Sign inSign up

dhsncats/certboto

By dhsncats

•Updated about 7 years ago

Image
1

1.1K

dhsncats/certboto repository overview

⁠certboto-docker 📜🤖☁️🐳

Build Status Total alerts Language grade: Python

⁠Docker Image

MicroBadger Layers MicroBadger Size

Certboto combines all the convenience of Certbot⁠ with the cloudiness of AWS S3 buckets⁠ and AWS Route53⁠ all wrapped up in a tasty Docker⁠ container.

⁠Usage

Consider using a docker-compose.yml file to run Certboto. See the Install section below.

To issue a new certificate:

docker-compose run certboto certonly -d lemmy.imotorhead.com

To renew existing certificates:

docker-compose run certboto

For additional certbot commands see the help:

docker-compose run certboto --help
⁠Install

Create a docker-compose.yml file similar to this:

---
version: "3.7"

secrets:
  credentials:
    file: /home/username/.aws/credentials

services:
  certboto:
    image: dhsncats/certboto
    init: true
    restart: "no"
    environment:
      - AWS_DEFAULT_REGION=us-east-1
      - BUCKET_NAME=my-certificates
      - BUCKET_PROFILE=certsync-role
      - DNS_PROFILE=dns-role
    secrets:
      - source: credentials
        target: credentials

Pull dhsncats/certboto from Docker hub⁠:

docker-compose pull

Or build dhsncats/certboto from source:

git clone https://github.com/cisagov/certboto-docker.git
cd certboto-docker
docker-compose build --build-arg VERSION=0.0.1

⁠Environment Variables

VariablePurpose
AWS_DEFAULT_REGIONDefault AWS region
BUCKET_NAMEThe bucket to store the Certbot configuration
BUCKET_PROFILEThe profile of your credentials to use for bucket access.
DNS_PROFILEThe profile of your credentials to use for route53 access.

⁠Secrets

FilenamePurpose
credentialsThe AWS credentials⁠ file.

⁠AWS Policies

⁠Certboto Roles

The BUCKET_PROFILE should assume a role with the following policy:

{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Sid": "VisualEditor0",
            "Effect": "Allow",
            "Action": [
                "s3:PutObject",
                "s3:GetObject",
                "s3:ListBucket",
                "s3:DeleteObject"
            ],
            "Resource": [
                "arn:aws:s3:::cert-bucket-name",
                "arn:aws:s3:::cert-bucket-name/*"
            ]
        }
    ]
}

The DNS_PROFILE should assume a role with the following policy:

{
    "Version": "2012-10-17",
    "Id": "certbot-dns-route53 sample policy",
    "Statement": [
        {
            "Effect": "Allow",
            "Action": [
                "route53:ListHostedZones",
                "route53:GetChange"
            ],
            "Resource": [
                "*"
            ]
        },
        {
            "Effect" : "Allow",
            "Action" : [
                "route53:ChangeResourceRecordSets"
            ],
            "Resource" : [
                "arn:aws:route53:::hostedzone/YOURHOSTEDZONEID"
            ]
        }
    ]
}
⁠Certificate Access Role

To access a specific certificate, a role with the following profile should be assumed:

{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Sid": "allow-cert-read",
            "Effect": "Allow",
            "Action": "s3:GetObject",
            "Resource": "arn:aws:s3:::cert-bucket-name/live/lemmy.imotorhead.com/*"
        }
    ]
}

⁠Contributing

We welcome contributions! Please see here⁠ for details.

⁠License

This project is in the worldwide public domain⁠.

This project is in the public domain within the United States, and copyright and related rights in the work worldwide are waived through the CC0 1.0 Universal public domain dedication⁠.

All contributions to this project will be released under the CC0 dedication. By submitting a pull request, you are agreeing to comply with this waiver of copyright interest.

Tag summary

Content type

Image

Digest

Size

83.8 MB

Last updated

about 7 years ago

docker pull dhsncats/certboto