12 Commits

Author SHA1 Message Date
asif 1824d9f139 feat(logger): Framework test file 2026-07-22 17:33:46 -06:00
asif 50b4cf105f chore(ide): Update IDE settings 2026-07-22 17:33:36 -06:00
asif 1e3b545a23 chore(ide): JetBrains IDE configuration files 2026-07-19 23:37:13 -06:00
asif 380509c966 chore(git): Update git control files 2026-07-19 23:36:58 -06:00
asif 71da487aa8 style(fmt): Reformat shell script 2026-07-19 23:33:56 -06:00
asif 3be6eaee0c [preflight] Add check for logger dependency
'logger' is required to facilitate logging to the journaling system.
2026-07-19 18:52:34 -06:00
asif 5c6c8ec4ea [params] Create journal logging switch
Create boolean variable to store journal logging preference.
Set to 'false' by default. Add parameter to activate this preference.
Update help to include this new parameter.
2026-07-19 18:49:34 -06:00
asif c7297a512c [version] Update version, modified date 2026-07-19 15:44:40 -06:00
Asif Bacchus fddb406717 fix error in hyperlink 2021-05-10 03:22:22 -06:00
Asif Bacchus 4ec190af47 update readme 2021-05-10 03:18:49 -06:00
Asif Bacchus 57ce2d1ac3 fixed headings so TOC links work 2021-05-10 03:09:30 -06:00
Asif Bacchus 1ffd374a4f fix: set TERM for tput if not set
- stop warning messages in syslog from systemd invocation
2021-05-10 02:55:16 -06:00
12 changed files with 699 additions and 428 deletions
+22 -3
View File
@@ -55,6 +55,23 @@
*.bat text eol=crlf *.bat text eol=crlf
*.cmd text eol=crlf *.cmd text eol=crlf
# web frontend stack -- force LF so SRI hashes are always correct
*.html text eol=lf
*.htm text eol=lf
*.css text eol=lf
*.min.css text eol=lf
*.js text eol=lf
*.min.js text eol=lf
*.php text eol=lf
# Visual Studio projects (Rider also)
*.cs diff=csharp
*.sln merge=union
*.csproj merge=union
*.vbproj merge=union
*.fsproj merge=union
*.dbproj merge=union
# Serialisation # Serialisation
*.json text *.json text
*.toml text *.toml text
@@ -76,6 +93,8 @@
# Exclude files from exporting # Exclude files from exporting
# #
.gitattributes export-ignore .gitattributes export-ignore
.gitignore export-ignore .gitignore export-ignore
.gitkeep export-ignore .gitkeep export-ignore
.idea export-ignore
.vscode export-ignore
+34
View File
@@ -1 +1,35 @@
#
# JetBrains exclusions
#
riderModule.iml
/_ReSharper.Caches/
# User-specific stuff
.idea/**/workspace.xml
.idea/**/tasks.xml
.idea/**/usage.statistics.xml
.idea/**/dictionaries
.idea/**/shelf
# Generated files
.idea/**/contentModel.xml
.idea/**/GitCommitMessageStorage.xml
# Sensitive or high-churn files
.idea/**/dataSources/
.idea/**/dataSources.ids
.idea/**/dataSources.local.xml
.idea/**/sqlDataSources.xml
.idea/**/dynamic.xml
.idea/**/uiDesigner.xml
.idea/**/dbnavigator.xml
# modules
.idea_modules/
# Editor-based Rest Client
.idea/httpRequests
# project-specific exclusions
*.log *.log
+6
View File
@@ -0,0 +1,6 @@
<?xml version="1.0" encoding="UTF-8"?>
<project version="4">
<component name="DeveloperToolsToolWindowSettingsV1" lastSelectedContentNodeId="base64-encoder-decoder" pluginVersion="9.0.0">
<developerToolsConfigurations />
</component>
</project>
+15
View File
@@ -0,0 +1,15 @@
<?xml version="1.0" encoding="UTF-8"?>
<project version="4">
<component name="GitToolBoxProjectSettings">
<option name="commitMessageIssueKeyValidationOverride">
<BoolValueOverride>
<option name="enabled" value="true" />
</BoolValueOverride>
</option>
<option name="commitMessageValidationEnabledOverride">
<BoolValueOverride>
<option name="enabled" value="true" />
</BoolValueOverride>
</option>
</component>
</project>
+8
View File
@@ -0,0 +1,8 @@
<?xml version="1.0" encoding="UTF-8"?>
<project version="4">
<component name="UserContentModel">
<attachedFolders />
<explicitIncludes />
<explicitExcludes />
</component>
</project>
+8
View File
@@ -0,0 +1,8 @@
<?xml version="1.0" encoding="UTF-8"?>
<project version="4">
<component name="com.itcodebox.notebooks.projectservice.ProjectUIState">
<option name="selectedNotebookId" value="1" />
<option name="selectedChapterId" value="1" />
<option name="selectedNoteId" value="1" />
</component>
</project>
+8
View File
@@ -0,0 +1,8 @@
<?xml version="1.0" encoding="UTF-8"?>
<project version="4">
<component name="RiderProjectSettingsUpdater">
<option name="singleClickDiffPreview" value="1" />
<option name="unhandledExceptionsIgnoreList" value="1" />
<option name="vcsConfiguration" value="3" />
</component>
</project>
Generated
+6
View File
@@ -0,0 +1,6 @@
<?xml version="1.0" encoding="UTF-8"?>
<project version="4">
<component name="VcsDirectoryMappings">
<mapping directory="" vcs="Git" />
</component>
</project>
+25 -16
View File
@@ -7,7 +7,7 @@ Update your *existing* Cloudflare DNS records with your current (dynamic) IP add
<!-- toc --> <!-- toc -->
- [Prerequisites](#prerequisites) - [Prerequisites](#prerequisites)
- [cfddns&#46;sh](#cfddns%2346sh) - [cfddns script](#cfddns-script)
* [Installation](#installation) * [Installation](#installation)
* [Usage](#usage) * [Usage](#usage)
+ [Parameters](#parameters) + [Parameters](#parameters)
@@ -15,10 +15,10 @@ Update your *existing* Cloudflare DNS records with your current (dynamic) IP add
* [File structure](#file-structure) * [File structure](#file-structure)
* [Bearer token](#bearer-token) * [Bearer token](#bearer-token)
* [Zone ID](#zone-id) * [Zone ID](#zone-id)
- [cfddns.service](#cfddnsservice) - [cfddns systemd service unit](#cfddns-systemd-service-unit)
* [IP4 and/or IP6](#ip4-andor-ip6) * [IP4 or IP6](#ip4-or-ip6)
+ [Examples](#examples) + [Examples](#examples)
- [cfddns.timer](#cfddnstimer) - [cfddns systemd timer unit](#cfddns-systemd-timer-unit)
* [Activation](#activation) * [Activation](#activation)
- [Logging](#logging) - [Logging](#logging)
* [Using Logwatch to monitor this script](#using-logwatch-to-monitor-this-script) * [Using Logwatch to monitor this script](#using-logwatch-to-monitor-this-script)
@@ -37,7 +37,7 @@ apt install -y curl jq
While the script does *not* require root privileges, you will need sudo/root access to install the *systemd* service and timer. While the script does *not* require root privileges, you will need sudo/root access to install the *systemd* service and timer.
## cfddns&#46;sh ## cfddns script
### Installation ### Installation
@@ -56,7 +56,7 @@ I recommend putting this script in your */usr/local/bin* directory or somewhere
sudo chmod +x /usr/local/bin/cfddns.sh sudo chmod +x /usr/local/bin/cfddns.sh
``` ```
> Note: You can rename *cfddns.sh* to anything you want, the script will auto-update itself. However, you **must** manually update the systemd service file (*cfddns.service*) `ExecStart` line as [explained below](#cfddns.service). > Note: You can rename *cfddns.sh* to anything you want, the script will auto-update itself. However, you **must** manually update the systemd service file (*cfddns.service*) `ExecStart` line as [explained below](#cfddns-script).
### Usage ### Usage
@@ -111,6 +111,13 @@ cfZoneId=83d564234134513245311b23412331dd
You can save the file as anything you like and anywhere youd like as long as you inform the script of its location using the `--credentials` parameter. By default, the script will look for a file named *cloudflare.credentials* in the same path as the script. You can save the file as anything you like and anywhere youd like as long as you inform the script of its location using the `--credentials` parameter. By default, the script will look for a file named *cloudflare.credentials* in the same path as the script.
Please remember that this file basically contains a password! As a result, it should be protected and access limited to the root account:
```bash
chown root:root /path/to/cloudflare.credentials
chmod 600 /path/to/cloudflare.credentials
```
### Bearer token ### Bearer token
I chose to use an API bearer token instead of a username/password or Global API token for security reasons. Your username/password and Global API token provide unfettered access to your account so if anyone gets hold of them, they can do anything to your account. An API bearer token, by contrast, can only do what you authorize it to do and you can revoke it at any time. Therefore, I suggest making a bearer token that is based on the “Edit zone DNS” template and restricted to the specific domain/zone you wish to update. Cloudflare provides an [excellent article](https://support.cloudflare.com/hc/en-us/articles/200167836-Managing-API-Tokens-and-Keys) on how to generate this token. I chose to use an API bearer token instead of a username/password or Global API token for security reasons. Your username/password and Global API token provide unfettered access to your account so if anyone gets hold of them, they can do anything to your account. An API bearer token, by contrast, can only do what you authorize it to do and you can revoke it at any time. Therefore, I suggest making a bearer token that is based on the “Edit zone DNS” template and restricted to the specific domain/zone you wish to update. Cloudflare provides an [excellent article](https://support.cloudflare.com/hc/en-us/articles/200167836-Managing-API-Tokens-and-Keys) on how to generate this token.
@@ -124,7 +131,7 @@ This is required by the Cloudflare API so it knows which zone you are editing an
To get your Zone ID, log into your Cloudflare account and open the domain in question. On the overview page, scroll down a bit and look to the right. You will see your Zone ID listed there. Copy that string into your configuration file. To get your Zone ID, log into your Cloudflare account and open the domain in question. On the overview page, scroll down a bit and look to the right. You will see your Zone ID listed there. Copy that string into your configuration file.
## cfddns.service ## cfddns systemd service unit
This file **must** be copied to your */etc/systemd/system* directory (or equivalent directory if you're not running Debian/Ubuntu). If you change the name of the cfddns&#46;sh file, you must update the filename in the `ExecStart` line as shown below: This file **must** be copied to your */etc/systemd/system* directory (or equivalent directory if you're not running Debian/Ubuntu). If you change the name of the cfddns&#46;sh file, you must update the filename in the `ExecStart` line as shown below:
@@ -136,13 +143,7 @@ ExecStart=/full/path/to/your/renamed.file -parameter1 -parameter2 -parameter...
... ...
```` ````
Dont forget to reload systemd after copying this file so it is recognized by the system! On most systems you can do this by running the following as root or via sudo: ### IP4 or IP6
```bash
systemctl daemon-reload
```
### IP4 and/or IP6
The cfddns.service file includes two *ExecStart* lines, one without a specified IP-protocol parameter (default IP4) and the other with the -6 (IP6) parameter. The service will run the cfddns&#46;sh script in default (IP4) mode with specified parameters first and then will run the script again in IP6 mode with specified parameters. The cfddns.service file includes two *ExecStart* lines, one without a specified IP-protocol parameter (default IP4) and the other with the -6 (IP6) parameter. The service will run the cfddns&#46;sh script in default (IP4) mode with specified parameters first and then will run the script again in IP6 mode with specified parameters.
@@ -183,9 +184,9 @@ The cfddns.service file includes two *ExecStart* lines, one without a specified
... ...
``` ```
## cfddns.timer ## cfddns systemd timer unit
This is the timer file that tells your system how often to call the *cfddns.service* file which runs the *cfddns&#46;sh* script. By default, the timer is set for 5 minutes after the system boots up (to allow for other processes to initialize even on slower systems like a RasPi) and is then run every 15 minutes thereafter. Remember when setting your timer that Cloudflare limits API calls to 1200 every 5 minutes. Just like the service file unit, this file **must** be copied to your */etc/systemd/system* directory (or equivalent directory if you're not running Debian/Ubuntu). This timer file unit tells your system how often to call the *cfddns.service* file which runs the *cfddns&#46;sh* script. By default, the timer is set for 5 minutes after the system boots up (to allow for other processes to initialize even on slower systems like a RasPi) and is then run every 15 minutes thereafter. Remember when setting your timer that Cloudflare limits API calls to 1200 every 5 minutes.
You can change the timer by modifying the relevant section of the *cfddns.timer* file: You can change the timer by modifying the relevant section of the *cfddns.timer* file:
@@ -198,6 +199,12 @@ OnUnitActiveSec=15min
*OnBootSec* is how long to wait after the system boots up before executing the *cfddns.service*. *OnUnitActiveSec* will then wait the specified time from that first (after boot) call or after the timer is explicitly started before calling *cfddns.service* again. I recommend setting OnUnitActiveSec to a low value (like 2 minutes) for testing then setting it to a more reasonable time (like 15 *OnBootSec* is how long to wait after the system boots up before executing the *cfddns.service*. *OnUnitActiveSec* will then wait the specified time from that first (after boot) call or after the timer is explicitly started before calling *cfddns.service* again. I recommend setting OnUnitActiveSec to a low value (like 2 minutes) for testing then setting it to a more reasonable time (like 15
minutes) after everything is working. minutes) after everything is working.
After youve copied both the systemd unit and this timer unit, dont forget to reload the systemd daemon so they are recognized by the system! On most systems you can do this by running the following as root or via sudo:
```bash
systemctl daemon-reload
```
### Activation ### Activation
You can start the timer system immediately via *systemctl* You can start the timer system immediately via *systemctl*
@@ -220,6 +227,8 @@ systemctl status cfddns.timer
It is NOT necessary to enable/start the *cfddns.service*, only the timer needs to be active. It is NOT necessary to enable/start the *cfddns.service*, only the timer needs to be active.
Also remember that if you make changes to settings like `OnUnitActiveSec` while testing or after testing is complete you *must* reload the systemd daemon! It will restart the appropriate units for you and your new settings will take effect immediately.
## Logging ## Logging
The script logs every major action it takes and provides details on any errors it encounters in the log file (see the [parameters section](#parameters) for details about setting log location and name). If errors are encountered, they are colour coded red and an explanation of the error code is provided. The script logs every major action it takes and provides details on any errors it encounters in the log file (see the [parameters section](#parameters) for details about setting log location and name). If errors are encountered, they are colour coded red and an explanation of the error code is provided.
+425 -401
View File
@@ -3,254 +3,261 @@
# #
# update Cloudflare DNS records with current (dynamic) IP address # update Cloudflare DNS records with current (dynamic) IP address
# Script by Asif Bacchus <asif@bacchus.cloud> # Script by Asif Bacchus <asif@bacchus.cloud>
# Last modified: May 7, 2021 # Last modified: July 19, 2026
# Version 3.0
# #
### text formatting presets using tput ### text formatting presets using tput
if command -v tput >/dev/null; then if command -v tput >/dev/null; then
bold=$(tput bold) [ -z "$TERM" ] && export TERM=xterm
cyan=$(tput setaf 6) bold=$(tput bold)
err=$(tput bold)$(tput setaf 1) cyan=$(tput setaf 6)
magenta=$(tput setaf 5) err=$(tput bold)$(tput setaf 1)
norm=$(tput sgr0) magenta=$(tput setaf 5)
ok=$(tput setaf 2) norm=$(tput sgr0)
warn=$(tput bold)$(tput setaf 3) ok=$(tput setaf 2)
yellow=$(tput setaf 3) warn=$(tput bold)$(tput setaf 3)
width=$(tput cols) yellow=$(tput setaf 3)
width=$(tput cols)
else else
bold="" bold=""
cyan="" cyan=""
err="" err=""
magenta="" magenta=""
norm="" norm=""
ok="" ok=""
warn="" warn=""
yellow="" yellow=""
width=80 width=80
fi fi
### functions ### functions
badParam() { badParam() {
if [ "$1" = "null" ]; then if [ "$1" = "null" ]; then
printf "\n%sERROR: '%s' cannot have a NULL (empty) value.\n" "$err" "$2" printf "\n%sERROR: '%s' cannot have a NULL (empty) value.\n" "$err" "$2"
printf "%sPlease use '--help' for assistance.%s\n\n" "$cyan" "$norm" printf "%sPlease use '--help' for assistance.%s\n\n" "$cyan" "$norm"
exit 1 exit 1
elif [ "$1" = "dne" ]; then elif [ "$1" = "dne" ]; then
printf "\n%sERROR: '%s %s'\n" "$err" "$2" "$3" printf "\n%sERROR: '%s %s'\n" "$err" "$2" "$3"
printf "file or directory does not exist or is empty.%s\n\n" "$norm" printf "file or directory does not exist or is empty.%s\n\n" "$norm"
exit 1 exit 1
elif [ "$1" = "errMsg" ]; then elif [ "$1" = "errMsg" ]; then
printf "\n%sERROR: %s%s\n\n" "$err" "$2" "$norm" printf "\n%sERROR: %s%s\n\n" "$err" "$2" "$norm"
exit 1 exit 1
fi fi
} }
exitError() { exitError() {
case "$1" in case "$1" in
3) 3)
errMsg="Unable to connect to Cloudflare servers. This is probably a temporary networking issue. Please try again later." errMsg="Unable to connect to Cloudflare servers. This is probably a temporary networking issue. Please try again later."
;; ;;
10) 10)
errMsg="Unable to auto-detect IP address. Try again later or supply the IP address to be used." errMsg="Unable to auto-detect IP address. Try again later or supply the IP address to be used."
;; ;;
20) 20)
errMsg="Cloudflare authorized email address (cfEmail) is either null or undefined. Please check your Cloudflare credentials file." errMsg="Cloudflare authorized email address (cfEmail) is either null or undefined. Please check your Cloudflare credentials file."
;; ;;
21) 21)
errMsg="Cloudflare authorized API key (cfKey) is either null or undefined. Please check your Cloudflare credentials file." errMsg="Cloudflare authorized API key (cfKey) is either null or undefined. Please check your Cloudflare credentials file."
;; ;;
22) 22)
errMsg="Cloudflare zone id (cfZoneId) is either null or undefined. Please check your Cloudflare credentials file." errMsg="Cloudflare zone id (cfZoneId) is either null or undefined. Please check your Cloudflare credentials file."
;; ;;
25) 25)
errMsg="Cloudflare API error. Please review any 'CF-ERR:' lines in this log for details." errMsg="Cloudflare API error. Please review any 'CF-ERR:' lines in this log for details."
;; ;;
26) 26)
errMsg="${failedHostCount} host update(s) failed. Any 'CF-ERR:' lines noted in this log may help determine what went wrong." errMsg="${failedHostCount} host update(s) failed. Any 'CF-ERR:' lines noted in this log may help determine what went wrong."
;; ;;
*) *)
writeLog error "An unspecified error occurred. (code: 99)" writeLog error "An unspecified error occurred. (code: 99)"
printf "%s[%s] -- Cloudflare DDNS update-script: completed with error(s) --%s\n" "$err" "$(stamp)" "$norm" >>"$logFile"
exit 99
;;
esac
writeLog error "$errMsg" "$1"
printf "%s[%s] -- Cloudflare DDNS update-script: completed with error(s) --%s\n" "$err" "$(stamp)" "$norm" >>"$logFile" printf "%s[%s] -- Cloudflare DDNS update-script: completed with error(s) --%s\n" "$err" "$(stamp)" "$norm" >>"$logFile"
exit "$1" exit 99
;;
esac
writeLog error "$errMsg" "$1"
printf "%s[%s] -- Cloudflare DDNS update-script: completed with error(s) --%s\n" "$err" "$(stamp)" "$norm" >>"$logFile"
exit "$1"
} }
exitOK() { exitOK() {
printf "%s[%s] -- Cloudflare DDNS update-script: completed successfully --%s\n" "$ok" "$(stamp)" "$norm" >>"$logFile" printf "%s[%s] -- Cloudflare DDNS update-script: completed successfully --%s\n" "$ok" "$(stamp)" "$norm" >>"$logFile"
exit 0 exit 0
} }
listCFErrors() { listCFErrors() {
# extract error codes and messages in separate variables, replace newlines with underscores # extract error codes and messages in separate variables, replace newlines with underscores
codes="$(printf "%s" "$1" | jq -r '.errors | .[] | .code' | tr '\n' '_')" codes="$(printf "%s" "$1" | jq -r '.errors | .[] | .code' | tr '\n' '_')"
messages="$(printf "%s" "$1" | jq -r '.errors | .[] | .message' | tr '\n' '_')" messages="$(printf "%s" "$1" | jq -r '.errors | .[] | .message' | tr '\n' '_')"
# iterate codes and messages and assemble into coherent messages in log # iterate codes and messages and assemble into coherent messages in log
while [ -n "$codes" ] && [ -n "$messages" ]; do while [ -n "$codes" ] && [ -n "$messages" ]; do
# get first code and message in respective sets # get first code and message in respective sets
code="${codes%%_*}" code="${codes%%_*}"
message="${messages%%_*}" message="${messages%%_*}"
# update codes and messages sets by removing first item in each set # update codes and messages sets by removing first item in each set
codes="${codes#*_}" codes="${codes#*_}"
messages="${messages#*_}" messages="${messages#*_}"
# output to log # output to log
writeLog cf "$message" "$code" writeLog cf "$message" "$code"
done done
} }
scriptExamples() { scriptExamples() {
newline newline
printf "Update Cloudflare DNS host A/AAAA records with current IP address.\n" printf "Update Cloudflare DNS host A/AAAA records with current IP address.\n"
printf "%sUsage: %s --records host.domain.tld[,host2.domain.tld,...] [parameters]%s\n\n" "$bold" "$scriptName" "$norm" printf "%sUsage: %s --records host.domain.tld[,host2.domain.tld,...] [parameters]%s\n\n" "$bold" "$scriptName" "$norm"
textBlock "${magenta}--- usage examples ---${norm}" textBlock "${magenta}--- usage examples ---${norm}"
newline newline
textBlockSwitches "${scriptName} -r myserver.mydomain.net" textBlockSwitches "${scriptName} -r myserver.mydomain.net"
textBlock "Update Cloudflare DNS records for myserver.mydomain.net with the auto-detected public IP4 address. Credentials will be expected in the default location and the log will be written in the default location also." textBlock "Update Cloudflare DNS records for myserver.mydomain.net with the auto-detected public IP4 address. Credentials will be expected in the default location and the log will be written in the default location also."
newline newline
textBlockSwitches "${scriptName} -r myserver.mydomain.net -6" textBlockSwitches "${scriptName} -r myserver.mydomain.net -6"
textBlock "Same as above, but update AAAA host records with the auto-detected public IP6 address." textBlock "Same as above, but update AAAA host records with the auto-detected public IP6 address."
newline newline
textBlockSwitches "${scriptName} -r myserver.mydomain.net,myserver2.mydomain.net -l /var/log/cfddns.log --nc" textBlockSwitches "${scriptName} -r myserver.mydomain.net,myserver2.mydomain.net -l /var/log/cfddns.log --nc"
textBlock "Update DNS entries for both listed hosts using auto-detected IP4 address. Write a non-coloured log to '/var/log/cfddns.log'." textBlock "Update DNS entries for both listed hosts using auto-detected IP4 address. Write a non-coloured log to '/var/log/cfddns.log'."
newline newline
textBlockSwitches "${scriptName} -r myserver.mydomain.net,myserver2.mydomain.net -l /var/log/cfddns.log --ip6 --ip fd21:7a62:2737:9c3a::a151" textBlockSwitches "${scriptName} -r myserver.mydomain.net,myserver2.mydomain.net -l /var/log/cfddns.log --ip6 --ip fd21:7a62:2737:9c3a::a151"
textBlock "Update DNS AAAA entries for listed hosts using the *specified* IP address. Write a colourful log to the location specified." textBlock "Update DNS AAAA entries for listed hosts using the *specified* IP address. Write a colourful log to the location specified."
newline newline
textBlockSwitches "${scriptName} -r myserver.mydomain.net -c /root/cloudflare.creds -l /var/log/cfddns.log --ip 1.2.3.4" textBlockSwitches "${scriptName} -r myserver.mydomain.net -c /root/cloudflare.creds -l /var/log/cfddns.log --ip 1.2.3.4"
textBlock "Update DNS A entry for listed hostname with the provided IP address. Read cloudflare credentials file from specified location, save log in specified location." textBlock "Update DNS A entry for listed hostname with the provided IP address. Read cloudflare credentials file from specified location, save log in specified location."
newline newline
textBlockSwitches "${scriptName} -r myserver.mydomain.net -c /root/cloudflare.creds -l /var/log/cfddns.log -6 -i fd21:7a62:2737:9c3a::a151" textBlockSwitches "${scriptName} -r myserver.mydomain.net -c /root/cloudflare.creds -l /var/log/cfddns.log -6 -i fd21:7a62:2737:9c3a::a151"
textBlock "Exact same as above, but change the AAAA record. This is how you run the script once for IP4 and again for IP6." textBlock "Exact same as above, but change the AAAA record. This is how you run the script once for IP4 and again for IP6."
exit 0 exit 0
} }
scriptHelp() { scriptHelp() {
newline newline
printf "Update Cloudflare DNS host A/AAAA records with current IP address.\n" printf "Update Cloudflare DNS host A/AAAA records with current IP address.\n"
printf "%sUsage: %s --records host.domain.tld[,host2.domain.tld,...] [parameters]%s\n\n" "$bold" "$scriptName" "$norm" printf "%sUsage: %s --records host.domain.tld[,host2.domain.tld,...] [parameters]%s\n\n" "$bold" "$scriptName" "$norm"
textBlock "The only required parameter is '--records' which is a comma-delimited list of hostnames to update. However, there are several other options which may be useful to implement." textBlock "The only required parameter is '--records' which is a comma-delimited list of hostnames to update. However, there are several other options which may be useful to implement."
textBlock "Parameters are listed below and followed by a description of their effect. If a default value exists, it will be listed on the following line in (parentheses)." textBlock "Parameters are listed below and followed by a description of their effect. If a default value exists, it will be listed on the following line in (parentheses)."
newline newline
textBlock "${magenta}--- script related parameters ---${norm}" textBlock "${magenta}--- script related parameters ---${norm}"
newline newline
textBlockSwitches "-c | --cred | --creds | --credentials | -f (deprecated, backward-compatibility)" textBlockSwitches "-c | --cred | --creds | --credentials | -f (deprecated, backward-compatibility)"
textBlock "Path to file containing your Cloudflare *token* credentials. Please refer to the repo README for more information on format, etc." textBlock "Path to file containing your Cloudflare *token* credentials. Please refer to the repo README for more information on format, etc."
textBlockDefaults "(${accountFile})" textBlockDefaults "(${accountFile})"
newline newline
textBlockSwitches "-l | --log" textBlockSwitches "-l | --log"
textBlock "Path where the log file should be written." textBlock "Path where the log file should be written."
textBlockDefaults "(${logFile})" textBlockDefaults "(${logFile})"
newline newline
textBlockSwitches "--nc | --no-color | --no-colour" textBlockSwitches "--nc | --no-color | --no-colour"
textBlock "Switch value. Disables ANSI colours in the log. Useful if you review the logs using a reader that does not parse ANSI colour codes." textBlock "Switch value. Disables ANSI colours in the log. Useful if you review the logs using a reader that does not parse ANSI colour codes."
textBlockDefaults "(disabled: print logs in colour)" textBlockDefaults "(disabled: print logs in colour)"
newline newline
textBlockSwitches "--log-console" textBlockSwitches "--log-console"
textBlock "Switch value. Output log to console (stdout) instead of a log file. Can be combined with --nc if desired." textBlock "Switch value. Output log to console (stdout) instead of a log file. Can be combined with --nc if desired."
textBlockDefaults "(disabled: output to log file)" textBlockDefaults "(disabled: output to log file)"
newline newline
textBlockSwitches "--no-log" textBlockSwitches "--log-journal"
textBlock "Switch value. Do not create a log (i.e. no console, no file). You will not have *any* output from the script if you choose this option, so you will not know if updates succeeded or failed." textBlock "Switch value. Output a structured log entry to your journaling system instead of a log file. Implies --nc."
textBlockDefaults "(disabled: output to log file)" textBlockDefaults "(disabled: output to log file)"
newline newline
textBlockSwitches "-h | --help | -?" textBlockSwitches "--no-log"
textBlock "Display this help screen." textBlock "Switch value. Do not create a log (i.e. no console, no file). You will not have *any* output from the script if you choose this option, so you will not know if updates succeeded or failed."
newline textBlockDefaults "(disabled: output to log file)"
textBlockSwitches "--examples" newline
textBlock "Show some usage examples." textBlockSwitches "-h | --help | -?"
newline textBlock "Display this help screen."
textBlock "${magenta}--- DNS related parameters ---${norm}" newline
newline textBlockSwitches "--examples"
textBlockSwitches "-r | --record | --records" textBlock "Show some usage examples."
textBlock "Comma-delimited list of hostnames for which IP addresses should be updated in Cloudflare DNS. This parameter is REQUIRED. Note that this script will only *update* records, it will not create new ones. If you supply hostnames that are not already defined in DNS, the script will log a warning and will skip those hostnames." newline
newline textBlock "${magenta}--- DNS related parameters ---${norm}"
textBlockSwitches "-i | --ip | --ip-address | -a | --address" newline
textBlock "New IP address for DNS host records. If you omit this, the script will attempt to auto-detect your public IP address and use that." textBlockSwitches "-r | --record | --records"
newline textBlock "Comma-delimited list of hostnames for which IP addresses should be updated in Cloudflare DNS. This parameter is REQUIRED. Note that this script will only *update* records, it will not create new ones. If you supply hostnames that are not already defined in DNS, the script will log a warning and will skip those hostnames."
textBlockSwitches "-4 | --ip4 | --ipv4" newline
textBlock "Switch value. Update Host 'A' records (IP4) only. Note that this script can only update either A *or* AAAA records. If you need to update both, you'll have to run the script once in IP4 mode and again in IP6 mode. If you specify both this switch and the IP6 switch, the last one specified will take effect." textBlockSwitches "-i | --ip | --ip-address | -a | --address"
textBlockDefaults "(enabled: update A records)" textBlock "New IP address for DNS host records. If you omit this, the script will attempt to auto-detect your public IP address and use that."
newline newline
textBlockSwitches "-6 | --ip6 | --ipv6" textBlockSwitches "-4 | --ip4 | --ipv4"
textBlock "Switch value. Update Host 'AAAA' records (IP6) only. Note that this script can only update either A *or* AAAA records. If you need to update both, you'll have to run the script once in IP4 mode and again in IP6 mode. If you specify both this switch and the IP4 switch, the last one specified will take effect." textBlock "Switch value. Update Host 'A' records (IP4) only. Note that this script can only update either A *or* AAAA records. If you need to update both, you'll have to run the script once in IP4 mode and again in IP6 mode. If you specify both this switch and the IP6 switch, the last one specified will take effect."
textBlockDefaults "(disabled: update A records)" textBlockDefaults "(enabled: update A records)"
newline newline
textBlock "Please refer to the repo README for more detailed information regarding this script and how to automate and monitor it." textBlockSwitches "-6 | --ip6 | --ipv6"
newline textBlock "Switch value. Update Host 'AAAA' records (IP6) only. Note that this script can only update either A *or* AAAA records. If you need to update both, you'll have to run the script once in IP4 mode and again in IP6 mode. If you specify both this switch and the IP4 switch, the last one specified will take effect."
exit 0 textBlockDefaults "(disabled: update A records)"
newline
textBlock "Please refer to the repo README for more detailed information regarding this script and how to automate and monitor it."
newline
exit 0
} }
stamp() { stamp() {
(date +%F" "%T) (date +%F" "%T)
} }
newline() { newline() {
printf "\n" printf "\n"
} }
textBlock() { textBlock() {
printf "%s\n" "$1" | fold -w "$width" -s printf "%s\n" "$1" | fold -w "$width" -s
} }
textBlockDefaults() { textBlockDefaults() {
printf "%s%s%s\n" "$yellow" "$1" "$norm" printf "%s%s%s\n" "$yellow" "$1" "$norm"
} }
textBlockSwitches() { textBlockSwitches() {
printf "%s%s%s\n" "$cyan" "$1" "$norm" printf "%s%s%s\n" "$cyan" "$1" "$norm"
} }
writeLog() { writeLog() {
case "$1" in case "$1" in
cf) cf)
printf "[%s] CF-ERR: %s (code: %s)\n" "$(stamp)" "$2" "$3" >>"$logFile" printf "[%s] CF-ERR: %s (code: %s)\n" "$(stamp)" "$2" "$3" >>"$logFile"
;; ;;
err) err)
printf "%s[%s] ERR: %s%s\n" "$err" "$(stamp)" "$2" "$norm" >>"$logFile" printf "%s[%s] ERR: %s%s\n" "$err" "$(stamp)" "$2" "$norm" >>"$logFile"
;; ;;
error) error)
printf "%s[%s] ERROR: %s (code: %s)%s\n" "$err" "$(stamp)" "$2" "$3" "$norm" >>"$logFile" printf "%s[%s] ERROR: %s (code: %s)%s\n" "$err" "$(stamp)" "$2" "$3" "$norm" >>"$logFile"
;; ;;
process) process)
printf "%s[%s] %s... %s" "$cyan" "$(stamp)" "$2" "$norm" >>"$logFile" printf "%s[%s] %s... %s" "$cyan" "$(stamp)" "$2" "$norm" >>"$logFile"
;; ;;
process-done) process-done)
printf "%s%s%s\n" "$cyan" "$2" "$norm" >>"$logFile" printf "%s%s%s\n" "$cyan" "$2" "$norm" >>"$logFile"
;; ;;
process-error) process-error)
printf "%sERROR%s\n" "$err" "$norm" >>"$logFile" printf "%sERROR%s\n" "$err" "$norm" >>"$logFile"
;; ;;
process-warning) process-warning)
printf "%s%s%s\n" "$warn" "$2" "$norm" >>"$logFile" printf "%s%s%s\n" "$warn" "$2" "$norm" >>"$logFile"
;; ;;
stamped) stamped)
printf "[%s] %s\n" "$(stamp)" "$2" >>"$logFile" printf "[%s] %s\n" "$(stamp)" "$2" >>"$logFile"
;; ;;
success) success)
printf "%s[%s] SUCCESS: %s%s\n" "$ok" "$(stamp)" "$2" "$norm" >>"$logFile" printf "%s[%s] SUCCESS: %s%s\n" "$ok" "$(stamp)" "$2" "$norm" >>"$logFile"
;; ;;
warn) warn)
printf "%s[%s] WARN: %s%s\n" "$warn" "$(stamp)" "$2" "$norm" >>"$logFile" printf "%s[%s] WARN: %s%s\n" "$warn" "$(stamp)" "$2" "$norm" >>"$logFile"
;; ;;
warning) warning)
printf "%s[%s] WARNING: %s%s\n" "$warn" "$(stamp)" "$2" "$norm" >>"$logFile" printf "%s[%s] WARNING: %s%s\n" "$warn" "$(stamp)" "$2" "$norm" >>"$logFile"
;; ;;
*) *)
printf "%s\n" "$2" >>"$logFile" printf "%s\n" "$2" >>"$logFile"
;; ;;
esac esac
} }
### default variable values ### default variable values
scriptPath="$(CDPATH='' \cd -- "$(dirname -- "$0")" && pwd -P)" scriptPath="$(CDPATH='' \cd -- "$(dirname -- "$0")" && pwd -P)"
scriptName="$(basename "$0")" scriptName="$(basename "$0")"
logFile="$scriptPath/${scriptName%.*}.log" logFile="$scriptPath/${scriptName%.*}.log"
logToJournal=0
accountFile="$scriptPath/cloudflare.credentials" accountFile="$scriptPath/cloudflare.credentials"
colourizeLogFile=1 colourizeLogFile=1
dnsRecords="" dnsRecords=""
@@ -265,276 +272,293 @@ failedHostCount=0
### process startup parameters ### process startup parameters
if [ -z "$1" ]; then if [ -z "$1" ]; then
scriptHelp scriptHelp
fi fi
while [ $# -gt 0 ]; do while [ $# -gt 0 ]; do
case "$1" in case "$1" in
-h | -\? | --help) -h | -\? | --help)
# display help # display help
scriptHelp scriptHelp
;; ;;
--examples) --examples)
# display sample commands # display sample commands
scriptExamples scriptExamples
;; ;;
-l | --log) -l | --log)
# set log file location # set log file location
if [ -n "$2" ]; then if [ -n "$2" ]; then
logFile="${2%/}" logFile="${2%/}"
shift shift
else else
badParam null "$@" badParam null "$@"
fi fi
;; ;;
--log-console) --log-console)
# log to the console instead of a file # log to the console instead of a file
logFile="/dev/stdout" logFile="/dev/stdout"
;; ;;
--no-log) --log-journal)
# do not log anything # log to the journal system instead of a file
logFile="/dev/null" logToJournal=1
;; ;;
--nc | --no-color | --no-colour) --no-log)
# do not colourize log file # do not log anything
colourizeLogFile=0 logFile="/dev/null"
;; ;;
-c | --cred* | -f) --nc | --no-color | --no-colour)
# path to Cloudflare credentials file # do not colourize log file
if [ -n "$2" ]; then colourizeLogFile=0
if [ -f "$2" ] && [ -s "$2" ]; then ;;
accountFile="${2%/}" -c | --cred* | -f)
shift # path to Cloudflare credentials file
else if [ -n "$2" ]; then
badParam dne "$@" if [ -f "$2" ] && [ -s "$2" ]; then
fi accountFile="${2%/}"
else shift
badParam null "$@" else
fi badParam dne "$@"
;; fi
-r | --record | --records) else
# DNS records to update badParam null "$@"
if [ -n "$2" ]; then fi
dnsRecords=$(printf "%s" "$2" | sed -e 's/ //g') ;;
shift -r | --record | --records)
else # DNS records to update
badParam null "$@" if [ -n "$2" ]; then
fi dnsRecords=$(printf "%s" "$2" | sed -e 's/ //g')
;; shift
-i | --ip | --ip-address | -a | --address) else
# IP address to use (not parsed for correctness) badParam null "$@"
if [ -n "$2" ]; then fi
ipAddress="$2" ;;
shift -i | --ip | --ip-address | -a | --address)
else # IP address to use (not parsed for correctness)
badParam null "$@" if [ -n "$2" ]; then
fi ipAddress="$2"
;; shift
-4 | --ip4 | --ipv4) else
# operate in IP4 mode (default) badParam null "$@"
ip4=1 fi
ip6=0 ;;
;; -4 | --ip4 | --ipv4)
-6 | --ip6 | --ipv6) # operate in IP4 mode (default)
# operate in IP6 mode ip4=1
ip6=1 ip6=0
ip4=0 ;;
;; -6 | --ip6 | --ipv6)
*) # operate in IP6 mode
printf "\n%sUnknown option: %s\n" "$err" "$1" ip6=1
printf "%sUse '--help' for valid options.%s\n\n" "$cyan" "$norm" ip4=0
exit 1 ;;
;; *)
esac printf "\n%sUnknown option: %s\n" "$err" "$1"
shift printf "%sUse '--help' for valid options.%s\n\n" "$cyan" "$norm"
exit 1
;;
esac
shift
done done
### pre-flight checks ### pre-flight checks
if ! command -v curl >/dev/null; then if ! command -v curl >/dev/null; then
printf "\n%sThis script requires 'curl' be installed and accessible. Exiting.%s\n\n" "$err" "$norm" printf "\n%sThis script requires 'curl' be installed and accessible. Exiting.%s\n\n" "$err" "$norm"
exit 2 exit 2
fi fi
if ! command -v jq >/dev/null; then if ! command -v jq >/dev/null; then
printf "\n%sThis script requires 'jq' be installed and accessible. Exiting.%s\n\n" "$err" "$norm" printf "\n%sThis script requires 'jq' be installed and accessible. Exiting.%s\n\n" "$err" "$norm"
exit 2 exit 2
fi fi
[ -z "$dnsRecords" ] && badParam errMsg "You must specify at least one DNS record to update. Exiting." [ -z "$dnsRecords" ] && badParam errMsg "You must specify at least one DNS record to update. Exiting."
# verify credentials file exists and is not empty (default check) # verify credentials file exists and is not empty (default check)
if [ ! -f "$accountFile" ] || [ ! -s "$accountFile" ]; then if [ ! -f "$accountFile" ] || [ ! -s "$accountFile" ]; then
badParam errMsg "Cannot find Cloudflare credentials file (${accountFile}). Exiting." badParam errMsg "Cannot find Cloudflare credentials file (${accountFile}). Exiting."
fi
if ! command -v logger >/dev/null 2>&1; then
printf "\n%sThis script requires 'logger' be installed to write entries to your journaling system. Exiting.%s\n\n" "$err" "$norm"
exit 2
fi fi
# turn off log file colourization if parameter is set # turn off log file colourization if parameter is set
if [ "$colourizeLogFile" -eq 0 ]; then if [ "$colourizeLogFile" -eq 0 ]; then
bold="" bold=""
cyan="" cyan=""
err="" err=""
magenta="" magenta=""
norm="" norm=""
ok="" ok=""
warn="" warn=""
yellow="" yellow=""
fi fi
### initial log entries ### initial log entries
{ {
printf "%s[%s] -- Cloudflare DDNS update-script: starting --%s\n" "$ok" "$(stamp)" "$norm"
printf "Parameters:\n"
printf "script path: %s\n" "$scriptPath/$scriptName"
printf "credentials file: %s\n" "$accountFile"
printf "%s[%s] -- Cloudflare DDNS update-script: starting --%s\n" "$ok" "$(stamp)" "$norm"
printf "Parameters:\n"
printf "script path: %s\n" "$scriptPath/$scriptName"
printf "credentials file: %s\n" "$accountFile"
if [ "$ip4" -eq 1 ]; then
printf "mode: IP4\n"
elif [ "$ip6" -eq 1 ]; then
printf "mode: IP6\n"
fi
# detect and report IP address
if [ -z "$ipAddress" ]; then
# detect public ip address
if [ "$ip4" -eq 1 ]; then if [ "$ip4" -eq 1 ]; then
printf "mode: IP4\n" if ! ipAddress="$(curl -s $ip4DetectionSvc)"; then
elif [ "$ip6" -eq 1 ]; then printf "ddns ip address:%s ERROR%s\n" "$err" "$norm"
printf "mode: IP6\n" exitError 10
fi
fi fi
if [ "$ip6" -eq 1 ]; then
# detect and report IP address if ! ipAddress="$(curl -s $ip6DetectionSvc)"; then
if [ -z "$ipAddress" ]; then printf "ddns ip address:%s ERROR%s\n" "$err" "$norm"
# detect public ip address exitError 10
if [ "$ip4" -eq 1 ]; then fi
if ! ipAddress="$(curl -s $ip4DetectionSvc)"; then
printf "ddns ip address:%s ERROR%s\n" "$err" "$norm"
exitError 10
fi
fi
if [ "$ip6" -eq 1 ]; then
if ! ipAddress="$(curl -s $ip6DetectionSvc)"; then
printf "ddns ip address:%s ERROR%s\n" "$err" "$norm"
exitError 10
fi
fi
printf "ddns ip address (detected): %s\n" "$ipAddress"
else
printf "ddns ip address (supplied): %s\n" "$ipAddress"
fi fi
printf "ddns ip address (detected): %s\n" "$ipAddress"
else
printf "ddns ip address (supplied): %s\n" "$ipAddress"
fi
# iterate DNS records to update # iterate DNS records to update
dnsRecordsToUpdate="$(printf '%s' "${dnsRecords}" | sed "s/${dnsSeparator}*$//")$dnsSeparator" dnsRecordsToUpdate="$(printf '%s' "${dnsRecords}" | sed "s/${dnsSeparator}*$//")$dnsSeparator"
while [ -n "$dnsRecordsToUpdate" ] && [ "$dnsRecordsToUpdate" != "$dnsSeparator" ]; do while [ -n "$dnsRecordsToUpdate" ] && [ "$dnsRecordsToUpdate" != "$dnsSeparator" ]; do
record="${dnsRecordsToUpdate%%${dnsSeparator}*}" record="${dnsRecordsToUpdate%%${dnsSeparator}*}"
dnsRecordsToUpdate="${dnsRecordsToUpdate#*${dnsSeparator}}" dnsRecordsToUpdate="${dnsRecordsToUpdate#*${dnsSeparator}}"
if [ -z "$record" ]; then continue; fi if [ -z "$record" ]; then
printf "updating record: %s\n" "$record" continue
done fi
printf "updating record: %s\n" "$record"
done
printf "(end of parameter list)\n" printf "(end of parameter list)\n"
} >>"$logFile" } >>"$logFile"
### read Cloudflare credentials ### read Cloudflare credentials
writeLog process "Reading Cloudflare credentials" writeLog process "Reading Cloudflare credentials"
case "$accountFile" in case "$accountFile" in
/*) /*)
# absolute path, use as-is # absolute path, use as-is
# shellcheck source=./cloudflare.credentials # shellcheck source=./cloudflare.credentials
. "$accountFile" . "$accountFile"
;; ;;
*) *)
# relative path, rewrite # relative path, rewrite
# shellcheck source=./cloudflare.credentials # shellcheck source=./cloudflare.credentials
. "./$accountFile" . "./$accountFile"
;; ;;
esac esac
if [ -z "$cfKey" ]; then if [ -z "$cfKey" ]; then
writeLog process-error writeLog process-error
exitError 21 exitError 21
fi fi
if [ -z "$cfZoneId" ]; then if [ -z "$cfZoneId" ]; then
writeLog process-error writeLog process-error
exitError 22 exitError 22
fi fi
writeLog process-done "DONE" writeLog process-done "DONE"
### connect to Cloudflare and do what needs to be done! ### connect to Cloudflare and do what needs to be done!
dnsRecordsToUpdate="$dnsRecords$dnsSeparator" dnsRecordsToUpdate="$dnsRecords$dnsSeparator"
if [ "$ip4" -eq 1 ]; then if [ "$ip4" -eq 1 ]; then
recordType="A" recordType="A"
elif [ "$ip6" -eq 1 ]; then elif [ "$ip6" -eq 1 ]; then
recordType="AAAA" recordType="AAAA"
fi fi
# iterate hosts to update # iterate hosts to update
while [ -n "$dnsRecordsToUpdate" ] && [ "$dnsRecordsToUpdate" != "$dnsSeparator" ]; do while [ -n "$dnsRecordsToUpdate" ] && [ "$dnsRecordsToUpdate" != "$dnsSeparator" ]; do
record="${dnsRecordsToUpdate%%${dnsSeparator}*}" record="${dnsRecordsToUpdate%%${dnsSeparator}*}"
dnsRecordsToUpdate="${dnsRecordsToUpdate#*${dnsSeparator}}" dnsRecordsToUpdate="${dnsRecordsToUpdate#*${dnsSeparator}}"
if [ -z "$record" ]; then continue; fi if [ -z "$record" ]; then
writeLog process "Processing ${record}" continue
fi
writeLog process "Processing ${record}"
# exit if curl/network error # exit if curl/network error
if ! cfLookup="$(curl -s -X GET "https://api.cloudflare.com/client/v4/zones/${cfZoneId}/dns_records?name=${record}&type=${recordType}" \ if ! cfLookup="$(
-H "Authorization: Bearer ${cfKey}" \ curl -s -X GET "https://api.cloudflare.com/client/v4/zones/${cfZoneId}/dns_records?name=${record}&type=${recordType}" \
-H "Content-Type: application/json")"; then -H "Authorization: Bearer ${cfKey}" \
writeLog process-error -H "Content-Type: application/json"
exitError 3 )"; then
fi writeLog process-error
exitError 3
fi
# exit if API error # exit if API error
# exit here since API errors on GET request probably indicates authentication error which would affect all remaining operations # exit here since API errors on GET request probably indicates authentication error which would affect all remaining operations
# no reason to continue processing other hosts and pile-up errors which might look like a DoS attempt # no reason to continue processing other hosts and pile-up errors which might look like a DoS attempt
cfSuccess="$(printf "%s" "$cfLookup" | jq -r '.success')" cfSuccess="$(printf "%s" "$cfLookup" | jq -r '.success')"
if [ "$cfSuccess" = "false" ]; then if [ "$cfSuccess" = "false" ]; then
writeLog process-error writeLog process-error
listCFErrors "$cfLookup" listCFErrors "$cfLookup"
exitError 25 exitError 25
fi fi
resultCount="$(printf "%s" "$cfLookup" | jq '.result_info.count')" resultCount="$(printf "%s" "$cfLookup" | jq '.result_info.count')"
# skip to next host if cannot find existing host record (this script *updates* only, does not create!) # skip to next host if cannot find existing host record (this script *updates* only, does not create!)
if [ "$resultCount" = "0" ]; then if [ "$resultCount" = "0" ]; then
# warn if record of host not found # warn if record of host not found
writeLog process-warning "NOT FOUND" writeLog process-warning "NOT FOUND"
writeLog warn "Cannot find existing record to update for DNS entry: ${record}" writeLog warn "Cannot find existing record to update for DNS entry: ${record}"
invalidDomainCount=$((invalidDomainCount + 1)) invalidDomainCount=$((invalidDomainCount + 1))
continue continue
fi fi
objectId=$(printf "%s" "$cfLookup" | jq -r '.result | .[] | .id') objectId=$(printf "%s" "$cfLookup" | jq -r '.result | .[] | .id')
currentIpAddr=$(printf "%s" "$cfLookup" | jq -r '.result | .[] | .content') currentIpAddr=$(printf "%s" "$cfLookup" | jq -r '.result | .[] | .content')
writeLog process-done "FOUND: IP = ${currentIpAddr}" writeLog process-done "FOUND: IP = ${currentIpAddr}"
# skip to next hostname if record already up-to-date # skip to next hostname if record already up-to-date
if [ "$currentIpAddr" = "$ipAddress" ]; then if [ "$currentIpAddr" = "$ipAddress" ]; then
writeLog stamped "IP address for ${record} is already up-to-date" writeLog stamped "IP address for ${record} is already up-to-date"
continue continue
fi fi
# update record # update record
writeLog process "Updating IP address for ${record}" writeLog process "Updating IP address for ${record}"
updateJSON="$(jq -n --arg key0 content --arg value0 "${ipAddress}" '{($key0):$value0}')" updateJSON="$(jq -n --arg key0 content --arg value0 "${ipAddress}" '{($key0):$value0}')"
# exit if curl/network error # exit if curl/network error
if ! cfResult="$(curl -s -X PATCH "https://api.cloudflare.com/client/v4/zones/${cfZoneId}/dns_records/${objectId}" \ if ! cfResult="$(
-H "Authorization: Bearer ${cfKey}" \ curl -s -X PATCH "https://api.cloudflare.com/client/v4/zones/${cfZoneId}/dns_records/${objectId}" \
-H "Content-Type: application/json" \ -H "Authorization: Bearer ${cfKey}" \
--data "${updateJSON}")"; then -H "Content-Type: application/json" \
writeLog process-error --data "${updateJSON}"
exitError 3 )"; then
fi writeLog process-error
exitError 3
fi
# note update success or failure # note update success or failure
cfSuccess="$(printf "%s" "$cfResult" | jq '.success')" cfSuccess="$(printf "%s" "$cfResult" | jq '.success')"
if [ "$cfSuccess" = "true" ]; then if [ "$cfSuccess" = "true" ]; then
writeLog process-done "DONE" writeLog process-done "DONE"
writeLog success "IP address for ${record} updated." writeLog success "IP address for ${record} updated."
else else
writeLog process-error writeLog process-error
listCFErrors "$cfResult" listCFErrors "$cfResult"
writeLog err "Unable to update IP address for ${record}" writeLog err "Unable to update IP address for ${record}"
# do not exit with error, API error here is probably an update issue specific to this host # do not exit with error, API error here is probably an update issue specific to this host
# increment counter and note it after all processing finished # increment counter and note it after all processing finished
failedHostCount=$((failedHostCount + 1)) failedHostCount=$((failedHostCount + 1))
fi fi
done done
# exit # exit
if [ "$invalidDomainCount" -ne 0 ]; then if [ "$invalidDomainCount" -ne 0 ]; then
writeLog warning "${invalidDomainCount} invalid host(s) supplied for updating." writeLog warning "${invalidDomainCount} invalid host(s) supplied for updating."
fi fi
if [ "$failedHostCount" -ne 0 ]; then if [ "$failedHostCount" -ne 0 ]; then
exitError 26 exitError 26
else else
exitOK exitOK
fi fi
### exit return codes ### exit return codes
+16 -8
View File
@@ -15,17 +15,17 @@ If you need help getting logwatch installed and set-up, please [check out my blo
<!-- toc --> <!-- toc -->
- [LogFile Group file (/etc/logwatch/conf/logfiles/cfddns.conf)](#logfile-group-file-etclogwatchconflogfilescfddnsconf) - [LogFile Group file](#logfile-group-file)
* [Log file location](#log-file-location) * [Log file location](#log-file-location)
* [Archive location and name format](#archive-location-and-name-format) * [Archive location and name format](#archive-location-and-name-format)
* [External script for timestamp processing](#external-script-for-timestamp-processing) * [External script for timestamp processing](#external-script-for-timestamp-processing)
- [Service definition file (/etc/logwatch/conf/services/cfddns.conf)](#service-definition-file-etclogwatchconfservicescfddnsconf) - [Service definition file](#service-definition-file)
* [LogFile Group file definition](#logfile-group-file-definition) * [LogFile Group file definition](#logfile-group-file-definition)
* [Report title](#report-title) * [Report title](#report-title)
* [Detail level](#detail-level) * [Detail level](#detail-level)
- [Service script (/etc/logwatch/scripts/services/cfddns)](#service-script-etclogwatchscriptsservicescfddns) - [Service script](#service-script)
* [Detail levels](#detail-levels) * [Detail levels](#detail-levels)
- [Timestamp processing script (/etc/logwatch/scripts/shared/sqfullstampanywhere)](#timestamp-processing-script-etclogwatchscriptssharedsqfullstampanywhere) - [Timestamp processing script](#timestamp-processing-script)
* [The time format specification](#the-time-format-specification) * [The time format specification](#the-time-format-specification)
* [The search REGEX](#the-search-regex) * [The search REGEX](#the-search-regex)
- [Testing](#testing) - [Testing](#testing)
@@ -33,7 +33,9 @@ If you need help getting logwatch installed and set-up, please [check out my blo
<!-- tocstop --> <!-- tocstop -->
## LogFile Group file (/etc/logwatch/conf/logfiles/cfddns.conf) ## LogFile Group file
> This file is located within the repo at */etc/logwatch/conf/logfiles/cfddns.conf*
### Log file location ### Log file location
@@ -79,7 +81,9 @@ The script file is called with an asterisk (*\**) before the filename.
If you change the name of this file, you will have to change this line. Remember that whatever you type here as a name is converted to all-lowercase so your filename should be all lowercase also. If you change the name of this file, you will have to change this line. Remember that whatever you type here as a name is converted to all-lowercase so your filename should be all lowercase also.
## Service definition file (/etc/logwatch/conf/services/cfddns.conf) ## Service definition file
> This file is located within the repo at */etc/logwatch/conf/services/cfddns.conf*
### LogFile Group file definition ### LogFile Group file definition
@@ -119,7 +123,9 @@ Simply change it to the value you want enforced. For example, here I'm setting
Detail = 5 Detail = 5
``` ```
## Service script (/etc/logwatch/scripts/services/cfddns) ## Service script
> This file is located within the repo at */etc/logwatch/scripts/services/cfddns*
Logwatch calls any script with a name that **matches the service name**. You'll notice that I just named everything *cfddns* to keep things simple. You can change this to whatever you want. If you changed the service name to *"cloudflare*.conf", for example, you would have to rename this script file to "*cloudflare*" with no extension. Note: The script is a PERL file (note the Logwatch calls any script with a name that **matches the service name**. You'll notice that I just named everything *cfddns* to keep things simple. You can change this to whatever you want. If you changed the service name to *"cloudflare*.conf", for example, you would have to rename this script file to "*cloudflare*" with no extension. Note: The script is a PERL file (note the
shebang) but it can be written in any language. shebang) but it can be written in any language.
@@ -160,7 +166,9 @@ The script supports four (4) detail levels as follows:
- **Use this detail level only when you need to see the entire log file and cannot otherwise access the log file.** - **Use this detail level only when you need to see the entire log file and cannot otherwise access the log file.**
- Depending on how your logwatch treats this log dump, you may see gibberish control codes like *\e[0m;]*. If this is the case, run the script with the `--no-colour` or `--nc` option to remove ANSI colour formatting. - Depending on how your logwatch treats this log dump, you may see gibberish control codes like *\e[0m;]*. If this is the case, run the script with the `--no-colour` or `--nc` option to remove ANSI colour formatting.
## Timestamp processing script (/etc/logwatch/scripts/shared/sqfullstampanywhere) ## Timestamp processing script
> This file is located within the repo at */etc/logwatch/scripts/shared/sqfullstampanywhere*
This is basically a modified version of the '*applyeurodate*' script that comes with Logwatch. It had to be modified to search within [square brackets] and to accept characters coming before the stamp (i.e. ANSI colour codes). If you change the '**stamp**' variable in the updater script to update the timestamp to your liking (which to totally fine!) then you'll probably have to update this file. There are two lines you need to modify to suit your new '**stamp**' variable. This is basically a modified version of the '*applyeurodate*' script that comes with Logwatch. It had to be modified to search within [square brackets] and to accept characters coming before the stamp (i.e. ANSI colour codes). If you change the '**stamp**' variable in the updater script to update the timestamp to your liking (which to totally fine!) then you'll probably have to update this file. There are two lines you need to modify to suit your new '**stamp**' variable.
+126
View File
@@ -0,0 +1,126 @@
#!/bin/sh
getTimeStamp() {
(date +%F" "%T)
}
# $1: message, $2: level, $3: operation, $4: code
writeJsonLog() {
PROGRAM_NAME="cfddns"
DEFAULT_CODE=99
DEFAULT_LEVEL="info"
DEFAULT_MESSAGE="An unspecified error has occurred"
DEFAULT_OPERATION="unspecified"
if [ -z "$1" ]; then
PROPS="$(
jq --null-input \
--arg level "err" \
--arg pName "$PROGRAM_NAME" \
--arg operation "$DEFAULT_OPERATION" \
--arg code "$DEFAULT_CODE" \
--arg message "$DEFAULT_MESSAGE" \
'{"level":$level, "programName":$pName, "operation":$operation, "code":$code, "message":$message}' \
)"
else
PROPS="$(
jq --null-input \
--arg level "${2:-$DEFAULT_LEVEL}" \
--arg pName "$PROGRAM_NAME" \
--arg operation "${3:-$DEFAULT_OPERATION}" \
--arg code "${4:-$DEFAULT_CODE}" \
--arg message "$1" \
'{"level":$level, "programName":$pName, "operation":$operation, "code":$code, "message":$message}' \
)"
fi
echo "$PROPS" | jq "."
return
}
# $1: message, $2: level, $3: operation, $4: code
writeJournalLog() {
PROGRAM_NAME="cfddns"
DEFAULT_CODE=99
DEFAULT_LEVEL="info"
DEFAULT_MESSAGE="An unspecified error has occurred"
DEFAULT_OPERATION="unspecified"
# translate error levels
if [ -z "$2" ]; then
LOG_LEVEL=1
else
case "$2" in
"emergency" | "emerg")
LOG_LEVEL=7
;;
"alert")
LOG_LEVEL=6
;;
"critical" | "crit")
LOG_LEVEL=5
;;
"error" | "err")
LOG_LEVEL=4
;;
"warning" | "warn")
LOG_LEVEL=3
;;
"notice")
LOG_LEVEL=2
;;
"info")
LOG_LEVEL=1
;;
"debug")
LOG_LEVEL=0
;;
esac
fi
# log the message
if [ -z "$1" ]; then
logger --journald <<end
MESSAGE_ID=$(systemd-id128 new)
SYSLOG_TIMESTAMP=$(getTimeStamp)
SYSLOG_FACILITY=3
SYSLOG_IDENTIFIER=${PROGRAM_NAME}
PRIORITY=4
ERRNO=${DEFAULT_CODE}
OPERATION=${DEFAULT_OPERATION}
MESSAGE=${DEFAULT_MESSAGE}
end
else
logger --journald <<end
MESSAGE_ID=$(systemd-id128 new)
SYSLOG_TIMESTAMP=$(getTimeStamp)
SYSLOG_FACILITY=3
SYSLOG_IDENTIFIER=${PROGRAM_NAME}
PRIORITY=${LOG_LEVEL}
ERRNO=${4:-$DEFAULT_CODE}
OPERATION=${3:-$DEFAULT_OPERATION}
MESSAGE=$1
end
fi
return
}
if [ "$1" = "json" ]; then
writeJsonLog # this will generate a generic error message
writeJsonLog "This is a test message" # generate this message at the default level with the default code
writeJsonLog "This is a test message" "warning" # generate this message at the 'warning' level with the default code
writeJsonLog "This is a test message" "error" "testing" # generate this message at the 'error' level, part of a 'test' operation, and with the default code
writeJsonLog "This is a test message" "alert" "testing" 10 # generate this message at the 'alert' level with all parameters set
elif [ "$1" = "journal" ]; then
writeJournalLog # this will generate a generic error message
writeJournalLog "This is a test message" # generate this message at the default level with the default code
writeJournalLog "This is a test message" "warning" # generate this message at the 'warning' level with the default code
writeJournalLog "This is a test message" "error" "testing" # generate this message at the 'error' level as part of a 'test' operation, and with the default code
writeJournalLog "This is a test message" "alert" "testing" 10 # generate this message at the 'alert' level with all parameters set
else
printf "\nPlease specify either 'json' or 'journal' after the script name. Exiting.\n\n"
exit 1
fi
exit 0