Tomcat that automatically fetches certificates via letsencrypt
2.4K
Showcase Tomcat Docker Image that automatically fetches and renews certificates via letsencrypt.
Uses
Try out by running examples.
The building blocks are conveniently packaged into a docker image: schnatterer/letsencrypt-tomcat.
This image is neither intended to be used as base image nor to be run itself.
It's a mere container were you can copy the components needed for your app.
It contains the following directories:
/letsencrypt necessary for all apps:
dehydrated for cert retrivaldumb-init for properly handling your main process and the certificate processmeta-entrypoint.sh for launching the processes[/tomcat-reloading-connector](https://github.com/schnatterer/tomcat-reloading-connector) necessary for standalone
tomcat instances, so they can reload the certificate at runtime/lib - pre-compiled version of Apache Portable Runtime (APR) and JNI wrappers for APR used by Tomcat (libtcnative).So in your Dockerfile just copy what you need as shown in examples. For the whole process to work, your container requires the following packages:
Your tomcat server must be configured to
/static/.well-known/acme-challenge on http://${DOMAIN}/static/.well-known/acme-challenge
in order for to be able to answer to the letsencrypt challenges,http://localhost:${LOCAL_HTTP_PORT}/ (default port 8080).If successful, the certificate files will be stored here:
/certs/${DOMAIN}/cert.pem/certs/${DOMAIN}/privkey.pem/certs/${DOMAIN}/fullchain.pemDOMAIN that passes the TLD to be used for requesting certificates forLOCAL_HTTP_PORT - (default 8080). Once this (internal) port is ready to receive traffic, the certificate challenge will begin.STAGING - If set to true creates certs against letsencrypt staging, which has no rate limit but
is not accepted by your browser.ENABLE_LETSENCRYPT - if set to false the letsencrypt process is not startedCREATE_SELFSIGNED - if set to false no selfsigned certifcate is generated at start up.CERT_DIR (default: /certs/), so you might want to
persist this folder.First, make sure to set the DNS record to match your IP address and that port 80 and 443 are available.
Note that:
-v... Persists your cert in a volume certs if left out an anonymous volume is usedsudo docker run --rm -it \
-p80:8080 -p443:8443 \
-eDOMAIN=example.com \
-v certs:/certs/ \
-eSTAGING=true \
schnatterer/letsencrypt-tomcat:standalone
# or
# schnatterer/letsencrypt-tomcat:spring-boot
# schnatterer/letsencrypt-tomcat:embedded-tomcat
# First build the base image ( packages the building blocks for letsencrypt tomcat)
docker build -t schnatterer/letsencrypt-tomcat .
# Build the examples
docker build -t schnatterer/letsencrypt-tomcat:standalone --file=examples/standalone/Dockerfile .
docker build -t schnatterer/letsencrypt-tomcat:spring-boot --file=examples/spring-boot/Dockerfile .
docker build -t schnatterer/letsencrypt-tomcat:embedded-tomcat --file=examples/embedded-tomcat/Dockerfile .
Content type
Image
Digest
Size
958.1 kB
Last updated
over 5 years ago
docker pull schnatterer/letsencrypt-tomcat