A Certbot DNS authenticator plugin for ArvanCloud, plus a prebuilt Docker image on Docker Hub.
It automates the ACME dns-01 challenge by creating and deleting
_acme-challenge TXT records through the ArvanCloud API, so you can obtain
wildcard certificates (*.example.com) from Let's Encrypt — with the API
key passed inline (no credentials file required).
.
├── Dockerfile # builds certbot + this plugin into one image
├── certbot-dns-arvancloud/ # the pip-installable plugin package
│ ├── pyproject.toml
│ └── certbot_dns_arvancloud/
└── LICENSE
docker pull s4l3h1/certbot-dns-arvancloud
Or build it yourself from this repo — the build fails if the plugin doesn't register, so a successful build means it's ready:
docker build -t s4l3h1/certbot-dns-arvancloud .
Either way you do this once; reuse the image for every certificate.
docker run --rm -v "$PWD/certs:/etc/letsencrypt" s4l3h1/certbot-dns-arvancloud certonly \
--authenticator dns-arvancloud \
--dns-arvancloud-api-key 'YOUR_ARVAN_API_KEY' \
--dns-arvancloud-propagation-seconds 60 \
--agree-tos --register-unsafely-without-email --non-interactive \
-d example.com -d '*.example.com'
That's it. The PEM files appear on the host at:
./certs/live/example.com/
fullchain.pem # server certificate (cert + chain)
privkey.pem # private key
cert.pem # leaf certificate only
chain.pem # intermediate chain only
Notes:
-v "$PWD/certs:/etc/letsencrypt" mount is how you retrieve the cert.
Without it the certificate is created inside the container and thrown away by
--rm. (It's a volume, not a config file — no arvan.ini needed.)sudo or sudo chown them.--dry-run to rehearse against Let's Encrypt staging without issuing a
real cert (and without using rate limits).--register-unsafely-without-email with
-m [email protected].Renewal is fully unattended. Certbot saved the authenticator and API key in the renewal config, so just run:
docker run --rm -v "$PWD/certs:/etc/letsencrypt" s4l3h1/certbot-dns-arvancloud renew
Let's Encrypt certs last 90 days; run this on a schedule (~every 60 days). It renews only what's near expiry.
Security note: an inline
--dns-arvancloud-api-keyis visible in your shell history and inpswhile the container runs, and Certbot saves it in plaintext incerts/renewal/<domain>.conf(that's what makes unattendedrenewwork). On a shared host, prefer the credentials-file alternative below or inject the key from a secret manager.
| Flag | Description |
|---|---|
--authenticator dns-arvancloud | Select this plugin. |
--dns-arvancloud-api-key | ArvanCloud API key (token), passed inline. |
--dns-arvancloud-credentials | Path to an INI credentials file (alternative to the inline key). |
--dns-arvancloud-propagation-seconds | Seconds to wait for DNS to propagate before validation. Default 60. Raise it if validation fails intermittently. |
If you'd rather not pass the key inline, put it in an INI file (token only — the
plugin adds the apikey prefix), chmod 600 it, and mount it:
# arvan.ini
dns_arvancloud_api_key = YOUR_ARVAN_API_KEY
docker run --rm \
-v "$PWD/certs:/etc/letsencrypt" \
-v "$PWD/arvan.ini:/arvan.ini:ro" \
s4l3h1/certbot-dns-arvancloud certonly \
--authenticator dns-arvancloud \
--dns-arvancloud-credentials /arvan.ini \
--dns-arvancloud-propagation-seconds 60 \
--agree-tos --register-unsafely-without-email --non-interactive \
-d example.com -d '*.example.com'
pip install certbot ./certbot-dns-arvancloud
certbot certonly \
--authenticator dns-arvancloud \
--dns-arvancloud-api-key 'YOUR_ARVAN_API_KEY' \
--dns-arvancloud-propagation-seconds 60 \
-d example.com -d '*.example.com'
GET /cdn/4.0/domains/{zone} and uses the longest that exists,
so apex domains and subdomains both work.POST /cdn/4.0/domains/{zone}/dns-records with a TXT record.User-Agent, because ArvanCloud's edge
rejects bot-like agents (curl, python-requests) with a 403.MIT.
Content type
Image
Digest
sha256:8979ef4a2…
Size
89.1 MB
Last updated
5 months ago
docker pull s4l3h1/certbot-dns-arvancloud