Sign inSign up

devopsworks/certspotter

By devopsworks

•Updated over 7 years ago

An (unofficial) image for certspotter (https://github.com/SSLMate/certspotter), a CT log monitor.

Image
0

1.2K

devopsworks/certspotter repository overview

⁠certspotter Docker image

This is an (unofficial) image for SSLMate/certspotter⁠, a Certificate Transparency Log Monitor.

It will warn you in slack when a new certificate is found in the CT logs⁠.

⁠Usage

⁠Using this image
docker run -d --name certspotter \
    -e CS_DELAY=43200 \
    -e CS_DOMAINS=".everything.org www.specific.org" \
    -e CS_SLACK_URL=https://hooks.slack.com/services/SOME/SLACK/TOKEN \
    -e CS_DEBUG=1 \
    devopsworks/certspotter
⁠Environment variables
VariableDescriptionDefault
CS_DELAYInterval between certspotter runs86400 (1 day)
CS_DOMAINSDomains to watch fornone (compulsory)
CS_SLACK_URLSlack URL for notificationsnone
CS_DEBUGSets certspotter & scripts in verbose mode""
⁠Additionnal notification hooks

The image will execute any script present in /certspotter/hooks.d/ and passes a message as the first argument.

Hooks will be called:

  • when the container starts
  • when a new certificate is found for the watched domains
⁠Example
mkdir hooks.d/
cat > hooks.d/url.sh<<EOF
#!/bin/bash

echo -e "${1}\n" | curl -sXPOST http://some.url/seen --data @-
EOF
chmod +x hooks.d/url.sh
docker run -d --name certspotter \
    -v $(pwd)/hooks.d/:/certspotter/hooks.d/ \
    -e CS_DELAY=43200 \
    -e CS_DOMAINS=".everything.org www.specific.org" \
    -e CS_SLACK_URL=https://hooks.slack.com/services/SOME/SLACK/TOKEN \
    -e CS_DEBUG=1 \
    devopsworks/certspotter
⁠Building your own
docker build . -t some/tag

⁠Caveats

DNS_DOMAINS and -script are not used since I could not make them work using docker. Debugging required...

⁠Licence

Tag summary

Content type

Image

Digest

Size

59.5 MB

Last updated

over 7 years ago

docker pull devopsworks/certspotter