Sign inSign up

jumpaku/nginx-letsencrypt-reverse-proxy

By jumpaku

•Updated about 6 years ago

Image
0

640

jumpaku/nginx-letsencrypt-reverse-proxy repository overview

⁠nginx-letsencrypt-reverse-proxy

A docker image of reverse proxy.

  • It routes requests based on host fields of request headers.
  • It redirects all HTTP requests to HTTPS.
  • It obtains and renews Let's Encrypt certificates automatically.

⁠Environments

environmentdefaultrequireddescription
RENEW_SCHED0 0 1 * *noschedule of certificates renewal attempts
DOMAINS nodomains and their routings
STAGElocalnostage to deploy
CLIENT_MAX_BODY_SIZE1mnoclient_max_body_size
  • RENEW_SCHED is specified as a cron expression. See https://crontab.guru⁠.
  • DOMAINS is specified as a , separated sequence, each element of which is represented as domain or domain -> URL.
    • For each element represented as domain, the container obtains and renews the certificate of the domain.
    • For each element represented as domain -> URL, in addition to the above, the container routes requests with the domain to the specified URL.
  • STAGE is specified as one of local, staging or production.
    • If local is specified, the container obtains and renews self-signed certificates.
    • If staging is specified, the container obtains and renews Let's Encrypt certificates for testing.
    • If production is specified, the container obtains and renews Let's Encrypt certificates for publishing.
  • CLIENT_MAX_BODY_SIZE: See client_max_body_size at http://nginx.org/en/docs/http/ngx_http_core_module.html#client_max_body_size⁠

⁠Volumes

⁠/certificates/

Obtained certificates are placed at /certificates/STAGE/domain/ in the container.

⁠Example

  1. Run docker-compose
    docker-compose up --build -d
    
    with the following docker-compose.yml.
    version: '3'
    
    services: 
       reverse_proxy:
          container_name: 'reverse_proxy'
          image: 'jumpaku/nginx-letsencrypt-reverse-proxy'
          ports: 
                - '80:80'
                - '443:443'
          environment: 
                - "RENEW_SCHED="
                - "STAGE=local"
                #- "STAGE=staging"
                #- "STAGE=production"
                - "DOMAINS=sub0.example.com, sub1.example.com -> http://othello:8080"
          volumes: 
                - "./certificates:/certificates"
       othello:
          container_name: 'othello'
          image: 'jumpaku/jumpaku-othello'
    
  2. Enter the container reverse_proxy.
    docker-compose exec reverse_proxy bash
    
  3. Try the following requests.
    curl http://localhost
    # => fails
    
    curl -k https://localhost
    # => fails
    
    curl -H 'Host: sub0.example.com' http://localhost
    # => 301
    
    curl -k -H 'Host: sub0.example.com' https://localhost
    # => 204
    
    curl -H 'Host: sub1.example.com' http://localhost
    # => 301
    
    curl -k -H 'Host: sub1.example.com' https://localhost
    # => 200
    
  4. Check obtained certificates at ./certificates/ in host machine.

Tag summary

Content type

Image

Digest

Size

85.6 MB

Last updated

about 6 years ago

docker pull jumpaku/nginx-letsencrypt-reverse-proxy