Restore install and cron docs for the cert check

These were dropped in b1b4296 when the README was trimmed, which left no
record in the repo of how the script gets onto the server or how it is
scheduled.
This commit is contained in:
Walusimbi Silver
2026-09-03 14:31:33 +03:00
parent a9774ae55a
commit 7f188cc12a

View File

@@ -12,5 +12,58 @@ maintenance checks can be added here over time.
## SSL Certificate Expiry Alerts
`scripts/check-cert-expiry.sh` checks Let's Encrypt certificates and alerts when
any certificate expires in less than 14 days.
`scripts/check-cert-expiry.sh` checks every Let's Encrypt certificate under
`/etc/letsencrypt/live` and sends an ntfy alert when any certificate expires in
less than 14 days.
### Install
```bash
sudo install -m 0755 scripts/check-cert-expiry.sh /opt/scripts/check-cert-expiry.sh
```
### Root cron
```cron
15 8 * * * /opt/scripts/check-cert-expiry.sh >>/var/log/cert-expiry-check.log 2>&1
```
### Defaults
```bash
CERT_DIR=/etc/letsencrypt/live
EXPIRY_DAYS=14
NTFY_URL=https://ntfy.silverwal.com/certbot
ALERT_ON_NO_CERTS=true
```
### Overrides
```bash
EXPIRY_DAYS=21 /opt/scripts/check-cert-expiry.sh
```
If the ntfy topic is protected with an access token:
```bash
NTFY_TOKEN=your-token /opt/scripts/check-cert-expiry.sh
```
### Manual test
```bash
sudo /opt/scripts/check-cert-expiry.sh
```
The script exits `0` when all certificates are healthy and `1` when it sends an
alert or cannot run the check correctly.
## Notification Notes
ntfy is a good default for this server because it is already self-hosted, simple
to call from shell scripts, and supports useful alert metadata such as title,
priority, and tags.
For jobs where silence is also a failure, pair ntfy with a dead man's switch such
as Healthchecks. ntfy tells you what the script found; Healthchecks tells you when
the script did not run at all.