Sign inSign up

vanyauhalin/nginx

By vanyauhalin

•Updated over 1 year ago

A simple Docker image for Nginx that eliminates the need to configure it over and over again

Image
0

1.3K

vanyauhalin/nginx repository overview

⁠Nginx Docker Image

This is a simple Docker image for Nginx, created by someone not specialized in configuring Nginx or writing shell scripts, to eliminate the need to configure it over and over again.

This image contains:

  • A static Brotli module.
  • Support for obtaining SSL certificates with their auto-renewal.
  • The ability to substitute environment variables in the Nginx configuration.
  • A few basic snippets to configure Nginx.

Important criteria for creating this image were:

  • Do not attempt to automate the formation of the configuration file.
  • Do not enforce any configuration options.
  • Write scripts as simply and clearly as possible.
  • Avoid performing complex operations in scripts.

⁠Contents

⁠Installation

Pull image from Docker Hub:

docker pull vanyauhalin/nginx

... or from GitHub Container registry:

docker pull ghcr.io/vanyauhalin/nginx

⁠Description

Description in progress, sorry...

Show ae help message
Usage: ae [options] <subcommand>
       ae obtain [options] <type>
       ae renew [options]
       ae logs [options]
       ae acme <arguments>

Options:
  -p            Pipes the output to the log file
                (available for 'install', 'obtain', 'schedule', 'trigger' and 'renew' subcommands)

Subcommands:
  help          Shows this help message
  install       Installs the client
  obtain        Obtains certificates
  schedule      Schedules certificate renewal
  trigger       Triggers scheduled operations
  renew         Renews certificates
  logs          Shows the log file
  env           Shows the environment variables
  acme          Runs the acme client

Obtain options:
  -g            Obtains certificates only for non-existing domains
  -s            Skips Nginx reload

Obtain types:
  self          Obtains self-signed certificates
  test          Obtains test certificates
  prod          Obtains production certificates

Renew options:
  -f            Forces renewal of certificates

Logs options:
  -f            Follows the log file
  -n <lines>    Shows the last <lines> lines of the log file

Environment variables:
  AE_ENABLED             Whether ae is enabled
  AE_CRON                Cron schedule for certificate renewal
  AE_DAYS                Validity period for certificates when obtaining new ones
  AE_DOMAINS             Comma-separated list of domains to obtain certificates for
  AE_EMAIL               Email address to use when obtaining certificates
  AE_KEY_SIZE            Size of the RSA key to be generated
  AE_HEALTHCHECKS_URL    URL to Healthchecks check
Show ng help message
Usage: ng <subcommand>

Subcommands:
  help          Shows this help message
  render        Renders the Nginx config from the template

Environment variables:
  NG_ENABLED             Whether ng is enabled
Show mentioned files and directories in the tree format
├─ etc
│  └─ nginx
│     ├─ snippets
│     │  ├─ example.com
│     │  │  ├─ proxy-ssl-certificate.conf
│     │  │  └─ ssl-certificate.conf
│     │  ├─ acme-challenge.conf
│     │  ├─ base-headers.conf
│     │  ├─ base-options.conf
│     │  ├─ brotli-options.conf
│     │  ├─ force-https.conf
│     │  ├─ force-non-www.conf
│     │  ├─ gzip-options.conf
│     │  ├─ map-connection.conf
│     │  ├─ map-non-www.conf
│     │  ├─ proxy-options.conf
│     │  ├─ proxy-ssl-options.conf
│     │  ├─ ssl-dhparam.conf
│     │  ├─ ssl-headers.conf
│     │  └─ ssl-options.conf
│     ├─ ssl
│     │  ├─ example.com
│     │  │  ├─ chain.pem
│     │  │  ├─ fullchain.pem
│     │  │  └─ privkey.pem
│     │  └─ dhparam.pem
│     ├─ nginx.conf
│     └─ nginx.conf.template
├─ usr
│  ├─ bin
│  │  └─ envsubst
│  ├─ local
│  │  ├─ bin
│  │  │  ├─ acme
│  │  │  ├─ ae
│  │  │  ├─ entrypoint
│  │  │  └─ ng
│  │  └─ lib
│  │     ├─ color.sh
│  │     └─ log.sh
│  └─ sbin
│     └─ nginx
├─ log
│  ├─ ae
│  │  └─ output.log
│  └─ nginx
│     ├─ access.log
│     └─ error.log
└─ var
   └─ www
      └─ example.com

⁠Acknowledgements

This image would not have happened without studying other people's project.

wokalek/nginx-brotli⁠
The creation of this image began with studying Alexander Wokalek's work. His image formed the basis of this image with almost no changes. In a sense, this project is a fork of that one. If you are looking for Nginx without additional overhead, but with only the brotli module compiled, consider using wokalek's image.

nginx-le/nginx-le⁠
The image created by Umputun⁠ demonstrated how to work with scripts that process SSL certificates within the same image with Nginx.

h5bp/server-configs-nginx⁠, lebinh/nginx-conf⁠
I would like to mention several resources in one line from which snippets were collected.

Mozilla SSL Configuration Generator⁠, Report URI Content Security Policy Generator⁠
Let us not forget about useful generators, which also helped to form a few snippets.

⁠License

MIT⁠ (c) Ivan Uhalin⁠

Tag summary

Content type

Image

Digest

sha256:94fa7808a…

Size

11 MB

Last updated

over 1 year ago

docker pull vanyauhalin/nginx