Sign inSign up

stevecorya/agassi

By stevecorya

•Updated about 3 years ago

Dominate the server (ingress proxy)

Image
0

2.8K

stevecorya/agassi repository overview

CodeFactor Grade

⁠Agassi

Agassi is inspired by the setup detailed at Docker Swarm Rocks⁠. When Traefik dropped support for distributed certificate storage, it created a situation all certificates were stored locally on a single machine. This removed redundency from the setup.

Taking advantage of etcd and Docker Swarm's built-in state management, Agassi is able to run without the use of generative templates. Each agassi service is mapped to a virtual host, which are created by the client and retrieved by the server.

By using Agassi, you are accepting the Let's Encrypt Subscriber Agreement⁠.

⁠Configuration

ENVARDetailDefault
AGASSI_ACME_ACCOUNT_KEY_FILEthe path to the key to the ACME account
AGASSI_ACME_PRODUCTIONif set to any value, fetch certificates from production Let's Encrypt
AGASSI_ACME_TIMEOUTseconds before fetching the certificate times out30
AGASSI_AUTH_REALMthe realm to use from basic authenticationAgassi
AGASSI_CPANEL_API_TOKEN_FILEthe path to the cPanel API token
AGASSI_CPANEL_SERVERthe base URL for the cpanel endpoint
AGASSI_CPANEL_USERNAMEthe username to log in to cPanel
AGASSI_DEFAULT_KEY_FILEthe path to the default key used for signing certificates
AGASSI_DNS_TTLthe time to live for DNS records (seconds)14400
AGASSI_DOCKER_API_VERSIONpassed to dockerode⁠v1.37
AGASSI_DOCKER_HOSTTCP socket passed to dockerodelocalhost
AGASSI_DOCKER_PORTTCP port passed to dockerode2375
AGASSS_ETCD_HOSTScomma-seperated array of strings of etcd3 hostshttp://localhost:2379⁠
AGASSI_EXPIRATION_THRESHOLDdays before certificate expires to renew45
AGASSI_LABEL_PREFIXlabel prefix to define virtual hostspage.agassi.
AGASSI_LETS_ENCRYPT_EMAILemail address used to send certificate renewal notifications
AGASSI_LOG_LEVELtrace, debug, info, warn, error, fatalinfo
AGASSI_MAINTENANCE_INTERVALhow often to prune services and update certificates (hours)12
AGASSI_TARGET_CNAME*cname value to which DNS records point

* this must end with a dot, e.g., subdomain.example.com.

⁠Labels

  • page.agassi.domain set to your target domain e.g. example.com
  • page.agassi.auth see Authorization⁠ for how to generate an auth string
  • page.agassi.options.target the service access address for example http://myservice:80 All options prefixed with page.agassi.options. are camel-cased (set prependPath with the label page.agassi.opts.prepend-path) and passed to node-http-proxy⁠. Pass the labels into your swarm compose file.
services:
  service-01:
    image:
    deploy:
      labels:
        page.agassi.domain: example.com
        page.agassi.options.target: http://service-01:80

⁠Flow

Agassi requires the use of two seperate services, a client (ACME, etcd, and docker) and a server (HTTPS).

⁠Client

Client spins up.

Client checks for existing services and makes sure certificates are current.

Client subscribes to new service updates.

⁠Server

Server spins up.

Starts listening to HTTPS requests.

⁠Authorization

To generate a basic auth parameter:

echo $(htpasswd -n -B -C 4 user | base64 -w 0)

To generate a default and ACME account key

openssl genrsa 4096 | docker secret create my_key -

Tag summary

Content type

Image

Digest

sha256:0d4d2349d…

Size

397.4 MB

Last updated

about 3 years ago

docker pull stevecorya/agassi