Sign inSign up

hedger/certbot-dns-henet

By hedger

•Updated almost 2 years ago

certbot with Hurricane Electric DNS Authentication Provider (dns.he.net) and renewal automation.

Image
Networking
Security
Integration & delivery
1

567

hedger/certbot-dns-henet repository overview

⁠certbot with Hurricane Electric Authentication Provider

⁠About

  • This image is designed for automating ACME DNS-01 validation with Hurricane Electric free DNS service⁠.
  • Based on the official certbot image⁠.
  • Provides the certbot command with the dns-henet plugin pre-installed, as well as basic automation for renewing certificates.

Github repo⁠

⁠Usage

By default, the image runs in manual mode, for compatibility with the official image.

To use the image in fully automated mode, run the following command:

docker run --rm \
    -e DOMAINS="example.com *.example.com" \
    -e EMAIL="[email protected]" \
    -v $(pwd)/henet.ini:/run/dns-credentials/henet.ini \
    -v /etc/letsencrypt:/etc/letsencrypt \
    --entrypoint "/certbot_he_auto_ep.sh" \
    hedger/certbot-dns-henet

Alternatively, you can run the certbot command directly:

docker run -it --rm \
    -v /etc/letsencrypt:/etc/letsencrypt \
    -v /var/lib/letsencrypt:/var/lib/letsencrypt \
    -v /var/log/letsencrypt:/var/log/letsencrypt \
    -v $(pwd)/henet.ini:/run/dns-credentials/henet.ini \
    hedger/certbot-dns-henet \
    certonly \
    --authenticator dns-henet \
    --dns-henet-credentials /run/dns-credentials/henet.ini \
    --domain '*.example.com' --domain 'example.com' \

⁠Environment Variables

  • DOMAINS: should contain a space-separated list of domains to include in the certificate. Required.
  • EMAIL: should contain the email address to use for registration and recovery contact. Optional, but recommended.
  • DAEMON: if set to any value, the container will run in daemon mode and renew the certificate automatically. Optional.
  • CRON_SCHEDULE: should contain a cron schedule for renewing the certificate. Optional, default is 28 6 */2 * *, which means once every other day.
  • CREDENTIALS_FILE: should contain the path to the credentials file in the container. Optional, default is /run/dns-credentials/henet.ini.
  • STAGING: if set to any value, the Let's Encrypt staging server will be used instead of the production server. Optional.
  • MUST_STAPLE: if set to any value, the certificate will be generated with the OCSP Must-Staple extension⁠. Optional, default is not set.

Additionally, you must provide the henet.ini file with your dns.he.net credentials. The file should be mounted to $CREDENTIALS_FILE (/run/dns-credentials/henet.ini by default).

Credentials file uses plain INI format:

dns_henet_username=USERNAME
dns_henet_password=PASSWORD

⁠Liveness Status

Container reports its status using Docker's HEALTHCHECK feature. It checks if the certificates are present and no other certbot process is running. That way you can set up container startup order in your orchestration system. For example, in Docker Compose you can use depends_on:

services:
  certbot:
    image: hedger/certbot-dns-henet
    environment:
      DOMAINS: "example.com *.example.com"
      EMAIL: "[email protected]"
      DAEMON: 1
      CREDENTIALS_FILE: /run/secrets/he-auth
    entrypoint: /certbot_he_auto_ep.sh
    secrets:
      - he-auth
    ...

  nginx:
    ...
    depends_on:
      certbot:
        condition: service_healthy

secrets:
  he-auth:
    file: ./he.ini

⁠Acknowledgements

Based on original implementation⁠ by @gentoo-root (Maxim Mikityanskiy).

Tag summary

Content type

Image

Digest

sha256:2c77e5cb8…

Size

46.8 MB

Last updated

almost 2 years ago

docker pull hedger/certbot-dns-henet