Note: This container is automatically built by docker-image-rebuilder every night and will receive updates whenever the upstream NGINX, Certbot or Alpine packages change. (Dockerfile)
docker-composeFirst, create add one of the following in a new or existing docker-compose.yml file, depending on whether you want to run the container as root.
Supports running as user container using some extra configuration:
version: '2.3'
services:
http:
image: ntninja/nginx-autotls
user: "<uid>:<gid>"
sysctls:
- net.ipv4.ip_unprivileged_port_start=80
expose:
- 80
- 443
environment:
- CERTBOT_AGREE_TOS=y # By setting this you agree to Let's Encrypt TOS
- CERTBOT_EMAIL=<contact-address>
volumes:
- type: volume
source: nginx-cache
target: "/var/cache/nginx"
- type: volume
source: nginx-cache
target: "/var/tmp/nginx"
- type: bind
source: "./nginx-data"
target: "/data"
volumes:
nginx-cache:
driver_opts:
type: tmpfs
device: tmpfs
o: size=100m,uid=<uid>,gid=<gid>
Running as root is easier but grants unnecessary extra privileges to the container image:
version: '2.3'
services:
http:
image: ntninja/nginx-autotls
expose:
- 80
- 443
environment:
- CERTBOT_AGREE_TOS=y # By setting this you agree to Let's Encrypt TOS
- CERTBOT_EMAIL=<contact-address>
volumes:
- type: bind
source: "./nginx-data"
target: "/data"
Second, ensure that the mentioned nginx-data directory exists: mkdir -p nginx-data and that it is owned by the container user when not running as root: chown <uid>:<gid> nginx-data
Third, run the container once to copy the initial configuration: docker-compose run http – it will print an error (No names were found in your configuration files.), but don't worry!
Fourth, edit nginx-data/nginx/conf.d/default.conf to add your nginx configuration:
# HTTP server – Required for certificate verification
server {
listen 80 default_server;
listen [::]:80 default_server;
# HTTPS redirect – keep this unless you want to serve some other HTTP-only content
location / {
return 301 https://$host$request_uri;
}
}
# Main HTTPS Server
server {
listen 443 default_server ssl http2;
listen [::]:443 default_server ssl http2;
# List all server names here, they are used to determine which names the certificate should be valid for
server_name <domain-name>[ <domain-name>[ …]];
# Some recommended security headers that you should consider sending
# Description of what these mean: https://owasp.org/www-project-secure-headers/ (read before enabling each of these!)
#add_header "Expect-CT" "enforce, max-age=30" always;
#add_header "Referrer-Policy" "strict-origin" always;
#add_header "X-XSS-Protection" "1; mode=block" always;
#add_header "X-Content-Type-Options" "nosniff" always;
#add_header "Strict-Transport-Security" "max-age=31536000; includeSubDomains; preload" always;
# … add main site content here …
}
Now start the server with docker-compose up and it should work if everything is correctly set up, otherwise the bundled certbot will hopefully tell you what went wrong.
Content type
Image
Digest
sha256:5ca9f4411…
Size
24.2 MB
Last updated
over 2 years ago
docker pull ntninja/nginx-autotls