Sign inSign up

imoize/nginx-quic

By imoize

•Updated over 2 years ago

Nginx with http3 and acme.sh support

Image
1

1.2K

imoize/nginx-quic repository overview

⁠Nginx http3 Docker Image

NGINX is a web server that can be also used as a reverse proxy, load balancer, and HTTP cache. Recommended for high-demanding sites due to its ability to provide faster content.

Github Build Status GitHub GitHub Package Repository Docker Pulls

⁠Supported Architectures

Multi-platform available trough docker manifest. Simply pulling using latest tag should retrieve the correct image for your arch.

The architectures supported by this image:

ArchitectureAvailable
x86-64✅
arm64✅

⁠Usage

Here are some example to help you get started creating a container, easiest way to setup is using docker-compose or use docker cli.

  • docker-compose (recommended)
---
version: "3.9"
services:
  nginx-quic:
    image: imoize/nginx-quic:latest
    container_name: nginx-quic
    ports:
      - 80:80
      - 443:443
    environment:
      - PUID=1001
      - PGID=1001
      - TZ=Asia/Jakarta
    volumes:
      - /path/to/app/data:/config
    restart: always
  • docker cli
docker run -d \
  --name=nginx-quic \
  -p 80:80
  -p 443:443 \
  -e PUID=1001 \
  -e PGID=1001 \
  -e TZ=Asia/Jakarta \
  -v /path/to/app/data:/config \
  --restart always \
  imoize/nginx-quic:latest

⁠Available environment variables:

NameDescriptionDefault Value
PUIDUser UID
PGIDGroup GID
TZSpecify a timezone see this list⁠.UTC
S6_VERBOSITYControls the verbosity of s6-rc. See this.⁠1

⁠Configuration

⁠Environment variables

When you start the nginx-quic image, you can adjust the configuration of the instance by passing one or more environment variables either on the docker-compose file or on the docker run command line. Please note that some variables are only considered when the container is started for the first time. If you want to add a new environment variable:

  • for docker-compose add the variable name and value:
nginx-quic:
    ...
    environment:
      - PUID=1001
      - TZ=Asia/Jakarta
      - S6_VERBOSITY=2
    ...
  • for manual execution add a -e option with each variable and value:
  docker run -d \
  -e PUID=1001 \
  -e TZ=Asia/Jakarta \
  -e S6_VERBOSITY=2 \
  imoize/nginx-quic:latest

⁠Volume

⁠Persisting your application

If you remove the container all your data will be lost, and the next time you run the image the data and config will be reinitialized. To avoid this loss of data, you should mount a volume that will persist even after the container is removed.

For persistence you should map directory inside container in /config path to host directory as data volumes. Application state will persist as long as directory on the host are not removed.

e.g: /path/to/app/data:/config

nginx-quic:
    ...
    environment:
      - PUID=1001
    volumes:
      - /path/to/app/data:/config
    ...

/config folder contains nginx relevant configuration files.

⁠User / Group Identifiers

For example: PUID=1001 and PGID=1001, to find yours user id and gid type id <your_username> in terminal.

  $ id your_username
    uid=1001(user) gid=1001(group) groups=1001(group)

⁠Issue certificate and install with acme.sh

⁠Request certificate
  1. Access shell inside container
docker exec -it nginx-quic bash
  1. Request new certificate
DOMAIN="YOUR-DOMAIN"

export CF_Token="Your_Cloudflare_DNS_API_Key_Goes_here"

acme.sh --issue --dns dns_cf --ocsp-must-staple -d "$DOMAIN" -d "*.${DOMAIN}"
  1. Install certificate
DOMAIN="YOUR-DOMAIN"

CERT_DIR="/config/ssl/acme/${DOMAIN}"

mkdir -p "$CERT_DIR"

acme.sh -d "$DOMAIN" \
--install-cert \
--cert-file "${CERT_DIR}/${DOMAIN}.cer" \
--key-file "${CERT_DIR}/${DOMAIN}.key" \
--ca-file "${CERT_DIR}/ca.cer" \
--fullchain-file "${CERT_DIR}/fullchain.cer" \
--reloadcmd "chown -R $PUID:$PGID /config/ssl/acme && s6-svc -1 -h -r /run/service/svc-nginx"
⁠Edit nginx config

If /config is bind-mount to host then you can edit in your host folder directly.

  1. Edit config in /config/nginx/site-confs/default.conf, don't forget to replace YOUR-DOMAIN. should look like this :
server {
    listen      80;
    listen [::]:80;

    server_name YOUR-DOMAIN;

    # Redirect HTTP to HTTPS
    return 301 https://$host$request_uri;
}
server {
    listen      443 ssl;
    listen [::]:443 ssl;

    listen      443 quic;
    listen [::]:443 quic;

    server_name YOUR-DOMAIN;

    # uncomment
    include /config/nginx/conf.d/headers.conf;
  1. By default this image using self-signed certificate, Edit config in /config/nginx/conf.d/ssl.conf, don't forget to replace YOUR-DOMAIN. should look like this :
# self-signed certificate
# ssl_certificate /config/ssl/self-signed/cert.crt;
# ssl_certificate_key /config/ssl/self-signed/cert.key;

# acme letsencrypt certificate
ssl_certificate /config/ssl/acme/YOUR-DOMAIN/fullchain.cer;
ssl_certificate_key /config/ssl/acme/YOUR-DOMAIN/YOUR-DOMAIN.key;

# OCSP stapling
ssl_stapling on;
ssl_stapling_verify on;
ssl_trusted_certificate /config/ssl/acme/YOUR-DOMAIN/fullchain.cer;
  1. Restart your container to take effect.

⁠Crowdsec

  1. Install crowdsec.
  2. open /path/to/crowdsec/acquis.d/appsec.yaml and fill it with:
listen_addr: 0.0.0.0:7422
appsec_config: crowdsecurity/virtual-patching
name: myAppSecComponent
source: appsec
labels:
  type: appsec
  1. open /path/to/crowdsec/acquis.d/nginx.yaml and fill it with:
filenames:
  - /var/log/nginx/access.log
labels:
  type: nginx
---
source: docker
container_name:
 - nginx
labels:
  type: nginx
  1. run docker exec crowdsec cscli bouncers add nginx-bouncer and save the output
  2. open /config/crowdsec/crowdsec.conf
  3. set ENABLED to true
  4. use the output of step 4 as API_KEY
  5. save the file

⁠Contributing

We'd love for you to contribute to this container. You can submitting a pull request⁠ with your contribution.

⁠Issues

If you encountered a problem running this container, you can create an issue⁠.

Tag summary

Content type

Image

Digest

sha256:a38407963…

Size

18.7 MB

Last updated

over 2 years ago

docker pull imoize/nginx-quic