Sign inSign up

thebronway/domainctrl

By thebronway

•Updated 8 months ago

A Self-Hosted, Automated DDNS & SSL Certificate Manager

Image
Networking
Security
0

497

thebronway/domainctrl repository overview

⁠domainCtrl

License

⁠A Self-Hosted, Automated DDNS & SSL Certificate Manager.

domainCtrl provides a simple web dashboard to monitor and manage your domain records. It automatically updates your DNS 'A' records to match your home's dynamic public IP and uses Let's Encrypt to create and renew SSL certificates for your services.

Note: domainCtrl is in active development and should be used with caution.

Note: domainCtrl currently only supports AWS Route 53 (more providers coming soon).

⁠Try it yourself: Live Demo⁠

Current Version: v0.6
GitHub: thebronway/domainCtrl⁠
Docker Hub: thebronway/domainctrl⁠

⁠Screenshots

Desktop

Dashboard Screenshot

Settings Screenshot


Mobile
Mobile Screenshot

Mobile Screenshot

⁠Features

  • Dynamic DNS (DDNS): Automatically checks your public IP and updates DNS records if they change.
  • SSL Management: Wraps Certbot to handle creation and renewal of certificates using the DNS-01 challenge (Wildcard supported).
  • Web Dashboard: A clean, responsive UI to view the status of all your domains at a glance.
  • Settings UI: Configure domains, notifications, timezones, and log retention directly from the browser.
  • Notifications: Get alerts via Discord, Slack, Telegram, Email (SMTP), and more.
  • Mobile Friendly: Fully responsive design.

⁠Important Notes

  1. SSL Lifecycle: This app manages the full lifecycle of certificates. It can only renew certs it created. Existing certs should be replaced by ones generated here for auto-renewal.
  2. Authentication: This app has no login. You MUST run this behind a reverse proxy (Nginx, Traefik, etc.) with Basic Auth or SSO to secure the dashboard.

⁠Quick Start

⁠1. Prerequisites
  • A domain managed by a supported provider (currently only AWS Route 53).
  • API credentials with permissions to modify DNS records.
⁠2. Run with Docker
docker run -d \\
  --name domainctrl \\
  -p 8080:8080 \\
  -v $(pwd)/config:/config \\
  -v $(pwd)/certs:/certs \\
  -v $(pwd)/logs:/logs \\
  -e PROVIDER=Route53 \\
  -e AWS_ACCESS_KEY_ID="YOUR_KEY" \\
  -e AWS_SECRET_ACCESS_KEY="YOUR_SECRET" \\
  -e TZ=America/New_York \\
  --restart unless-stopped \\
  thebronway/domainctrl:latest
⁠3. Configure
  1. Open http://localhost:8080.
  2. Go to Settings.
  3. Add domains and toggle features (DDNS, SSL, Notifications).
  4. Save Changes.

⁠Volumes

VolumeDescription
/configStores settings and state. Mount to persist configuration.
/certsStores SSL certificates. Mount to share with your reverse proxy.
/logsStores application logs.

⁠Environment Variables

The application is configured primarily via the PROVIDER variable.

VariableDescriptionRequired
PROVIDERThe DNS provider to use. Currently supports: Route53.Yes
TZTimezone for logs and UI (e.g., America/New_York).No
⁠Provider-Specific Variables

If PROVIDER=Route53:

VariableDescriptionRequired
AWS_ACCESS_KEY_IDYour AWS Access Key.Yes
AWS_SECRET_ACCESS_KEYYour AWS Secret Key.Yes
⁠Optional Notification Variables

Secrets for notifications can be configured in the Settings UI or passed as environment variables.

VariableDescription
SMTP_USERUsername for SMTP authentication.
SMTP_PASSPassword for SMTP authentication.
DISCORD_WEBHOOK_URLDiscord Webhook URL.
SLACK_WEBHOOK_URLSlack Webhook URL.
TELEGRAM_URLApprise-format Telegram URL (e.g., tgram://bot_token/chat_id).
MSTEAMS_WEBHOOK_URLMicrosoft Teams Webhook URL.
PUSHOVER_URLApprise-format Pushover URL.
GCHAT_WEBHOOK_URLGoogle Chat Webhook URL.

Tag summary

Content type

Image

Digest

sha256:b4330654c…

Size

102.1 MB

Last updated

8 months ago

docker pull thebronway/domainctrl