need to modify to suit your new '**stamp**' variable.
|
||||
|
||||
|
||||
@@ -0,0 +1,161 @@
|
||||
#!/bin/sh
|
||||
|
||||
getTimeStamp() {
|
||||
(date -u +"%Y-%m-%dT%H:%M:%SZ")
|
||||
}
|
||||
|
||||
getHostname() {
|
||||
(hostname -s)
|
||||
}
|
||||
|
||||
lowercase() {
|
||||
echo "$1" | tr '[:upper:]' '[:lower:]'
|
||||
}
|
||||
|
||||
uppercase() {
|
||||
echo "$1" | tr '[:lower:]' '[:upper:]'
|
||||
}
|
||||
|
||||
standardizeLogLevels() {
|
||||
LEVEL_TO_STANDARDIZE="$(lowercase "$1")"
|
||||
case "$LEVEL_TO_STANDARDIZE" in
|
||||
"critical" | "crit" | "fatal")
|
||||
echo "CRIT"
|
||||
;;
|
||||
"error" | "err")
|
||||
echo "ERR"
|
||||
;;
|
||||
"warning" | "warn")
|
||||
echo "WARN"
|
||||
;;
|
||||
"information" | "info")
|
||||
echo "INFO"
|
||||
;;
|
||||
"debug" | "verbose")
|
||||
echo "DEBUG"
|
||||
;;
|
||||
*)
|
||||
echo "INFO"
|
||||
;;
|
||||
esac
|
||||
}
|
||||
|
||||
translateLogLevelsToJournalD() {
|
||||
LEVEL_TO_TRANSLATE="$(standardizeLogLevels "$1")"
|
||||
case "$LEVEL_TO_TRANSLATE" in
|
||||
"CRIT")
|
||||
echo 2
|
||||
;;
|
||||
"ERR")
|
||||
echo 3
|
||||
;;
|
||||
"WARN")
|
||||
echo 4
|
||||
;;
|
||||
"INFO")
|
||||
echo 6
|
||||
;;
|
||||
"DEBUG")
|
||||
echo 7
|
||||
;;
|
||||
*)
|
||||
echo 6
|
||||
esac
|
||||
}
|
||||
|
||||
# modified syslog fmt: <ISO-8601 timestamp> <hostname> <tag>[pid]: [LEVEL:$2] [STATUS:$3] <MESSAGE:$1> (<OPERATION:$4>:<CODE:$5>)
|
||||
writePlainTextLog() {
|
||||
# not enough information to generate a meaningful log message
|
||||
if [ -z "$1" ] || [ $# -lt 3 ]; then
|
||||
return
|
||||
fi
|
||||
|
||||
printf "%s %s %s[%s]: [%s] [%s] %s (%s:%s)\n" \
|
||||
"$(getTimeStamp)" "$(getHostname)" "$LOG_PROGRAM_NAME" "$$" \
|
||||
"$(standardizeLogLevels "$2")" "$(uppercase "$3")" "$1" "${4:-UNSPECIFIED}" "${5:-999}"
|
||||
}
|
||||
|
||||
# $1: message, $2: level, $3: status, [$4: operation], [$5: code]
|
||||
writeJsonLog() {
|
||||
# not enough information to generate a meaningful log message
|
||||
if [ -z "$1" ] || [ $# -lt 3 ]; then
|
||||
return
|
||||
fi
|
||||
|
||||
PROPS="$(
|
||||
jq --null-input \
|
||||
--arg timestamp "$(getTimeStamp)" \
|
||||
--arg hostname "$(getHostname)" \
|
||||
--arg pName "$LOG_PROGRAM_NAME" \
|
||||
--arg pid "$$" \
|
||||
--arg level "$(standardizeLogLevels "$2")" \
|
||||
--arg status "$(uppercase "$3")" \
|
||||
--arg message "$1" \
|
||||
--arg operation "${4:-UNSPECIFIED}" \
|
||||
--arg code "${5:-999}" \
|
||||
'{"timestamp":$timestamp, "hostname":$hostname, "programName":$pName, "pid":$pid, "level":$level, "status":$status, "message":$message, "operation":$operation, "code":$code}' \
|
||||
)"
|
||||
|
||||
echo "$PROPS" | jq "."
|
||||
return
|
||||
}
|
||||
|
||||
# $1: message, $2: level, $3: status, $4: operation, $5: code
|
||||
writeJournalDLog() {
|
||||
# not enough information to generate a meaningful log message
|
||||
if [ -z "$1" ] || [ $# -lt 3 ]; then
|
||||
return
|
||||
fi
|
||||
|
||||
J_TIMESTAMP="$(getTimeStamp)"
|
||||
J_PID="$$"
|
||||
J_PRIO="$(translateLogLevelsToJournalD "$2")"
|
||||
J_STAT="$(uppercase "$3")"
|
||||
|
||||
logger --journald <<end
|
||||
SYSLOG_TIMESTAMP=${J_TIMESTAMP}
|
||||
SYSLOG_FACILITY=3
|
||||
SYSLOG_IDENTIFIER=${LOG_PROGRAM_NAME}
|
||||
SYSLOG_PID=${J_PID}
|
||||
PRIORITY=${J_PRIO}
|
||||
STATUS=${J_STAT}
|
||||
MESSAGE=$1
|
||||
OPERATION=${4:-UNSPECIFIED}
|
||||
ERRNO=${5:-999}
|
||||
end
|
||||
|
||||
return
|
||||
}
|
||||
|
||||
LOG_PROGRAM_NAME="cfddns"
|
||||
|
||||
if [ "$1" = "text" ]; then
|
||||
writePlainTextLog # this will do nothing
|
||||
writePlainTextLog "Testing plain-text logging output" # this will also do nothing
|
||||
writePlainTextLog "Informational plain-text log message" "information" "ok" # info message
|
||||
writePlainTextLog "Plain-text message forced to info level" "whoops" "ok" # level translated to default
|
||||
writePlainTextLog "Warning! This is plain-text." "warning" "flagged" # warning level with 'flagged' status
|
||||
writePlainTextLog "Error sample! This is plain-text." "err" "error" # error level message
|
||||
writePlainTextLog "Unable to continue, critical failure. (This is plain-text)" "fatal" "exit" "startup" "2" # critical level error with operation and error code
|
||||
elif [ "$1" = "json" ]; then
|
||||
writeJsonLog # this will do nothing
|
||||
writeJsonLog "This is a test message" # this will also do nothing
|
||||
writeJsonLog "Informational JSON log message" "information" "ok" # info message
|
||||
writeJsonLog "JSON message forced to info level" "whoops" "ok" # level translated to default
|
||||
writeJsonLog "Warning! This is JSON." "warning" "flagged" # warning level with 'flagged' status
|
||||
writeJsonLog "Error sample! This is JSON." "err" "error" # error level message
|
||||
writeJsonLog "Unable to continue, critical failure. (This is JSON)" "fatal" "exit" "startup" "2" # critical level error with operation and error code
|
||||
elif [ "$1" = "journal" ]; then
|
||||
writeJournalDLog # this will do nothing
|
||||
writeJournalDLog "This is a test message" # this will also do nothing
|
||||
writeJournalDLog "Informational JOURNALD log message" "information" "ok" # info message
|
||||
writeJournalDLog "JOURNALD message forced to info level" "whoops" "ok" # level translated to default
|
||||
writeJournalDLog "Warning! This is a JOURNALD message." "warning" "flagged" # warning level with 'flagged' status
|
||||
writeJournalDLog "Error sample! This is a JOURNALD." "err" "error" # error level message
|
||||
writeJournalDLog "Unable to continue, critical failure. (This is JOURNALD message)" "fatal" "exit" "startup" "2" # critical level error with operation and error code
|
||||
else
|
||||
printf "\nPlease specify either 'text', 'json', or 'journal' after the script name. Exiting.\n\n"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
exit 0
|
||||
Reference in New Issue
Block a user