Sign inSign up

s4l3h1/certbot-dns-arvancloud

By s4l3h1

•Updated 5 months ago

Image
0

950

s4l3h1/certbot-dns-arvancloud repository overview

⁠certbot-dns-arvancloud

A Certbot⁠ DNS authenticator plugin for ArvanCloud⁠, plus a prebuilt Docker image on Docker Hub⁠.

It automates the ACME dns-01 challenge by creating and deleting _acme-challenge TXT records through the ArvanCloud API, so you can obtain wildcard certificates (*.example.com) from Let's Encrypt — with the API key passed inline (no credentials file required).

.
├── Dockerfile                 # builds certbot + this plugin into one image
├── certbot-dns-arvancloud/    # the pip-installable plugin package
│   ├── pyproject.toml
│   └── certbot_dns_arvancloud/
└── LICENSE

⁠Get the image (once)

docker pull s4l3h1/certbot-dns-arvancloud

Or build it yourself from this repo — the build fails if the plugin doesn't register, so a successful build means it's ready:

docker build -t s4l3h1/certbot-dns-arvancloud .

Either way you do this once; reuse the image for every certificate.

⁠Get a wildcard certificate (one command)

docker run --rm -v "$PWD/certs:/etc/letsencrypt" s4l3h1/certbot-dns-arvancloud certonly \
  --authenticator dns-arvancloud \
  --dns-arvancloud-api-key 'YOUR_ARVAN_API_KEY' \
  --dns-arvancloud-propagation-seconds 60 \
  --agree-tos --register-unsafely-without-email --non-interactive \
  -d example.com -d '*.example.com'

That's it. The PEM files appear on the host at:

./certs/live/example.com/
    fullchain.pem   # server certificate (cert + chain)
    privkey.pem     # private key
    cert.pem        # leaf certificate only
    chain.pem       # intermediate chain only

Notes:

  • The -v "$PWD/certs:/etc/letsencrypt" mount is how you retrieve the cert. Without it the certificate is created inside the container and thrown away by --rm. (It's a volume, not a config file — no arvan.ini needed.)
  • Files are written as root; read them with sudo or sudo chown them.
  • Add --dry-run to rehearse against Let's Encrypt staging without issuing a real cert (and without using rate limits).
  • Want expiry emails? Replace --register-unsafely-without-email with -m [email protected].

⁠Renew

Renewal is fully unattended. Certbot saved the authenticator and API key in the renewal config, so just run:

docker run --rm -v "$PWD/certs:/etc/letsencrypt" s4l3h1/certbot-dns-arvancloud renew

Let's Encrypt certs last 90 days; run this on a schedule (~every 60 days). It renews only what's near expiry.

Security note: an inline --dns-arvancloud-api-key is visible in your shell history and in ps while the container runs, and Certbot saves it in plaintext in certs/renewal/<domain>.conf (that's what makes unattended renew work). On a shared host, prefer the credentials-file alternative below or inject the key from a secret manager.


⁠Options

FlagDescription
--authenticator dns-arvancloudSelect this plugin.
--dns-arvancloud-api-keyArvanCloud API key (token), passed inline.
--dns-arvancloud-credentialsPath to an INI credentials file (alternative to the inline key).
--dns-arvancloud-propagation-secondsSeconds to wait for DNS to propagate before validation. Default 60. Raise it if validation fails intermittently.
⁠Credentials file alternative

If you'd rather not pass the key inline, put it in an INI file (token only — the plugin adds the apikey prefix), chmod 600 it, and mount it:

# arvan.ini
dns_arvancloud_api_key = YOUR_ARVAN_API_KEY
docker run --rm \
  -v "$PWD/certs:/etc/letsencrypt" \
  -v "$PWD/arvan.ini:/arvan.ini:ro" \
  s4l3h1/certbot-dns-arvancloud certonly \
    --authenticator dns-arvancloud \
    --dns-arvancloud-credentials /arvan.ini \
    --dns-arvancloud-propagation-seconds 60 \
    --agree-tos --register-unsafely-without-email --non-interactive \
    -d example.com -d '*.example.com'

⁠Without Docker (plain pip)

pip install certbot ./certbot-dns-arvancloud

certbot certonly \
  --authenticator dns-arvancloud \
  --dns-arvancloud-api-key 'YOUR_ARVAN_API_KEY' \
  --dns-arvancloud-propagation-seconds 60 \
  -d example.com -d '*.example.com'

⁠How it works

  • Zone discovery — probes progressively shorter suffixes of the challenge name against GET /cdn/4.0/domains/{zone} and uses the longest that exists, so apex domains and subdomains both work.
  • Create — POST /cdn/4.0/domains/{zone}/dns-records with a TXT record.
  • Cleanup — finds the matching TXT record (by name and value) and deletes it by id, leaving any other TXT records untouched.
  • The client sends a browser-style User-Agent, because ArvanCloud's edge rejects bot-like agents (curl, python-requests) with a 403.

⁠License

MIT⁠.

Tag summary

Content type

Image

Digest

sha256:8979ef4a2…

Size

89.1 MB

Last updated

5 months ago

docker pull s4l3h1/certbot-dns-arvancloud