#!/bin/sh # Certbot deploy hook: install only the renewed turn certificate, then ask the # distro unit to reload or restart. A restart can interrupt active allocations; # schedule renewal windows and verify the unit's ExecReload before production. set -eu : "${RENEWED_LINEAGE:?certbot did not provide RENEWED_LINEAGE}" openssl x509 -in "$RENEWED_LINEAGE/fullchain.pem" -noout \ -checkhost turn.lumbridgecorp.com >/dev/null 2>&1 || exit 0 getent group turnserver >/dev/null || { echo "coturn certificate hook: turnserver group does not exist" >&2 exit 1 } install -d -o root -g turnserver -m 0750 /etc/coturn/certs install -o root -g turnserver -m 0644 "$RENEWED_LINEAGE/fullchain.pem" /etc/coturn/certs/turn.fullchain.pem install -o root -g turnserver -m 0640 "$RENEWED_LINEAGE/privkey.pem" /etc/coturn/certs/turn.privkey.pem systemctl try-reload-or-restart coturn.service