Sign inSign up

kellman/microca

By kellman

•Updated over 6 years ago

Internal private CA services for containers

Image
0

3.1K

kellman/microca repository overview

⁠ORCA

⁠Private CA container

My very customized serverless certificate authority, designed to support backend cloud communication s with auto generated certificates for your apps and users. By design, the private certificates rema in in volitile storage in the container, and is only run to generate new certificates. Essentially a cts as an on demand certificate authority for authenticating your apps and users without exposing a certificate service to the network directly.

Export container volumes ["/etc/ssl", "/ca", "/nginx", "/web"] for state retention, otherwise the root ca and keys are lost when container is destroyed. BE AWARE. Configured for Securing Labs, set your own environment names to customize on launch like this. . . ENV LOCALAZ=east1 MYDOM=seclab.cloud MYORG="Securing Labs" MYUNIT="Public Cloud"

CA commands: initca - generate a new CA with root and signing keys. Default action if ENV is set destroyca - does what it says, erases everything and exits nginx-restore - if you have /nginx folder mounted it will create a default example config with certificate information showsubj - shows the details of a certificate you specify to read trustdomain - generates a certificate for the domain specified in ca/ and nginx/ if mounted trustuser - creates a user certificate from the CA trust that can be imported into your browser for authentication

mount shared storage in /ca for certs and /web for user and root chain export to nginx mounting your /etc/nginx/ to /nginx will facilitate cert updates as generated.

EXAMPLE RUNTIME SCRIPT:

#!/bin/bash
buildobj="kellman/microca"
buildstage="latest"

echo "$0 $@"
docker pull ${buildobj}:${buildstage}

LOCALAZ="mymac" 
MYDOM="gwfor.me" 
MYORG="Gateway In The Sky" 
MYUNIT="Public Cloud"

if [ -z "$1" ] ; then
    docker run --rm -h myca --name myca -v $PWD/ssl:/etc/ssl -v $PWD/web:/web -e LOCALAZ="$LOCALAZ" -e MYDOM="$MYDOM" -e MYORG="$MYORG" -e MYUNIT="$MYUNIT" -it ${buildobj}:${buildstage}

elif [ -z "$2" ] ; then
    docker run --rm -h myca --name myca -v $PWD/ca:/ca -v $PWD/ssl:/etc/ssl -v $PWD/web:/web -e LOCALAZ="$LOCALAZ" -e MYDOM="$MYDOM" -e MYORG="$MYORG" -e MYUNIT="$MYUNIT" -it ${buildobj}:${buildstage} "$1"
else
    docker run --rm -h myca --name myca -v $PWD/ca:/ca -v $PWD/ssl:/etc/ssl -v $PWD/web:/web -e LOCALAZ="$LOCALAZ" -e MYDOM="$MYDOM" -e MYORG="$MYORG" -e MYUNIT="$MYUNIT" -it ${buildobj}:${buildstage} "$1" "$2"
fi

Tag summary

Content type

Image

Digest

Size

7 MB

Last updated

over 6 years ago

docker pull kellman/microca