Sign inSign up

kouleen/lets-encrypt

By kouleen

•Updated about 2 months ago

Image
0

640

kouleen/lets-encrypt repository overview

# lets‑encrypt
> Go‑based Let's Encrypt ACME certificate management service, support Cloudflare DNS‑01 challenge, auto‑renew certificate, operate docker api to reload nginx config, built‑in SQLite storage, HTTP API.

GitHub: https://github.com/kouleen/lets‑encrypt

## Features
- ✅ ACME protocol, obtain / renew Let's Encrypt SSL certificate (DNS‑01 challenge for wildcard domain)
- ✅ Cloudflare DNS provider, use Cloudflare API Token to complete domain ownership verification
- ✅ Built‑in SQLite persistent storage, record certificate status, expire time, remaining days, error logs
- ✅ Built‑in HTTP API service(8099 port), manage certificate via REST interface
- ✅ Docker SDK integration: execute `docker exec` inside container, reload nginx config after certificate issued
- ✅ Mail notification: send verify / expire warning email by SMTP
- ✅ Certificate file persistence, output pem cert file to host directory for nginx using
- ✅ Check remote website certificate expire status

## Image Pull
```bash
docker pull kouleen/lets‑encrypt:latest

⁠Quick Start Run

⚠️Important: Must mount /var/run/docker.sock to allow container call host docker api.

docker run -d --name lets-encrypt \
  -p 8099:8099 \
  -v /home/nginx/certs:/app/nginx/certs \
  -v /var/run/docker.sock:/var/run/docker.sock \
  -e SEND_EMAIL="your‑sender‑[email protected]" \
  -e SEND_PWD="qq‑smtp‑auth‑code" \
  -e SMTP_SERVER="smtp.qq.com" \
  -e SMTP_PORT="587" \
  kouleen/lets‑encrypt:latest
⁠Environment Variables
EnvRequiredDescription
SEND_EMAILYesSMTP sender email address
SEND_PWDYesSMTP password / authorization code
SMTP_SERVERYesSMTP server host, e.g smtp.qq.com
SMTP_PORTYesSMTP port, 587 for STARTTLS

⁠Volume Mount

  1. /home/nginx/certs:/app/nginx/certs

Certificate output directory, bundle pem & private key will save here, nginx read cert from host path.

  1. /var/run/docker.sock:/var/run/docker.sock

Required! For call host docker api, execute docker exec reload nginx container config.

⁠Ports

  • 8099/tcp: HTTP api service port

⁠API Brief

Service start, visit http://127.0.0.1:8099 for api entry.

  • Create certificate task, submit domain & cloudflare api token
  • Query certificate list, status, remain days, error message
  • Check remote site ssl expire info
  • Renew certificate manually

⁠Workflow

  1. Submit domain + Cloudflare API token via HTTP API
  2. ACME apply certificate using DNS‑01 challenge, add temporary TXT record via Cloudflare API
  3. After certificate issued, write *.pem file to mount directory
  4. Call docker api, exec inside nginx container: nginx -t && nginx -s reload refresh ssl config
  5. Save task status, expire time, error log into SQLite database
  6. Send email notification when success or failure

⁠Cloudflare Token Permission Requirement

Create Cloudflare API Token, must grant permissions:

  • Zone → DNS → Edit
  • Zone → Zone → Read

Token must belong to the account where your domain is hosted.

⁠Important Notes

  1. This service use Let's Encrypt staging environment by default, change acme endpoint for production.
  2. Wildcard domain(*.example.com) only support DNS‑01 challenge.
  3. Do not expose 8099 port to public internet without auth protection.
  4. /var/run/docker.sock mount gives high permission, do careful security consideration.
  5. SQLite database file inside container, you can mount extra volume for persist db file.

⁠View Runtime Log

docker logs -f lets‑encrypt

⁠Stop & Remove

docker stop lets‑encrypt
docker rm lets‑encrypt

⁠Troubleshooting

  1. zone could not be found: Cloudflare token permission insufficient or domain not under this cloudflare account.
  2. docker client nil panic: make sure mount /var/run/docker.sock.
  3. pem file not found: certificate apply failed, check remark field for error detail.
  4. nginx reload fail: check nginx config syntax nginx -t inside nginx container.

⁠Source

GitHub: https://github.com/kouleen/lets-encrypt⁠

Tag summary

Content type

Image

Digest

sha256:c326292bb…

Size

24.4 MB

Last updated

about 2 months ago

docker pull kouleen/lets-encrypt