# lets‑encrypt
> Go‑based Let's Encrypt ACME certificate management service, support Cloudflare DNS‑01 challenge, auto‑renew certificate, operate docker api to reload nginx config, built‑in SQLite storage, HTTP API.
GitHub: https://github.com/kouleen/lets‑encrypt
## Features
- ✅ ACME protocol, obtain / renew Let's Encrypt SSL certificate (DNS‑01 challenge for wildcard domain)
- ✅ Cloudflare DNS provider, use Cloudflare API Token to complete domain ownership verification
- ✅ Built‑in SQLite persistent storage, record certificate status, expire time, remaining days, error logs
- ✅ Built‑in HTTP API service(8099 port), manage certificate via REST interface
- ✅ Docker SDK integration: execute `docker exec` inside container, reload nginx config after certificate issued
- ✅ Mail notification: send verify / expire warning email by SMTP
- ✅ Certificate file persistence, output pem cert file to host directory for nginx using
- ✅ Check remote website certificate expire status
## Image Pull
```bash
docker pull kouleen/lets‑encrypt:latest
⚠️Important: Must mount
/var/run/docker.sockto allow container call host docker api.
docker run -d --name lets-encrypt \
-p 8099:8099 \
-v /home/nginx/certs:/app/nginx/certs \
-v /var/run/docker.sock:/var/run/docker.sock \
-e SEND_EMAIL="your‑sender‑[email protected]" \
-e SEND_PWD="qq‑smtp‑auth‑code" \
-e SMTP_SERVER="smtp.qq.com" \
-e SMTP_PORT="587" \
kouleen/lets‑encrypt:latest
| Env | Required | Description |
|---|---|---|
SEND_EMAIL | Yes | SMTP sender email address |
SEND_PWD | Yes | SMTP password / authorization code |
SMTP_SERVER | Yes | SMTP server host, e.g smtp.qq.com |
SMTP_PORT | Yes | SMTP port, 587 for STARTTLS |
/home/nginx/certs:/app/nginx/certsCertificate output directory, bundle pem & private key will save here, nginx read cert from host path.
/var/run/docker.sock:/var/run/docker.sockRequired! For call host docker api, execute
docker execreload nginx container config.
8099/tcp: HTTP api service portService start, visit http://127.0.0.1:8099 for api entry.
*.pem file to mount directorynginx -t && nginx -s reload refresh ssl configCreate Cloudflare API Token, must grant permissions:
Token must belong to the account where your domain is hosted.
*.example.com) only support DNS‑01 challenge./var/run/docker.sock mount gives high permission, do careful security consideration.docker logs -f lets‑encrypt
docker stop lets‑encrypt
docker rm lets‑encrypt
zone could not be found: Cloudflare token permission insufficient or domain not under this cloudflare account./var/run/docker.sock.nginx -t inside nginx container.GitHub: https://github.com/kouleen/lets-encrypt
Content type
Image
Digest
sha256:c326292bb…
Size
24.4 MB
Last updated
about 2 months ago
docker pull kouleen/lets-encrypt