gchan / auto-letsencrypt Goto Github PK
View Code? Open in Web Editor NEWA Docker image to automatically request and renew SSL/TLS certificates from Let's Encrypt
A Docker image to automatically request and renew SSL/TLS certificates from Let's Encrypt
Since I have many webapp containers which all run on different subdomains, I have a proxy container which handles directing traffic in front of my webapps. So it makes more sense to me to simply redirect certbot requests to the certbot container, rather than picking one of my webapps at random to map a webroot with.
So I've modified the entrypoint a tad in my code to allow for the --standalone flag. I don't think it's a particularly tidy solution so I didn't make a pull request. But I figured it was worth raising an issue for as a discussion.
if [[ "$STANDALONE" == 1 ]] ; then
certbot certonly --standalone --agree-tos --noninteractive --text --expand \
--email ${EMAIL} \
${CERTBOT_DOMAINS}
else
certbot certonly --webroot --agree-tos --noninteractive --text --expand \
--email ${EMAIL} \
--webroot-path ${WEBROOT_PATH} \
${CERTBOT_DOMAINS}
fi
Thank you for the repo, it's very helpful.
Hi,
When assigning the DOMAINS env variable in the compose file, only the first domain is being processed.
Ex
DOMAINS=tbd.example.com www.tbd.example.com tbd2.example.com www.tbd2.example.com
A certificate will be requested only for the first domain:tbd.example.com
Compose sample:
environment:
- EMAIL=[email protected]
- WEBROOT_PATH=/data/certbot/www
- DOMAINS=tbd.example.com www.tbd.example.com tbd2.example.com www.tbd2.example.com
- CHECK_FREQ=7
Thank you.
Should be something like this instead
for domain in "${DOMAINS[@]}"; do
cp /etc/letsencrypt/live/$domain/* $CERTS_PATH/
done
Just to get it functional. But even then you end up with the problem of the files from different domains having the same name.
It would probably be better to simply cp -Lr /etc/letsencrypt/live/* $CERTS_PATH/
instead to keep the domain directories separate. Also (-L) to make sure that we don't copy a symlink that'll break when used as a volume between containers.
Edit: actually since certbot will only use the first domain in the list to create the certificate name I suppose cp -L /etc/letsencrypt/live/${DOMAINS[0]}/* $CERTS_PATH/
is what you want
A declarative, efficient, and flexible JavaScript library for building user interfaces.
๐ Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
An Open Source Machine Learning Framework for Everyone
The Web framework for perfectionists with deadlines.
A PHP framework for web artisans
Bring data to life with SVG, Canvas and HTML. ๐๐๐
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
Some thing interesting about web. New door for the world.
A server is a program made to process requests and deliver data to clients.
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
Some thing interesting about visualization, use data art
Some thing interesting about game, make everyone happy.
We are working to build community through open source technology. NB: members must have two-factor auth.
Open source projects and samples from Microsoft.
Google โค๏ธ Open Source for everyone.
Alibaba Open Source for everyone
Data-Driven Documents codes.
China tencent open source team.