Get certificates for IPv6 pods/services using certbot.
1.6K
This container is made for getting real world certificates for your kubernetes cluster.
The assumption is that you can point the DNS name to the container from outside. This is by default given for IPv6 only kubernetes services.
The source of this image can be found on code.ungleich.ch.
docker run -e DOMAIN=example.com \
-e [email protected] \
ungleich/ungleich-certbot
Using
docker run -e DOMAIN=example.com \
-e [email protected] \
-e START_NGINX=yes \
-e STAGING=no \
ungleich/ungleich-certbot
you will get a proper, real world usable nginx server. Inject the nginx configuration by meains of a volume to /etc/nginx/conf.d
Using
docker run -e DOMAIN=example.com \
-e [email protected] \
-e START_NGINX=yes \
-e NGINX_HTTP_REDIRECT=yes \
-e STAGING=no \
ungleich/ungleich-certbot
the container will listen on port 80 and redirect the traffic to port 443 (https).
By default, the container will stay alive and try to renew the
certificate every 86400 seconds. If you set the environment variable
ONLYGETCERT, then it will only get the certificates and exit.
If you only want to trigger renewing existing certificates and skip
getting the certificates initially, you can set the variable
RENEWCERTSONCE, then it will only renew all certificates and exit.
ONLYRENEWCERTS is set, only the reguler renew loop will run.ONLYRENEWCERTSONCE is set, renew will be run once and then the
container exitsThis mode can f.i. be used as a kubernetes Job.
If you want to keep / use your certificates, you are advised to create a volume below /etc/letsencrypt.
Usable with automatic renewal
Added support for nginx webserver, based on official nginx image
See https://code.ungleich.ch/ungleich-public/ungleich-k8s/.
Content type
Image
Digest
sha256:97243e385…
Size
34.4 MB
Last updated
almost 2 years ago
docker pull ungleich/ungleich-certbot:1.1.6