-
-
Notifications
You must be signed in to change notification settings - Fork 1k
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Add DNS Provider for Tencent Cloud (#1527)
- Loading branch information
Showing
10 changed files
with
489 additions
and
3 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,66 @@ | ||
--- | ||
title: "Tencent Cloud DNS" | ||
date: 2019-03-03T16:39:46+01:00 | ||
draft: false | ||
slug: tencentcloud | ||
--- | ||
|
||
<!-- THIS DOCUMENTATION IS AUTO-GENERATED. PLEASE DO NOT EDIT. --> | ||
<!-- providers/dns/tencentcloud/tencentcloud.toml --> | ||
<!-- THIS DOCUMENTATION IS AUTO-GENERATED. PLEASE DO NOT EDIT. --> | ||
|
||
Since: v4.6.0 | ||
|
||
Configuration for [Tencent Cloud DNS](https://cloud.tencent.com/product/cns). | ||
|
||
|
||
<!--more--> | ||
|
||
- Code: `tencentcloud` | ||
|
||
Here is an example bash command using the Tencent Cloud DNS provider: | ||
|
||
```bash | ||
TENCENTCLOUD_SECRET_ID=abcdefghijklmnopqrstuvwx \ | ||
TENCENTCLOUD_SECRET_KEY=your-secret-key \ | ||
lego --email [email protected] --dns tencentcloud --domains my.example.org run | ||
``` | ||
|
||
|
||
|
||
|
||
## Credentials | ||
|
||
| Environment Variable Name | Description | | ||
|-----------------------|-------------| | ||
| `TENCENTCLOUD_SECRET_ID` | Access key ID | | ||
| `TENCENTCLOUD_SECRET_KEY` | Access Key secret | | ||
|
||
The environment variable names can be suffixed by `_FILE` to reference a file instead of a value. | ||
More information [here](/lego/dns/#configuration-and-credentials). | ||
|
||
|
||
## Additional Configuration | ||
|
||
| Environment Variable Name | Description | | ||
|--------------------------------|-------------| | ||
| `TENCENTCLOUD_HTTP_TIMEOUT` | API request timeout | | ||
| `TENCENTCLOUD_POLLING_INTERVAL` | Time between DNS propagation check | | ||
| `TENCENTCLOUD_PROPAGATION_TIMEOUT` | Maximum waiting time for DNS propagation | | ||
| `TENCENTCLOUD_REGION` | Region | | ||
| `TENCENTCLOUD_TTL` | The TTL of the TXT record used for the DNS challenge | | ||
|
||
The environment variable names can be suffixed by `_FILE` to reference a file instead of a value. | ||
More information [here](/lego/dns/#configuration-and-credentials). | ||
|
||
|
||
|
||
|
||
## More information | ||
|
||
- [API documentation](https://cloud.tencent.com/document/product/1427/56153) | ||
- [Go client](https://github.com/tencentcloud/tencentcloud-sdk-go) | ||
|
||
<!-- THIS DOCUMENTATION IS AUTO-GENERATED. PLEASE DO NOT EDIT. --> | ||
<!-- providers/dns/tencentcloud/tencentcloud.toml --> | ||
<!-- THIS DOCUMENTATION IS AUTO-GENERATED. PLEASE DO NOT EDIT. --> |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,70 @@ | ||
package tencentcloud | ||
|
||
import ( | ||
"strings" | ||
|
||
"github.com/go-acme/lego/v4/challenge/dns01" | ||
"github.com/tencentcloud/tencentcloud-sdk-go/tencentcloud/common" | ||
dnspod "github.com/tencentcloud/tencentcloud-sdk-go/tencentcloud/dnspod/v20210323" | ||
) | ||
|
||
type domainData struct { | ||
domain string | ||
subDomain string | ||
} | ||
|
||
func getDomainData(fqdn string) (*domainData, error) { | ||
zone, err := dns01.FindZoneByFqdn(fqdn) | ||
if err != nil { | ||
return nil, err | ||
} | ||
|
||
return &domainData{ | ||
domain: zone, | ||
subDomain: dns01.UnFqdn(strings.TrimSuffix(fqdn, zone)), | ||
}, nil | ||
} | ||
|
||
func (d *DNSProvider) createRecordData(domainData *domainData, value string) error { | ||
request := dnspod.NewCreateRecordRequest() | ||
request.Domain = common.StringPtr(domainData.domain) | ||
request.SubDomain = common.StringPtr(domainData.subDomain) | ||
request.RecordType = common.StringPtr("TXT") | ||
request.RecordLine = common.StringPtr("默认") | ||
request.Value = common.StringPtr(value) | ||
request.TTL = common.Uint64Ptr(uint64(d.config.TTL)) | ||
|
||
_, err := d.client.CreateRecord(request) | ||
if err != nil { | ||
return err | ||
} | ||
|
||
return nil | ||
} | ||
|
||
func (d *DNSProvider) listRecordData(domainData *domainData) ([]*dnspod.RecordListItem, error) { | ||
request := dnspod.NewDescribeRecordListRequest() | ||
request.Domain = common.StringPtr(domainData.domain) | ||
request.Subdomain = common.StringPtr(domainData.subDomain) | ||
request.RecordType = common.StringPtr("TXT") | ||
|
||
response, err := d.client.DescribeRecordList(request) | ||
if err != nil { | ||
return nil, err | ||
} | ||
|
||
return response.Response.RecordList, nil | ||
} | ||
|
||
func (d *DNSProvider) deleteRecordData(domainData *domainData, item *dnspod.RecordListItem) error { | ||
request := dnspod.NewDeleteRecordRequest() | ||
request.Domain = common.StringPtr(domainData.domain) | ||
request.RecordId = item.RecordId | ||
|
||
_, err := d.client.DeleteRecord(request) | ||
if err != nil { | ||
return err | ||
} | ||
|
||
return nil | ||
} |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,142 @@ | ||
// Package tencentcloud implements a DNS provider for solving the DNS-01 challenge using Tencent Cloud DNS. | ||
package tencentcloud | ||
|
||
import ( | ||
"errors" | ||
"fmt" | ||
"time" | ||
|
||
"github.com/go-acme/lego/v4/challenge/dns01" | ||
"github.com/go-acme/lego/v4/platform/config/env" | ||
"github.com/tencentcloud/tencentcloud-sdk-go/tencentcloud/common" | ||
"github.com/tencentcloud/tencentcloud-sdk-go/tencentcloud/common/profile" | ||
dnspod "github.com/tencentcloud/tencentcloud-sdk-go/tencentcloud/dnspod/v20210323" | ||
) | ||
|
||
// Environment variables names. | ||
const ( | ||
envNamespace = "TENCENTCLOUD_" | ||
|
||
EnvSecretID = envNamespace + "SECRET_ID" | ||
EnvSecretKey = envNamespace + "SECRET_KEY" | ||
EnvRegion = envNamespace + "REGION" | ||
|
||
EnvTTL = envNamespace + "TTL" | ||
EnvPropagationTimeout = envNamespace + "PROPAGATION_TIMEOUT" | ||
EnvPollingInterval = envNamespace + "POLLING_INTERVAL" | ||
EnvHTTPTimeout = envNamespace + "HTTP_TIMEOUT" | ||
) | ||
|
||
// Config is used to configure the creation of the DNSProvider. | ||
type Config struct { | ||
SecretID string | ||
SecretKey string | ||
Region string | ||
|
||
PropagationTimeout time.Duration | ||
PollingInterval time.Duration | ||
TTL int | ||
HTTPTimeout time.Duration | ||
} | ||
|
||
// NewDefaultConfig returns a default configuration for the DNSProvider. | ||
func NewDefaultConfig() *Config { | ||
return &Config{ | ||
TTL: env.GetOrDefaultInt(EnvTTL, 600), | ||
PropagationTimeout: env.GetOrDefaultSecond(EnvPropagationTimeout, dns01.DefaultPropagationTimeout), | ||
PollingInterval: env.GetOrDefaultSecond(EnvPollingInterval, dns01.DefaultPollingInterval), | ||
HTTPTimeout: env.GetOrDefaultSecond(EnvHTTPTimeout, 10*time.Second), | ||
} | ||
} | ||
|
||
// DNSProvider implements the challenge.Provider interface. | ||
type DNSProvider struct { | ||
config *Config | ||
client *dnspod.Client | ||
} | ||
|
||
// NewDNSProvider returns a DNSProvider instance configured for Tencent Cloud DNS. | ||
// Credentials must be passed in the environment variable: TENCENTCLOUD_SECRET_ID, TENCENTCLOUD_SECRET_KEY. | ||
func NewDNSProvider() (*DNSProvider, error) { | ||
values, err := env.Get(EnvSecretID, EnvSecretKey) | ||
if err != nil { | ||
return nil, fmt.Errorf("tencentcloud: %w", err) | ||
} | ||
|
||
config := NewDefaultConfig() | ||
config.SecretID = values[EnvSecretID] | ||
config.SecretKey = values[EnvSecretKey] | ||
config.Region = env.GetOrDefaultString(EnvRegion, "") | ||
|
||
return NewDNSProviderConfig(config) | ||
} | ||
|
||
// NewDNSProviderConfig return a DNSProvider instance configured for Tencent Cloud DNS. | ||
func NewDNSProviderConfig(config *Config) (*DNSProvider, error) { | ||
if config == nil { | ||
return nil, errors.New("tencentcloud: the configuration of the DNS provider is nil") | ||
} | ||
|
||
if config.SecretID == "" || config.SecretKey == "" { | ||
return nil, errors.New("tencentcloud: credentials missing") | ||
} | ||
|
||
credential := common.NewCredential(config.SecretID, config.SecretKey) | ||
|
||
cpf := profile.NewClientProfile() | ||
cpf.HttpProfile.Endpoint = "dnspod.tencentcloudapi.com" | ||
|
||
client, err := dnspod.NewClient(credential, config.Region, cpf) | ||
if err != nil { | ||
return nil, fmt.Errorf("tencentcloud: %w", err) | ||
} | ||
|
||
return &DNSProvider{config: config, client: client}, nil | ||
} | ||
|
||
// Timeout returns the timeout and interval to use when checking for DNS propagation. | ||
// Adjusting here to cope with spikes in propagation times. | ||
func (d *DNSProvider) Timeout() (timeout, interval time.Duration) { | ||
return d.config.PropagationTimeout, d.config.PollingInterval | ||
} | ||
|
||
// Present creates a TXT record to fulfill the dns-01 challenge. | ||
func (d *DNSProvider) Present(domain, token, keyAuth string) error { | ||
fqdn, value := dns01.GetRecord(domain, keyAuth) | ||
|
||
domainData, err := getDomainData(fqdn) | ||
if err != nil { | ||
return fmt.Errorf("tencentcloud: failed to get domain data: %w", err) | ||
} | ||
|
||
err = d.createRecordData(domainData, value) | ||
if err != nil { | ||
return fmt.Errorf("tencentcloud: create record failed: %w", err) | ||
} | ||
|
||
return nil | ||
} | ||
|
||
// CleanUp removes the TXT record matching the specified parameters. | ||
func (d *DNSProvider) CleanUp(domain, token, keyAuth string) error { | ||
fqdn, _ := dns01.GetRecord(domain, keyAuth) | ||
|
||
domainData, err := getDomainData(fqdn) | ||
if err != nil { | ||
return fmt.Errorf("tencentcloud: failed to get domain data: %w", err) | ||
} | ||
|
||
records, err := d.listRecordData(domainData) | ||
if err != nil { | ||
return fmt.Errorf("tencentcloud: list records failed: %w", err) | ||
} | ||
|
||
for _, item := range records { | ||
err := d.deleteRecordData(domainData, item) | ||
if err != nil { | ||
return fmt.Errorf("tencentcloud: delete record failed: %w", err) | ||
} | ||
} | ||
|
||
return nil | ||
} |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,26 @@ | ||
Name = "Tencent Cloud DNS" | ||
Description = '''''' | ||
URL = "https://cloud.tencent.com/product/cns" | ||
Code = "tencentcloud" | ||
Since = "v4.6.0" | ||
|
||
Example = ''' | ||
TENCENTCLOUD_SECRET_ID=abcdefghijklmnopqrstuvwx \ | ||
TENCENTCLOUD_SECRET_KEY=your-secret-key \ | ||
lego --email [email protected] --dns tencentcloud --domains my.example.org run | ||
''' | ||
|
||
[Configuration] | ||
[Configuration.Credentials] | ||
TENCENTCLOUD_SECRET_ID = "Access key ID" | ||
TENCENTCLOUD_SECRET_KEY = "Access Key secret" | ||
[Configuration.Additional] | ||
TENCENTCLOUD_REGION = "Region" | ||
TENCENTCLOUD_POLLING_INTERVAL = "Time between DNS propagation check" | ||
TENCENTCLOUD_PROPAGATION_TIMEOUT = "Maximum waiting time for DNS propagation" | ||
TENCENTCLOUD_TTL = "The TTL of the TXT record used for the DNS challenge" | ||
TENCENTCLOUD_HTTP_TIMEOUT = "API request timeout" | ||
|
||
[Links] | ||
API = "https://cloud.tencent.com/document/product/1427/56153" | ||
GoClient = "https://github.com/tencentcloud/tencentcloud-sdk-go" |
Oops, something went wrong.