Same as ebarault/letsencrypt-autorenew-docker, with latest crontab
1.0K
Available on dockerhub here.
This image runs certbot under the hood to automate issuance and renewal of letsencrypt certificates.
Initial certificate requests are run at container first launch, once the image responds on a specified health check url.
Then certificates validity is checked at 02:00 on every 7th day-of-month from 1 through 31, and certificates are renewed only if expiring in less that 28 days, preventing from being rate limited by letsencrypt.
Issued certificates are made available in the container's /certs directory which can be mounted on the docker host or as a docker volume to make them available to other applications.
Adapt the provided docker-compose.yml file to fit your requirements. The required/optional parameters are described here after:
ebarault/letsencrypt-autorenew-dockerThe software in the docker container exposes internally the 443 port, which you should expose back on the docker host with no translation, such as in "443:443"
The following volumes of interest can be mounted on the docker host or as docker volumes:
standalone) A certbot plugin to use (e.g. manual)certbot command-line options (e.g. --redirect), refer to certbot documentationmy.domain.comsub.domain1.com,sub.domain2.commy.other.domain.com sub.domain1.com,sub.domain2.comAs in the provided docker-compose.yml file, the expected configuration should look similar to this:
version: '2'
services:
certbot:
build: .
# image: ebarault/letsencrypt-autorenew-docker:latest
container_name: certbot
ports:
- "443:443"
volumes:
- ./certs:/certs
- ./letsencrypt:/etc/letsencrypt
- ./var_log_letsencrypt:/var/log/letsencrypt
restart: always
environment:
# - WEBROOT=/path/to/web_root
- LOGFILE=/var/log/letsencrypt/certrenewal.log
- DEBUG=false
- STAGING=false
- DOMAINS=my.domain.com
- [email protected]
- CONCAT=false
- HEALTH_CHECK_URL=my.domain.com:80
When using a docker logging driver, the LOGFILE environment variable should not be set to make sure all the container logs (stdout/stderr) are directed to the console, and hence to the logging driver.
An example is provided for aws logging driver. This should be
version: '2'
services:
certbot:
# ...
environment:
# ...
# LOGFILE should not be set when working with a docker logging driver
# - LOGFILE=/var/log/letsencrypt/certrenewal.log
logging:
driver: "awslogs"
options:
awslogs-region: "${AWS_REGION}"
awslogs-group: "hooly-search"
awslogs-stream: "letsencrypt"
Build and run the container as follows:
docker-compose build
docker-compose up -d
docker-compose up -d
Content type
Image
Digest
Size
35.9 MB
Last updated
about 5 years ago
docker pull kfir/letsencrypt-autorenew-docker