Sign inSign up

ntninja/nginx-autotls

By ntninja

•Updated over 2 years ago

Image
0

937

ntninja/nginx-autotls repository overview

Note: This container is automatically built by docker-image-rebuilder⁠ every night and will receive updates whenever the upstream NGINX, Certbot or Alpine packages change. (Dockerfile)⁠

⁠NGINX with automatic TLS configuration

⁠Setup: Using docker-compose

First, create add one of the following in a new or existing docker-compose.yml file, depending on whether you want to run the container as root.

Supports running as user container using some extra configuration:

version: '2.3'

services:
  http:
    image: ntninja/nginx-autotls
    user: "<uid>:<gid>"
    sysctls:
     - net.ipv4.ip_unprivileged_port_start=80
    expose:
     - 80
     - 443
    environment:
     - CERTBOT_AGREE_TOS=y  # By setting this you agree to Let's Encrypt TOS
     - CERTBOT_EMAIL=<contact-address>
    volumes:
     - type: volume
       source: nginx-cache
       target: "/var/cache/nginx"
     - type: volume
       source: nginx-cache
       target: "/var/tmp/nginx"
     - type: bind
       source: "./nginx-data"
       target: "/data"

volumes:
  nginx-cache:
    driver_opts:
      type: tmpfs
      device: tmpfs
      o: size=100m,uid=<uid>,gid=<gid>

Running as root is easier but grants unnecessary extra privileges to the container image:

version: '2.3'

services:
  http:
    image: ntninja/nginx-autotls
    expose:
     - 80
     - 443
    environment:
     - CERTBOT_AGREE_TOS=y  # By setting this you agree to Let's Encrypt TOS
     - CERTBOT_EMAIL=<contact-address>
    volumes:
     - type: bind
       source: "./nginx-data"
       target: "/data"

Second, ensure that the mentioned nginx-data directory exists: mkdir -p nginx-data and that it is owned by the container user when not running as root: chown <uid>:<gid> nginx-data

Third, run the container once to copy the initial configuration: docker-compose run http – it will print an error (No names were found in your configuration files.), but don't worry!

Fourth, edit nginx-data/nginx/conf.d/default.conf to add your nginx configuration:

# HTTP server – Required for certificate verification
server {
	listen 80 default_server;
	listen [::]:80 default_server;
	
	# HTTPS redirect – keep this unless you want to serve some other HTTP-only content
	location / {
		return 301 https://$host$request_uri;
	}
}

# Main HTTPS Server
server {
	listen 443 default_server ssl http2;
	listen [::]:443 default_server ssl http2;
	
	# List all server names here, they are used to determine which names the certificate should be valid for
	server_name <domain-name>[ <domain-name>[ …]];
	
	# Some recommended security headers that you should consider sending
	# Description of what these mean: https://owasp.org/www-project-secure-headers/ (read before enabling each of these!)
	#add_header "Expect-CT" "enforce, max-age=30" always;
	#add_header "Referrer-Policy" "strict-origin" always;
	#add_header "X-XSS-Protection" "1; mode=block" always;
	#add_header "X-Content-Type-Options" "nosniff" always;
	#add_header "Strict-Transport-Security" "max-age=31536000; includeSubDomains; preload" always;
	
	# … add main site content here …
}

Now start the server with docker-compose up and it should work if everything is correctly set up, otherwise the bundled certbot will hopefully tell you what went wrong.

Tag summary

Content type

Image

Digest

sha256:5ca9f4411…

Size

24.2 MB

Last updated

over 2 years ago

docker pull ntninja/nginx-autotls