3 ms·
I use Let's Encrypt DNS validation. This does not require you to run anything on your server. You just need to have a way to distribute cert to your servers.
by imperalix 11y ago
I use Let's Encrypt DNS validation. This does not require you to run anything on your server. You just need to have a way to distribute cert to your servers.
- sandGorgon 11y agocan you explain this ? I'm trying to bake letsencrypt certificates in my docker images and I am trying to figure out a way around the race condition (nginx needs a certificate to run <-> certificate needs nginx to run).
- kccqzy 11y agoYou can obtain a certificate by running let's encrypt's docker image, which seems to contain a python web server just to do the validation.
- sandGorgon 11y agocannot run a docker inside a docker. the problem is not running a webserver, the problem is the race condition which needs to be solved when docker starts up.
- imron 11y agoHow about storing the letsencrypt certificates in a data-container/locally on the host and mapping those files to the nginx container when you start it? For the very first time, you can use let's encrypt's manual verification process, but then have the let's encrypt client set up to renew certs automatically (possibly even from a separate container) using same data file mappings.
- sandGorgon 11y agowhich is why im preferring to spend 10$ on a certificate instead (or rather 85$ for a wildcard).
- vacri 11y agoAs a totally-naive-to-your-problem-particulars and totally-hacky suggestion, why not start nginx with a starter cert, then mv the new cert into position and reload nginx?
- sandGorgon 11y agoexactly what I did - but then I bought a certificate from rapidssl for 10 bucks...
- DanielDent 11y agoHere's one approach: https://github.com/DanielDent/docker-nginx-ssl-proxy https://github.com/DanielDent/docker-nginx-ssl-proxy I use a temporary self-signed keypair, which then gets replaced when the certificate is issued.
- marcosdumay 11y agoHave an instance with plain-text http running only the Lets Encrypt challenge. Make an explicit rule for it on your load balancer, and deploy it first.