|
|
|
@ -1,6 +1,16 @@ |
|
|
|
|
#!/bin/bash |
|
|
|
|
## change to "bin/sh" when necessary |
|
|
|
|
|
|
|
|
|
display_help(){ |
|
|
|
|
logger "Usage: $0 [local|file|pass]" |
|
|
|
|
logger " local - Load variables from this script" |
|
|
|
|
logger " file - Load variables from a file" |
|
|
|
|
logger " pass - Load variables from pass" |
|
|
|
|
} |
|
|
|
|
|
|
|
|
|
load_variables(){ |
|
|
|
|
case "$1" in |
|
|
|
|
"local") |
|
|
|
|
############## CLOUDFLARE CREDENTIALS ############## |
|
|
|
|
# @auth_email - The email used to login 'https://dash.cloudflare.com' |
|
|
|
|
# @auth_method - Set to "global" for Global API Key or "token" for Scoped API Token |
|
|
|
@ -44,20 +54,46 @@ sitename="" |
|
|
|
|
slackchannel="" |
|
|
|
|
slackuri="" |
|
|
|
|
discorduri="" |
|
|
|
|
;; |
|
|
|
|
"file") |
|
|
|
|
# Load variables from file |
|
|
|
|
CONFIG_FILE="$HOME/.cloudflare/config6.ini" |
|
|
|
|
|
|
|
|
|
# Check if the configuration file exists |
|
|
|
|
if [ -f "$CONFIG_FILE" ]; then |
|
|
|
|
# Load configuration from the file |
|
|
|
|
source "$CONFIG_FILE" |
|
|
|
|
else |
|
|
|
|
logger "Error: Configuration file '$CONFIG_FILE' not found." |
|
|
|
|
exit 1 |
|
|
|
|
fi |
|
|
|
|
;; |
|
|
|
|
"pass") |
|
|
|
|
# Load variables from pass |
|
|
|
|
source <(pass credentials/cloudflare) |
|
|
|
|
;; |
|
|
|
|
*) |
|
|
|
|
logger "Invalid load_variables option" |
|
|
|
|
exit 1 |
|
|
|
|
;; |
|
|
|
|
esac |
|
|
|
|
} |
|
|
|
|
|
|
|
|
|
validate_variables(){ |
|
|
|
|
# Validate required variables |
|
|
|
|
if [[ -z $auth_email || -z $auth_key || -z $zone_identifier || -z $record_name ]]; then |
|
|
|
|
logger "Missing required variables. Please provide values for 'auth_email', 'auth_key', 'zone_identifier', and 'record_name'." |
|
|
|
|
exit 1 |
|
|
|
|
fi |
|
|
|
|
} |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
################################################ |
|
|
|
|
## Make sure we have a valid IPv6 connection |
|
|
|
|
################################################ |
|
|
|
|
check_ipv6_is_available(){ |
|
|
|
|
if ! { curl -6 -s --head --fail https://ipv6.google.com >/dev/null; }; then |
|
|
|
|
logger -s "$log_header_name: Unable to establish a valid IPv6 connection to a known host." |
|
|
|
|
exit 1 |
|
|
|
|
fi |
|
|
|
|
|
|
|
|
|
################################################ |
|
|
|
|
## Finding our IPv6 address |
|
|
|
|
################################################ |
|
|
|
|
# Regex credits to https://stackoverflow.com/a/17871737 |
|
|
|
|
ipv6_regex="(([0-9a-fA-F]{1,4}:){7,7}[0-9a-fA-F]{1,4}|([0-9a-fA-F]{1,4}:){1,7}:|([0-9a-fA-F]{1,4}:){1,6}:[0-9a-fA-F]{1,4}|([0-9a-fA-F]{1,4}:){1,5}(:[0-9a-fA-F]{1,4}){1,2}|([0-9a-fA-F]{1,4}:){1,4}(:[0-9a-fA-F]{1,4}){1,3}|([0-9a-fA-F]{1,4}:){1,3}(:[0-9a-fA-F]{1,4}){1,4}|([0-9a-fA-F]{1,4}:){1,2}(:[0-9a-fA-F]{1,4}){1,5}|[0-9a-fA-F]{1,4}:((:[0-9a-fA-F]{1,4}){1,6})|:((:[0-9a-fA-F]{1,4}){1,7}|:)|fe80:(:[0-9a-fA-F]{0,4}){0,4}%[0-9a-zA-Z]{1,}|::(ffff(:0{1,4}){0,1}:){0,1}((25[0-5]|(2[0-4]|1{0,1}[0-9]){0,1}[0-9])\.){3,3}(25[0-5]|(2[0-4]|1{0,1}[0-9]){0,1}[0-9])|([0-9a-fA-F]{1,4}:){1,4}:((25[0-5]|(2[0-4]|1{0,1}[0-9]){0,1}[0-9])\.){3,3}(25[0-5]|(2[0-4]|1{0,1}[0-9]){0,1}[0-9]))" |
|
|
|
|
|
|
|
|
@ -87,36 +123,29 @@ if [[ ! $ip =~ ^$ipv6_regex$ ]]; then |
|
|
|
|
logger -s "$log_header_name: Failed to find a valid IPv6 address." |
|
|
|
|
exit 1 |
|
|
|
|
fi |
|
|
|
|
} |
|
|
|
|
|
|
|
|
|
################################################ |
|
|
|
|
## Check and set the proper auth header |
|
|
|
|
################################################ |
|
|
|
|
set_auth_headers(){ |
|
|
|
|
if [[ "${auth_method}" == "global" ]]; then |
|
|
|
|
auth_header="X-Auth-Key:" |
|
|
|
|
else |
|
|
|
|
auth_header="Authorization: Bearer" |
|
|
|
|
fi |
|
|
|
|
} |
|
|
|
|
|
|
|
|
|
################################################ |
|
|
|
|
## Seek for the AAAA record |
|
|
|
|
################################################ |
|
|
|
|
check_if_aaaa_record_exists(){ |
|
|
|
|
logger "$log_header_name: Check Initiated" |
|
|
|
|
record=$(curl -s -X GET "https://api.cloudflare.com/client/v4/zones/$zone_identifier/dns_records?type=AAAA&name=$record_name" \ |
|
|
|
|
-H "X-Auth-Email: $auth_email" \ |
|
|
|
|
-H "$auth_header $auth_key" \ |
|
|
|
|
-H "Content-Type: application/json") |
|
|
|
|
|
|
|
|
|
################################################ |
|
|
|
|
## Check if the domain has an AAAA record |
|
|
|
|
################################################ |
|
|
|
|
if [[ $record == *"\"count\":0"* ]]; then |
|
|
|
|
logger -s "$log_header_name: Record does not exist, perhaps create one first? (${ip} for ${record_name})" |
|
|
|
|
exit 1 |
|
|
|
|
fi |
|
|
|
|
} |
|
|
|
|
|
|
|
|
|
################################################ |
|
|
|
|
## Get existing IP |
|
|
|
|
################################################ |
|
|
|
|
get_current_ip_from_cloudflare(){ |
|
|
|
|
old_ip=$(echo "$record" | sed -E 's/.*"content":"'${ipv6_regex}'".*/\1/') |
|
|
|
|
|
|
|
|
|
# Make sure the extracted IPv6 address is valid |
|
|
|
@ -130,24 +159,18 @@ if [[ $ip == $old_ip ]]; then |
|
|
|
|
logger "$log_header_name: IP ($ip) for ${record_name} has not changed." |
|
|
|
|
exit 0 |
|
|
|
|
fi |
|
|
|
|
} |
|
|
|
|
|
|
|
|
|
################################################ |
|
|
|
|
## Set the record identifier from result |
|
|
|
|
################################################ |
|
|
|
|
update_ip_on_cloudflare(){ |
|
|
|
|
record_identifier=$(echo "$record" | sed -E 's/.*"id":"([A-Za-z0-9_]+)".*/\1/') |
|
|
|
|
|
|
|
|
|
################################################ |
|
|
|
|
## Change the IP@Cloudflare using the API |
|
|
|
|
################################################ |
|
|
|
|
update=$(curl -s -X PATCH "https://api.cloudflare.com/client/v4/zones/$zone_identifier/dns_records/$record_identifier" \ |
|
|
|
|
-H "X-Auth-Email: $auth_email" \ |
|
|
|
|
-H "$auth_header $auth_key" \ |
|
|
|
|
-H "Content-Type: application/json" \ |
|
|
|
|
--data "{\"content\":\"$ip\",\"ttl\":\"$ttl\",\"proxied\":$proxy}") |
|
|
|
|
} |
|
|
|
|
|
|
|
|
|
################################################ |
|
|
|
|
## Report the status |
|
|
|
|
################################################ |
|
|
|
|
send_webhooks(){ |
|
|
|
|
case "$update" in |
|
|
|
|
*"\"success\":false"*) |
|
|
|
|
echo -e "$log_header_name: $ip $record_name DDNS failed for $record_identifier ($ip). DUMPING RESULTS:\n$update" | logger -s |
|
|
|
@ -184,3 +207,26 @@ case "$update" in |
|
|
|
|
exit 0 |
|
|
|
|
;; |
|
|
|
|
esac |
|
|
|
|
} |
|
|
|
|
|
|
|
|
|
main(){ |
|
|
|
|
validate_variables |
|
|
|
|
check_ipv6_is_available |
|
|
|
|
set_auth_headers |
|
|
|
|
check_if_aaaa_record_exists |
|
|
|
|
get_current_ip_from_cloudflare |
|
|
|
|
update_ip_on_cloudflare |
|
|
|
|
send_webhooks |
|
|
|
|
} |
|
|
|
|
|
|
|
|
|
# switch for environment variables loading |
|
|
|
|
case "$1" in |
|
|
|
|
"local"|"file"|"pass") |
|
|
|
|
load_variables "$1" |
|
|
|
|
main |
|
|
|
|
;; |
|
|
|
|
*) |
|
|
|
|
display_help |
|
|
|
|
exit 1 |
|
|
|
|
;; |
|
|
|
|
esac |