Internal private CA services for containers
3.1K
My very customized serverless certificate authority, designed to support backend cloud communication s with auto generated certificates for your apps and users. By design, the private certificates rema in in volitile storage in the container, and is only run to generate new certificates. Essentially a cts as an on demand certificate authority for authenticating your apps and users without exposing a certificate service to the network directly.
Export container volumes ["/etc/ssl", "/ca", "/nginx", "/web"] for state retention, otherwise the root ca and keys are lost when container is destroyed. BE AWARE. Configured for Securing Labs, set your own environment names to customize on launch like this. . . ENV LOCALAZ=east1 MYDOM=seclab.cloud MYORG="Securing Labs" MYUNIT="Public Cloud"
CA commands: initca - generate a new CA with root and signing keys. Default action if ENV is set destroyca - does what it says, erases everything and exits nginx-restore - if you have /nginx folder mounted it will create a default example config with certificate information showsubj - shows the details of a certificate you specify to read trustdomain - generates a certificate for the domain specified in ca/ and nginx/ if mounted trustuser - creates a user certificate from the CA trust that can be imported into your browser for authentication
mount shared storage in /ca for certs and /web for user and root chain export to nginx mounting your /etc/nginx/ to /nginx will facilitate cert updates as generated.
EXAMPLE RUNTIME SCRIPT:
#!/bin/bash
buildobj="kellman/microca"
buildstage="latest"
echo "$0 $@"
docker pull ${buildobj}:${buildstage}
LOCALAZ="mymac"
MYDOM="gwfor.me"
MYORG="Gateway In The Sky"
MYUNIT="Public Cloud"
if [ -z "$1" ] ; then
docker run --rm -h myca --name myca -v $PWD/ssl:/etc/ssl -v $PWD/web:/web -e LOCALAZ="$LOCALAZ" -e MYDOM="$MYDOM" -e MYORG="$MYORG" -e MYUNIT="$MYUNIT" -it ${buildobj}:${buildstage}
elif [ -z "$2" ] ; then
docker run --rm -h myca --name myca -v $PWD/ca:/ca -v $PWD/ssl:/etc/ssl -v $PWD/web:/web -e LOCALAZ="$LOCALAZ" -e MYDOM="$MYDOM" -e MYORG="$MYORG" -e MYUNIT="$MYUNIT" -it ${buildobj}:${buildstage} "$1"
else
docker run --rm -h myca --name myca -v $PWD/ca:/ca -v $PWD/ssl:/etc/ssl -v $PWD/web:/web -e LOCALAZ="$LOCALAZ" -e MYDOM="$MYDOM" -e MYORG="$MYORG" -e MYUNIT="$MYUNIT" -it ${buildobj}:${buildstage} "$1" "$2"
fi
Content type
Image
Digest
Size
7 MB
Last updated
over 6 years ago
docker pull kellman/microca