From 688c1571e418a91c5eec29c59070a267faf1e3fc Mon Sep 17 00:00:00 2001 From: Josh Hawkins <32435876+hawkeye217@users.noreply.github.com> Date: Sun, 30 Aug 2026 12:43:23 -0500 Subject: [PATCH] keep certsync's cert selection identical to nginx's --- docker/main/rootfs/etc/s6-overlay/s6-rc.d/certsync/run | 8 +++++--- 1 file changed, 5 insertions(+), 3 deletions(-) diff --git a/docker/main/rootfs/etc/s6-overlay/s6-rc.d/certsync/run b/docker/main/rootfs/etc/s6-overlay/s6-rc.d/certsync/run index 7d0a3723c1..0c699c2db4 100755 --- a/docker/main/rootfs/etc/s6-overlay/s6-rc.d/certsync/run +++ b/docker/main/rootfs/etc/s6-overlay/s6-rc.d/certsync/run @@ -26,9 +26,11 @@ function reload_nginx() { echo "[INFO] Starting certsync..." -# Resolved once, to match the choice nginx made at its own startup: watching a -# path nginx did not load would compare fingerprints that can never agree. -if [ -f /etc/letsencrypt/live/frigate/fullchain.pem ]; then +# Resolved once, and the condition must stay identical to the nginx run +# script's. Testing only fullchain.pem here would pick the mounted cert on a +# half-populated mount that nginx rejected, and the two fingerprints would then +# never agree, reloading nginx every cycle forever. +if [ -f /etc/letsencrypt/live/frigate/privkey.pem ] && [ -f /etc/letsencrypt/live/frigate/fullchain.pem ]; then lefile="/etc/letsencrypt/live/frigate/fullchain.pem" else lefile="/config/tls/fullchain.pem"