Files
CloudflareDDNS/cfddns.sh
T
asif 2b0128d0c1 fix(log): Prevent preflight duplicate logging
Prevent writing preflight error messages to the console twice when using console logging mode.
2026-07-24 01:08:54 -06:00

554 lines
19 KiB
Bash

#!/bin/sh
#
# update Cloudflare DNS records with current (dynamic) IP address
# Script by Asif Bacchus <asif@bacchus.cloud>
# Last modified: July 19, 2026
# Version 3.0
#
### text formatting presets using tput
if command -v tput >/dev/null; then
[ -z "$TERM" ] && export TERM=xterm
bold=$(tput bold)
cyan=$(tput setaf 6)
err=$(tput bold)$(tput setaf 1)
magenta=$(tput setaf 5)
norm=$(tput sgr0)
ok=$(tput setaf 2)
warn=$(tput bold)$(tput setaf 3)
yellow=$(tput setaf 3)
width=$(tput cols)
else
bold=""
cyan=""
err=""
magenta=""
norm=""
ok=""
warn=""
yellow=""
width=80
fi
badParam() {
if [ "$1" = "null" ]; then
printf "\n%sERROR: '%s' cannot have a NULL (empty) value.\n" "$err" "$2"
printf "%sPlease use '--help' for assistance.%s\n\n" "$cyan" "$norm"
exit 1
elif [ "$1" = "dne" ]; then
printf "\n%sERROR: '%s %s'\n" "$err" "$2" "$3"
printf "file or directory does not exist or is empty.%s\n\n" "$norm"
exit 1
elif [ "$1" = "errMsg" ]; then
printf "\n%sERROR: %s%s\n\n" "$err" "$2" "$norm"
exit 1
fi
}
getHostname() {
(hostname -s)
}
getTimeStamp() {
(date -u +"%Y-%m-%dT%H:%M:%SZ")
}
lowercase() {
echo "$1" | tr '[:upper:]' '[:lower:]'
}
uppercase() {
echo "$1" | tr '[:lower:]' '[:upper:]'
}
# 1: cloudflare error object, 2: operation identifier
listCFErrors() {
# extract error codes and messages in separate variables, replace newlines with underscores
codes="$(printf "%s" "$1" | jq -r '.errors | .[] | .code' | tr '\n' '_')"
messages="$(printf "%s" "$1" | jq -r '.errors | .[] | .message' | tr '\n' '_')"
# iterate codes and messages, assemble into a coherent log message
while [ -n "$codes" ] && [ -n "$messages" ]; do
# get the first code and message in respective sets
code="${codes%%_*}"
message="${messages%%_*}"
# update sets of codes and messages by removing the first item (above) in each set
codes="${codes#*_}"
messages="${messages#*_}"
# output to log
writePlainTextLog "${message}" "err" "fail" "$2" "$code"
done
}
standardizeLogLevels() {
LEVEL_TO_STANDARDIZE="$(lowercase "$1")"
case "$LEVEL_TO_STANDARDIZE" in
"critical" | "crit" | "fatal")
echo "CRIT"
;;
"error" | "err")
echo "ERR"
;;
"warning" | "warn")
echo "WARN"
;;
"information" | "info")
echo "INFO"
;;
"debug" | "verbose")
echo "DEBUG"
;;
*)
echo "INFO"
;;
esac
}
# modified syslog fmt: <ISO-8601 timestamp> <hostname> <tag>[pid]: [LEVEL:$2] [STATUS:$3] <MESSAGE:$1> (<OPERATION:$4>:<CODE:$5>)
writePlainTextLog() {
# not enough information to generate a meaningful log message
if [ -z "$1" ] || [ $# -lt 3 ]; then
return
fi
printf "%s %s %s[%s]: [%s] [%s] %s (%s:%s)\n" \
"$(getTimeStamp)" "$(getHostname)" "$LOG_PROGRAM_NAME" "$$" \
"$(standardizeLogLevels "$2")" "$(uppercase "$3")" "$1" "${4:-UNSPECIFIED}" "${5:-0}" \
>>"$logFile"
}
scriptExamples() {
newline
printf "Update Cloudflare DNS host A/AAAA records with current IP address.\n"
printf "%sUsage: %s --records host.domain.tld[,host2.domain.tld,...] [parameters]%s\n\n" "$bold" "$scriptName" "$norm"
textBlock "${magenta}--- usage examples ---${norm}"
newline
textBlockSwitches "${scriptName} -r myserver.mydomain.net"
textBlock "Update Cloudflare DNS records for myserver.mydomain.net with the auto-detected public IP4 address. Credentials will be expected in the default location and the log will be written in the default location also."
newline
textBlockSwitches "${scriptName} -r myserver.mydomain.net -6"
textBlock "Same as above, but update AAAA host records with the auto-detected public IP6 address."
newline
textBlockSwitches "${scriptName} -r myserver.mydomain.net,myserver2.mydomain.net -l /var/log/cfddns.log --nc"
textBlock "Update DNS entries for both listed hosts using auto-detected IP4 address. Write a non-coloured log to '/var/log/cfddns.log'."
newline
textBlockSwitches "${scriptName} -r myserver.mydomain.net,myserver2.mydomain.net -l /var/log/cfddns.log --ip6 --ip fd21:7a62:2737:9c3a::a151"
textBlock "Update DNS AAAA entries for listed hosts using the *specified* IP address. Write a colourful log to the location specified."
newline
textBlockSwitches "${scriptName} -r myserver.mydomain.net -c /root/cloudflare.creds -l /var/log/cfddns.log --ip 1.2.3.4"
textBlock "Update DNS A entry for listed hostname with the provided IP address. Read cloudflare credentials file from specified location, save log in specified location."
newline
textBlockSwitches "${scriptName} -r myserver.mydomain.net -c /root/cloudflare.creds -l /var/log/cfddns.log -6 -i fd21:7a62:2737:9c3a::a151"
textBlock "Exact same as above, but change the AAAA record. This is how you run the script once for IP4 and again for IP6."
exit 0
}
scriptHelp() {
newline
printf "Update Cloudflare DNS host A/AAAA records with current IP address.\n"
printf "%sUsage: %s --records host.domain.tld[,host2.domain.tld,...] [parameters]%s\n\n" "$bold" "$scriptName" "$norm"
textBlock "The only required parameter is '--records' which is a comma-delimited list of hostnames to update. However, there are several other options which may be useful to implement."
textBlock "Parameters are listed below and followed by a description of their effect. If a default value exists, it will be listed on the following line in (parentheses)."
newline
textBlock "${magenta}--- script-related parameters ---${norm}"
newline
textBlockSwitches "-c | --cred | --creds | --credentials | -f (deprecated, backward-compatibility)"
textBlock "Path to the file containing your Cloudflare *token* credentials. Please refer to the repo README for more information on format, etc."
textBlockDefaults "(${accountFile})"
newline
textBlockSwitches "--log-file"
textBlock "Path where the log file should be written. Script will use file-based logging."
textBlockDefaults "(${logFile})"
newline
textBlockSwitches "--log-console"
textBlock "Switch value. Script will use console-based (stdout) logging."
textBlockDefaults "(disabled: use file-based logging)"
newline
textBlockSwitches "--log-journal"
textBlock "Switch value. Script will use journald-based logging."
textBlockDefaults "(disabled: use file-based logging)"
newline
textBlockSwitches "--log-none"
textBlock "Switch value. Script will not log anything. You will not have *any* output from the script if you choose this option, so you will not know if updates succeed or fail."
textBlockDefaults "(disabled: use file-based logging)"
newline
textBlockSwitches "--fmt-json"
textBlock "Switch value. Use JSON formatted key-value pair structured logging format. Best when using a log parsing tool or log management system to read your log files. Does not apply when using '--log-journal'."
textBlockDefaults "(enabled)"
newline
textBlockSwitches "--fmt-syslog"
textBlock "Switch value. Use a modified syslog (plain-text) format for log messages. Ideal when logging to the console. Does not apply when using '--log-journal'."
textBlockDefaults "(disabled: use structured JSON logging)"
newline
textBlockSwitches "-h | --help | -?"
textBlock "Display this information screen."
newline
textBlockSwitches "--examples"
textBlock "Show some usage examples."
newline
textBlock "${magenta}--- DNS related parameters ---${norm}"
newline
textBlockSwitches "-r | --record | --records"
textBlock "Comma-delimited list of hostnames for which IP addresses should be updated in Cloudflare DNS. This parameter is REQUIRED. Note that this script will only *update* records, it will not create new ones. If you supply hostnames that are not already defined in DNS, the script will log a warning and will skip those hostnames."
newline
textBlockSwitches "-i | --ip | --ip-address | -a | --address"
textBlock "New IP address for DNS host records. If you omit this, the script will attempt to auto-detect your public IP address and use that. N.B. IP addresses are *not* parsed for correctness."
newline
textBlockSwitches "-4 | --ip4 | --ipv4"
textBlock "Switch value. Update Host 'A' records (IP4) only. Note that this script can only update either A *or* AAAA records. If you need to update both, you'll have to run the script once in IP4 mode and again in IP6 mode. If you specify both this switch and the IP6 switch, the last one specified will take effect."
textBlockDefaults "(enabled: update A records)"
newline
textBlockSwitches "-6 | --ip6 | --ipv6"
textBlock "Switch value. Update Host 'AAAA' records (IP6) only. Note that this script can only update either A *or* AAAA records. If you need to update both, you'll have to run the script once in IP4 mode and again in IP6 mode. If you specify both this switch and the IP4 switch, the last one specified will take effect."
textBlockDefaults "(disabled: update A records)"
newline
textBlock "Please refer to the repo README for more detailed information regarding this script and how to automate and monitor it."
newline
exit 0
}
newline() {
printf "\n"
}
textBlock() {
printf "%s\n" "$1" | fold -w "$width" -s
}
textBlockDefaults() {
printf "%s%s%s\n" "$yellow" "$1" "$norm"
}
textBlockSwitches() {
printf "%s%s%s\n" "$cyan" "$1" "$norm"
}
### default variable values
scriptPath="$(CDPATH='' \cd -- "$(dirname -- "$0")" && pwd -P)"
scriptName="$(basename "$0")"
logFile="$scriptPath/${scriptName%.*}.log"
logToJournal=0
useJsonLogFmt=1
useSyslogLogFmt=0
accountFile="$scriptPath/cloudflare.credentials"
colourizeLogFile=1
dnsRecords=""
dnsSeparator=","
ipAddress=""
ip4=1
ip6=0
ip4DetectionSvc="http://ipv4.icanhazip.com"
ip6DetectionSvc="http://ipv6.icanhazip.com"
invalidDomainCount=0
failedHostCount=0
### process startup parameters
if [ -z "$1" ]; then
scriptHelp
fi
while [ $# -gt 0 ]; do
case "$1" in
-h | -\? | --help)
# display help
scriptHelp
;;
--examples)
# display sample commands
scriptExamples
;;
--log-file)
# use file-based logging at the specified location
if [ -n "$2" ]; then
logFile="${2%/}"
shift
else
badParam null "$@"
fi
;;
--log-console)
# use console-based logging
logFile="/dev/stdout"
;;
--log-journal)
# use journald-based logging
logToJournal=1
;;
--log-none)
# do not log anything
logFile="/dev/null"
;;
--fmt-json)
# use JSON log formatting
useJsonLogFmt=1
useSyslogLogFmt=0
;;
--fmt-syslog)
# use modified syslog plain-text log formatting
useSyslogLogFmt=1
useJsonLogFmt=0
;;
-c | --cred* | -f)
# path to the Cloudflare credentials file
if [ -n "$2" ]; then
if [ -f "$2" ] && [ -s "$2" ]; then
accountFile="${2%/}"
shift
else
badParam dne "$@"
fi
else
badParam null "$@"
fi
;;
-r | --record | --records)
# DNS records to update
if [ -n "$2" ]; then
dnsRecords=$(printf "%s" "$2" | sed -e 's/ //g')
shift
else
badParam null "$@"
fi
;;
-i | --ip | --ip-address | -a | --address)
# IP address to use (not parsed for correctness)
if [ -n "$2" ]; then
ipAddress="$2"
shift
else
badParam null "$@"
fi
;;
-4 | --ip4 | --ipv4)
# operate in IP4 mode (default)
ip4=1
ip6=0
;;
-6 | --ip6 | --ipv6)
# operate in IP6 mode
ip6=1
ip4=0
;;
*)
printf "\n%sUnknown option: %s\n" "$err" "$1"
printf "%sUse '--help' for valid options.%s\n\n" "$cyan" "$norm"
exit 1
;;
esac
shift
done
### pre-flight checks
if ! command -v curl >/dev/null; then
printf "\n%sThis script requires 'curl' be installed and accessible. Exiting.%s\n\n" "$err" "$norm"
[ "$logToConsole" -eq 0 ] && writePlainTextLog "'curl' must be installed and accessible" "fatal" "fail" "preexec" 2
exit 2
fi
if ! command -v jq >/dev/null; then
printf "\n%sThis script requires 'jq' be installed and accessible. Exiting.%s\n\n" "$err" "$norm"
[ "$logToConsole" -eq 0 ] && writePlainTextLog "'jq' must be installed and accessible" "fatal" "fail" "preexec" 2
exit 2
fi
if [ -z "$dnsRecords" ]; then
badParam errMsg "You must specify at least one DNS record to update. Exiting."
[ "$logToConsole" -eq 0 ] &&
writePlainTextLog "At least one DNS record to update must be specified" "fatal" "fail" "params" 1
fi
# verify the credentials file exists and is not empty (default check)
if [ ! -f "$accountFile" ] || [ ! -s "$accountFile" ]; then
badParam errMsg "Cannot find the Cloudflare credentials file (${accountFile}). Exiting."
[ "$logToConsole" -eq 0 ] &&
writePlainTextLog "Cannot find the specified Cloudflare credentials file (${accountFile})" "fatal" "fail" "params" 1
fi
if [ "$logToJournal" -eq 1 ] && ! command -v logger >/dev/null 2>&1; then
printf "\n%sThis script requires 'logger' be installed to write entries to your journaling system. Exiting.%s\n\n" "$err" "$norm"
exit 2
fi
# turn off log file colourization if parameter is set
if [ "$colourizeLogFile" -eq 0 ]; then
bold=""
cyan=""
err=""
magenta=""
norm=""
ok=""
warn=""
yellow=""
fi
### initial log entries
writePlainTextLog "starting '${scriptName}'" "info" "ok" "script"
writePlainTextLog "script path: ${scriptPath}/${scriptName}" "debug" "ok" "startup"
writePlainTextLog "credentials file: ${accountFile}" "debug" "ok" "startup"
if [ "$ip4" -eq 1 ]; then
writePlainTextLog "mode: IPv4" "debug" "ok" "startup"
elif [ "$ip6" -eq 1 ]; then
writePlainTextLog "mode: IPv6" "debug" "ok" "startup"
fi
# detect and report IP address
if [ -z "$ipAddress" ]; then
# detect public ip address
if [ "$ip4" -eq 1 ]; then
if ! ipAddress="$(curl -s $ip4DetectionSvc)"; then
writePlainTextLog \
"Unable to auto-detect this machine's public IP address; try again later or supply the IP address to be used" "err" "fail" "detectip" 10
exit 10
fi
fi
if [ "$ip6" -eq 1 ]; then
if ! ipAddress="$(curl -s $ip6DetectionSvc)"; then
writePlainTextLog \
"Unable to auto-detect this machine's public IP address; try again later or supply the IP address to be used" "err" "fail" "detectip" 10
exit 10
fi
fi
writePlainTextLog "DDNS IP address (detected): $ipAddress" "info" "ok" "startup"
else
writePlainTextLog "DDNS IP address (supplied): $ipAddress" "info" "ok" "startup"
fi
# iterate DNS records to update
dnsRecordsToUpdate="$(printf '%s' "${dnsRecords}" | sed "s/${dnsSeparator}*$//")$dnsSeparator"
while [ -n "$dnsRecordsToUpdate" ] && [ "$dnsRecordsToUpdate" != "$dnsSeparator" ]; do
record="${dnsRecordsToUpdate%%${dnsSeparator}*}"
dnsRecordsToUpdate="${dnsRecordsToUpdate#*${dnsSeparator}}"
if [ -z "$record" ]; then
continue
fi
writePlainTextLog "DNS host record '${record}' queued for update" "info" "ok" "startup"
done
### read Cloudflare credentials
case "$accountFile" in
/*)
# absolute path, use as-is
# shellcheck source=./cloudflare.credentials
. "$accountFile"
;;
*)
# relative path, rewrite
# shellcheck source=./cloudflare.credentials
. "./$accountFile"
;;
esac
if [ -z "$cfKey" ]; then
writePlainTextLog "Cloudflare authorized API key (cfKey) is either null or undefined; please check your Cloudflare credentials file" "err" "fail" "creds" 21
exit 21
fi
if [ -z "$cfZoneId" ]; then
writePlainTextLog "Cloudflare zone id (cfZoneId) is either null or undefined; please check your Cloudflare credentials file" "err" "fail" "creds" 22
exit 22
fi
writePlainTextLog "Cloudflare credentials file read successfully" "debug" "ok" "creds"
### connect to Cloudflare and do what needs to be done!
dnsRecordsToUpdate="$dnsRecords$dnsSeparator"
if [ "$ip4" -eq 1 ]; then
recordType="A"
elif [ "$ip6" -eq 1 ]; then
recordType="AAAA"
fi
# iterate hosts to update
while [ -n "$dnsRecordsToUpdate" ] && [ "$dnsRecordsToUpdate" != "$dnsSeparator" ]; do
record="${dnsRecordsToUpdate%%${dnsSeparator}*}"
dnsRecordsToUpdate="${dnsRecordsToUpdate#*${dnsSeparator}}"
if [ -z "$record" ]; then
continue
fi
# exit if curl/network error
if ! cfLookup="$(
curl -s -X GET "https://api.cloudflare.com/client/v4/zones/${cfZoneId}/dns_records?name=${record}&type=${recordType}" \
-H "Authorization: Bearer ${cfKey}" \
-H "Content-Type: application/json"
)"; then
writePlainTextLog "Unable to connect to Cloudflare servers; please try again later." "err" "fail" "cflogin" 3
exit 3
fi
# an API error on this GET request likely indicates an authentication error that would affect all remaining operations
# no reason to continue processing other dns records and pile-up errors which might look like a DoS attempt
cfSuccess="$(printf "%s" "$cfLookup" | jq -r '.success')"
if [ "$cfSuccess" = "false" ]; then
listCFErrors "$cfLookup" "cflogin"
writePlainTextLog "Cloudflare API error; review any previously logged 'CF-ERR:' lines for details." "err" "fail" "cflogin" 25
exit 25
fi
resultCount="$(printf "%s" "$cfLookup" | jq '.result_info.count')"
# skip to the next host if an existing host record cannot be found (this script *updates* only, does not create!)
if [ "$resultCount" = "0" ]; then
writePlainTextLog "Cannot find an existing record matching '${record}' to update" "warn" "warn" "ddns"
invalidDomainCount=$((invalidDomainCount + 1))
continue
fi
objectId=$(printf "%s" "$cfLookup" | jq -r '.result | .[] | .id')
currentIpAddr=$(printf "%s" "$cfLookup" | jq -r '.result | .[] | .content')
writePlainTextLog "The current IP address for '${record}' is ${currentIpAddr}" "debug" "ok" "ddns"
# skip to next hostname if record already up to date
if [ "$currentIpAddr" = "$ipAddress" ]; then
writePlainTextLog "The IP address for '${record}' is already up to date" "info" "ok" "ddns"
continue
fi
# update record
updateJSON="$(jq -n --arg key0 content --arg value0 "${ipAddress}" '{($key0):$value0}')"
# exit if curl/network error
if ! cfResult="$(
curl -s -X PATCH "https://api.cloudflare.com/client/v4/zones/${cfZoneId}/dns_records/${objectId}" \
-H "Authorization: Bearer ${cfKey}" \
-H "Content-Type: application/json" \
--data "${updateJSON}"
)"; then
writePlainTextLog "Unable to connect to Cloudflare servers; please try again later." "err" "fail" "ddns" 3
exit 3
fi
# note update success or failure
cfSuccess="$(printf "%s" "$cfResult" | jq '.success')"
if [ "$cfSuccess" = "true" ]; then
writePlainTextLog "The IP address for '${record}' successfully updated" "info" "ok" "ddns"
else
listCFErrors "$cfResult" "ddns"
writePlainTextLog "Unable to update the IP address for '${record}'" "err" "fail" "ddns"
# do not exit with error, API error here is probably an update issue specific to this host
# increment counter and note it after all processing finished
failedHostCount=$((failedHostCount + 1))
fi
done
# exit
if [ "$invalidDomainCount" -ne 0 ]; then
writePlainTextLog "${invalidDomainCount} invalid host(s) were supplied for updating" "warn" "warn" "ddns"
fi
if [ "$failedHostCount" -ne 0 ]; then
writePlainTextLog \
"${failedHostCount} host update(s) failed; review 'CF-ERR:' lines in this log to help determine what may have gone wrong" "err" "fail" "ddns" 26
exit 26
else
writePlainTextLog "${scriptName} completed successfully" "info" "ok" "script"
fi
### exit return codes
# 0: normal exit, no errors
# 1: invalid or unknown parameter
# 2: cannot find or access required external program(s)
# 3: curl error (probably connection)
# 10: cannot auto-detect IP address
# 21: accountFile has a null or missing cfKey variable
# 22: accountFile has a null or missing cfZoneId variable
# 25: Cloudflare API error
# 26: one or more updates failed
# 99: unspecified error occurred