A Docker container that helps manage SSL certificates by providing a Unix socket for certbot commands and wrapping each command with certbot authentication options and the luadns plugin.
The Dockerfile pulls from alpine:latest, copies a few scripts scripts, and installs dependencies for certbot & certbot's luadns plugin used for DNS authentication.
Certbot attempts to renew all existing certificates found within the /config/data directory every 6 hours (or 4 times/day) using cron.
Certificates can be requested using the autocert.sh wrapper found within the container.
autocert.sh can also be executed via commands sent through the Unix socket /config/cert/autocert.sock. Giving other containers access to the cert directory will allow containers to generate and view certificates without directly accessing the DNS credential file.
The wrapper executes certbot in non-interactive mode, accepts all ACME Subscriber Agreements, and adds other options to enable Luadns authentication. All certbot options that alter the execution path of certbot will be dropped by default. Otherwise autocert.sh will forward any other certbot option flag.
There are a few variables that may need to be set in order for autocert to execute properly.
ENV DEFAULT_EMAIL="[email protected]"
VOLUME "/config"
EMAIL - [OPTIONAL] an email for certbot to use by default if not provided./config - the folder path for configuration within the container:
cert/ contains hard copies of SSL certificates from data/live.data/ contain's certbot's previous work & archieves.luadns.ini text file of luands email & API token.It is highly recommended that one map the configuration directory when running the container; this will save certbot's previous work in the event of failure. In doing so, we decrease the chances of ever reaching the request rate limit for let's encrypt.
Enviroment variables should be set prior to testing this container.
example.com is a reserved TLD and will be automatically rejected by certbot.
docker run -e DEFAULT_EMAIL='[email protected]' -v /config/:/config/ camcamfresh/autocert
This wrapper works with most preexisting commands. Just replace certbot with autocert.sh and remove any preexisting authentication options.
General Exection
autocert.sh certonly -d 'example.com' -d '*.example.com' --cert-name 'wildcard_example.com'
autocert.sh renew
autocert.sh revoke --cert-name 'wildcard_example.com'
Socket Execution
echo "autocert.sh certonly -d 'example.com' -d '*.example.com'" | socat unix-client:autocert.sock -;
echo "autocert.sh certonly -d 'example.com' -d '*.example.com'" | socat unix-client:autocert.sock stdin;
echo "autocert.sh certonly -d 'example.com' -d '*.example.com'" | nc -U autocert.sock;
Using this code requires the use of LuaDNS as a DNS provider. However it can be changed to another DNS provider by forking the code and changing the dns-plugin to another supported DNS provider (see Certbot's website for available providers).
Content type
Image
Digest
Size
400.2 MB
Last updated
about 5 years ago
docker pull camcamfresh/autocert