Certboto combines all the convenience of Certbot with the cloudiness of AWS S3 buckets and AWS Route53 all wrapped up in a tasty Docker container.
Consider using a docker-compose.yml file to run Certboto.
See the Install section below.
To issue a new certificate:
docker-compose run certboto certonly -d lemmy.imotorhead.com
To renew existing certificates:
docker-compose run certboto
For additional certbot commands see the help:
docker-compose run certboto --help
Create a docker-compose.yml file similar to this:
---
version: "3.7"
secrets:
credentials:
file: /home/username/.aws/credentials
services:
certboto:
image: dhsncats/certboto
init: true
restart: "no"
environment:
- AWS_DEFAULT_REGION=us-east-1
- BUCKET_NAME=my-certificates
- BUCKET_PROFILE=certsync-role
- DNS_PROFILE=dns-role
secrets:
- source: credentials
target: credentials
Pull dhsncats/certboto from Docker hub:
docker-compose pull
Or build dhsncats/certboto from source:
git clone https://github.com/cisagov/certboto-docker.git
cd certboto-docker
docker-compose build --build-arg VERSION=0.0.1
| Variable | Purpose |
|---|---|
| AWS_DEFAULT_REGION | Default AWS region |
| BUCKET_NAME | The bucket to store the Certbot configuration |
| BUCKET_PROFILE | The profile of your credentials to use for bucket access. |
| DNS_PROFILE | The profile of your credentials to use for route53 access. |
| Filename | Purpose |
|---|---|
| credentials | The AWS credentials file. |
The BUCKET_PROFILE should assume a role with the following policy:
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "VisualEditor0",
"Effect": "Allow",
"Action": [
"s3:PutObject",
"s3:GetObject",
"s3:ListBucket",
"s3:DeleteObject"
],
"Resource": [
"arn:aws:s3:::cert-bucket-name",
"arn:aws:s3:::cert-bucket-name/*"
]
}
]
}
The DNS_PROFILE should assume a role with the following policy:
{
"Version": "2012-10-17",
"Id": "certbot-dns-route53 sample policy",
"Statement": [
{
"Effect": "Allow",
"Action": [
"route53:ListHostedZones",
"route53:GetChange"
],
"Resource": [
"*"
]
},
{
"Effect" : "Allow",
"Action" : [
"route53:ChangeResourceRecordSets"
],
"Resource" : [
"arn:aws:route53:::hostedzone/YOURHOSTEDZONEID"
]
}
]
}
To access a specific certificate, a role with the following profile should be assumed:
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "allow-cert-read",
"Effect": "Allow",
"Action": "s3:GetObject",
"Resource": "arn:aws:s3:::cert-bucket-name/live/lemmy.imotorhead.com/*"
}
]
}
We welcome contributions! Please see here for details.
This project is in the worldwide public domain.
This project is in the public domain within the United States, and copyright and related rights in the work worldwide are waived through the CC0 1.0 Universal public domain dedication.
All contributions to this project will be released under the CC0 dedication. By submitting a pull request, you are agreeing to comply with this waiver of copyright interest.
Content type
Image
Digest
Size
83.8 MB
Last updated
about 7 years ago
docker pull dhsncats/certboto