Create/Renew certificates using Certbot, AWS Route53 and Encrypting with KMS & S3
2.7K
This docker image was created to solve an issue of automating standalone certificates using Route53 as a DNS provider from Certbot.
To utilise this container at its best deploy to AWS via Terraform. GITHUB URL.
This Docker Image will download a S3 bucket created in AWS.
The bucket needs to contain the CN names in a list format, e.g. hello.bprudence.com, not-real.bprudence.co.uk
The container then runs through the text file creating/renewing the certs for each CN.
The files are then encrypted with a KMS key provided then pushed to S3. To get the raw cert files, you will have to download the file from s3 and use KMS decerypt
Note - 90 Day certs are issues as the service is controlled by LetsEncrypt.
S3 Bucket for single source of truth CN List file as explained above Owners email address. (Recommend a group email address like a distribution group to avoid single persons of failure)
The image requires certain environment variables. The required variables and expected values are listed below:
-e "S3_BUCKET=just-the-bucket-name"
-e "CN_LIST_FILE=s3-prefix/and-file-name/with-extension.txt"
-e "[email protected]"
-e "KMS_KEY_ID=kms-key-id-12345"
Content type
Image
Digest
Size
61.4 MB
Last updated
about 8 years ago
docker pull bprudence/aws-route53-certbot