certbot with the OVH plugin to generate & renew SSL certificates
379
See source : https://github.com/pifou25/docker-jeedom/tree/master/certbot
C'est un script python, le container docker installe les dépendances nécessaires et lance le script.
voir le tuto https://buzut.net/certbot-challenge-dns-ovh-wildcard/
il faut avoir son nom de domaine chez OVH, on peut utiliser un jocker (wildcard) ou pas, ouvrir les accès
à l'API OVH, générer un fichier .ovhapi dans ce répertoire avec les tocken de ces accès
(doc du plugin ovh)[https://certbot-dns-ovh.readthedocs.io/en/stable/]
Dans le répertoire /certbot: valoriser la variable DOMAIN puis lancer docker-compose dans la même ligne:
DOMAIN=my.domaine.com docker-compose up
Dans une stack existante, lancer ce service périodiquement pour renouveler les certificats enregistrés dans le répertoire /letsencrypt
docker build -t certbot .
docker run --name certbot -v /etc/letsencrypt:/etc/letsencrypt certbot
Renouveler le bail: utilise la même image, surcharge la commande: docker run image commande...
# ce script trouve parfaitement sa place dans /usr/local/sbin/renewCerts.sh
#!/bin/bash
docker run certbot certbot certonly --dns-ovh --dns-ovh-credentials /root/.ovhapi --non-interactive --agree-tos --email [email protected] -d buzut.fr
docker run certbot certbot certonly --dns-ovh --dns-ovh-credentials /root/.ovhapi --non-interactive --agree-tos --email [email protected] -d *.buzut.fr
Content type
Image
Digest
Size
341 MB
Last updated
over 6 years ago
docker pull pifou25/certbot