Gets the cert bundle of a porkbun domain via the v3 api!
823
A simple rust utility to pull and renew the Let's Encrypt certificate generated by Porkbun. Meant for small deployments where you don't need big scalability. If you do, check out this Let's Encrypt integration guide or perhaps this Let's Encrypt forum post for more guidance.
All source code available at my Codeberg edameki/porkbun_cert_getter!
The container is a one-shot! That is to say, it will not stay alive and poll for renewals on its own. I'm a podman believer, so I suggest using making it a quadlet and using a systemd timer unit to run it occasionally!
PORKBUN_API_KEY (or PORKBUN_API_KEY_FILE)PORKBUN_API_SECRET_KEY (or PORKBUN_API_SECRET_KEY_FILE)PORKBUN_DOMAIN (or PORKBUN_DOMAIN_FILE)OUT_DIR
/home/certworker/bundleporkbun_cert_getter.container
[Unit]
Description=Cert Getter Quadlet
# Before=whatever_needs_certs.pod
[Service]
Type=oneshot
Restart=on-failure
# Don't spam retry and potentially discover Porkbun's usage limit
RestartSec=15s
RestartSteps=6
RestartMaxDelaySec=60min
# In case I need to pull an update
TimeoutStartSec=90s
[Container]
Image=docker.io/edameki/porkbun_cert_getter:latest
Environment="PORKBUN_DOMAIN=mywebsite.domain"
Environment="PORKBUN_API_KEY_FILE=/run/secrets/porkbun_api_key"
Environment="PORKBUN_API_SECRET_KEY_FILE=/run/secrets/porkbun_api_secret_key"
Secret=porkbun_api_key
Secret=porkbun_api_secret_key
Volume=certs.volume:/home/certworker/bundle:rw,U,z
porkbun_cert_getter.timer
[Unit]
Description=Cert Getter Timer
# The container quadlet turns into porkbun_cert_getter.service, so we dont' need to actually specify it.
# Unit=porkbun_cert_getter.service
[Timer]
# Every day, at 1:30AM (give or take 5 minutes), with up to 10 minutes random delay.
# Don't want to hit Porkbun at the same time as everyone else, so we show some courtesy.
OnCalendar=*-*-* 01:30:00
AccuracySec=5min
RandomizedDelaySec=10min
Content type
Image
Digest
sha256:c608f3922…
Size
42.1 MB
Last updated
4 months ago
docker pull edameki/porkbun_cert_getter