A container to simplify generation of LetsEncrypt certificates against Amazon Route53 DNS.
1.6K
This container is designed to be used for local development. As such, it has not been hardened as required for a production environment.
The purpose of this container is to manage local development certificate creation and renewal for Let's Encrypt certificates against Amazon Route53.
This image uses environment variables to for providing the necessary values to the container.
AWS_ACCESS_KEY_IDAWS_SECRET_ACCESS_KEYSELF_SIGNED_SUBJECTAWS_ACCESS_KEY_ID is provided, certbot will be unable to authenticate to Amazon Route53.
In that case a self-signed certificates will be created instead under /etc/pki/tls. This is the subject of the
self-signed certificate./C=US/ST=NY/L=New York/O=Example Company/CN=localdev.example.comBASE_DOMAINBASE_DOMAIN as well as a wildcard for the base domain.localdev.example.com. This generates certificates for localdev.example.com
and *.localdev.example.com.ADDL_DOMAIN_PREFIXBASE_DOMAIN.jdoe. If BASE_DOMAIN was localdev.example.com, then an additional certificate for
*.jdoe.localdev.example.com would be requested.The following volumes are used by certbot:
/etc/pki/tls/cert/cert.pem - Corresponds to Let's Encrypt's fullchain.pem
file./etc/pki/tls/private/privkey.pem - Corresponds to Let's Encrypt's privkey.pem
file.docker run -it --rm -e AWS_ACCESS_KEY_ID=AAAAAAAAAAAAAAAA \
-e AWS_SECRET_ACCESS_KEY=BBBBBBBBBBBBBBBB \
-e BASE_DOMAIN=localdev.example.com -e ADDL_DOMAIN_PREFIX=jdoe \
-v $HOME/Dev/.letsencrypt-data:/etc/letsencrypt \
-v $HOME/Dev/project/certificates:/etc/pki/tls \
wildscamp/certbot-route53
letsencrypt:
image: wildscamp/certbot-route53
environment:
- AWS_ACCESS_KEY_ID=AAAAAAAAAAAAAAAA
- AWS_SECRET_ACCESS_KEY=BBBBBBBBBBBBBBBB
- BASE_DOMAIN=localdev.example.com
- ADDL_DOMAIN_PREFIX=jdoe
volumes:
- ../.letsencrypt-data:/etc/letsencrypt
- ./certificates:/etc/pki/tls
Content type
Image
Digest
Size
53.2 MB
Last updated
about 6 years ago
docker pull wildscamp/certbot-route53