10 ms·
Setting up a static HTTPS website on your Raspberry Pi using Docker and Nginx
- capableweb 5y agoTangential at best: where can you get a hold on a Raspberry Pi 4 in Europe? Every store is sold-out and the ones that aren't only allow one per customer.
- horsellama 5y agoPimoroni has some in stock https://shop.pimoroni.com/products/raspberry-pi-4?variant=29157087445075 https://shop.pimoroni.com/products/raspberry-pi-4?variant=29...
- capableweb 5y ago> This product is limited to 1 per customer
- geerlingguy 5y agoMost people just need one, fortunately.
- capableweb 5y agoSure, that's probably true. Wasn't what I asked for in my original comment though :)
- horsellama 5y agoOops, sorry didn’t notice that they are doing this now. I’ve bought some at few weeks of distance tho (a zeroW and a 3B)
- butz 5y agoAre there any other, more available cheap boards, that could run a simple web server?
- rolph 5y agoive reflashed old routers with openWRT into a server cluster, they are a lot more portable, quiet and power efficient, of course this doesnt scale up well as the hardware has its limits. keep in mind you dont have to host the entire website on one server, so you can balance the load that way if you need to.
- oynqr 5y agoCheck out some of the supported boards for armbian, nanopis are usually pretty cheap and decent enough.
- kzrdude 5y agoWhy are pis so often limited like this, is it a requirement from the foundation? Just curious.
- megous 5y agohttps://rpishop.cz/869-mini-pocitace https://rpishop.cz/869-mini-pocitace
- capableweb 5y ago> Maximálně 1 ks na zákazníka. Which I assume means something like "This product is limited to 1 per customer"
- pzduniak 5y agohttps://botland.com.pl https://botland.com.pl will sell you up to 10.
- capableweb 5y agoThanks, looks like a nice choice! Unfortunately they only have 2 (4GB model, rest is out of stock) in stock at the moment ("Available quantity: 2" it says), but will keep an eye for when they get re-stocked.
- emilfihlman 5y agohttps://www.verkkokauppa.com/fi/product/57364/mndkd/Raspberry-Pi-4-model-B-4-Gt-yhden-piirilevyn-tietokone https://www.verkkokauppa.com/fi/product/57364/mndkd/Raspberr... You might want to also grab the sd card from there. I recommend getting the power supply, case and fan from Digikey.
- yjftsjthsd-h 5y agoIt's a bit more work, but for single-digit quantities you could just buy one per store from a bunch of vendors, possibly repeating weekly or whatever until you get the desired number?
- kaycebasques 5y agoI'm ashamed that I was so naïve about this, but I was disappointed to realize that hosting a website to the entire public internet on my Pi was non-trivial. Of course once I dug into the idea it was obvious why it was difficult and furthermore that it would be a dangerous thing to do. Just sharing and curious if anyone has done it or knows useful documentation on the topic.
- 13415 5y agoWhy was is complicated? I'm hosting https://talumriel.de https://talumriel.de for my German novels on a Rapberry Pi 3b, using Nginx and Letsencrypt with cryptbot. It's probably not super-secure, but the setup was very easy. I basically just followed one of the tutorials on the Net.
- dividuum 5y agoIt sounds like you Pi doesn't have a public IP address. So you need some way to tunnel requests to it. On solution would to be SSH into one of your own public boxes somewhere and use reverse port forwarding (-R). Although that's probably not very reliabile on its own as you have to make sure the connection stays alive. More professional solutions are probably ngrok or cloudflare tunnel. The latter is meant exactly for what you describe: expose a service on a private machine as a public facing web site.
- capableweb 5y agoPort forwarding from your router is another option, redirect all 443/80 traffic from the public interface of the router to your Raspberry, preferably on a separate VLAN and also firewalls on both your router and Raspberry before enabling that.
- lovek3292 5y agoOne command" production ready server
- InvaderFizz 5y agoI was initially looking at this to see how they automated their Let's Encrypt and if it was better than just using Caddy. I was disappointed to find they are just creating a self-signed RootCA and issuing certs. > Now if you go into Chromium browser settings and search "certificates", in the Security tab, Manage Certificates, you can add an Authority. Import 'ca.pem'. Tell the browser to Trust this certificate for identifying websites. This should add 'org-test-ca' to your browser. This allows HTTPS certificates signed by that to be seen as valid in your browser.
- deleted 5y ago[deleted]
- deleted 5y ago[deleted]
- inportb 5y agoThis is how I automate LE (technically ACME/ZeroSSL) in my Nginx reverse proxy. https://git.inportb.com/jyio/docker-nginx-auto https://git.inportb.com/jyio/docker-nginx-auto Basically, inotifywait on the config directory and request new certificates as needed. Grep the config files for hostnames (and ignore if labeled NOSSL). And a configuration snippet to include the same SSL config for anything that needs SSL (including the .well-known/acme-challenge directory). Oh, and use cron to renew periodically.
- InvaderFizz 5y ago> inotifywait on the config directory I like this idea. I'm going to start using this.
- inportb 5y agoJust be aware that nginx needs a self-signed certificate in the very beginning, to serve the .well-known/acme-challenge directory. To simplify the initial setup, I include a default "snake oil" certificate, which gets overwritten.
- schwartzworld 5y agoIt seems like a lot of work to serve a static site over your local network. How is this different from running `python -m SimpleHTTPServer`?
- capableweb 5y agoFor development I'm sure SimpleHTTPServer is fine for most use-cases (except SPAs, of course), but for more serious use, nginx and SimpleHTTPServer couldn't be more different.
- suprfsat 5y agoDoesn't involve installing an obsolete version of Python.
- schwartzworld 5y agoI just meant if you aren't exposing it to the outside world, why not use any other server? Curious about the real advantages.
- oynqr 5y agopython -m http.server ok fun guy
- butz 5y agoWhy even use docker for a static website server?
- yrds96 5y ago"One command" production ready server
- megous 5y agoYou mean like `apt install nginx`? :)
- codegeek 5y agoI am not a fan of docker for everything but 'apt install nginx' would not give you https out of the box. I am beginning to like Caddy which comes with https enabled but I have never used it in production yet.
- megous 5y agoIf you want https you can just run certbot. It will bootstrap the nginx config. I dislike programs that change the configuration automatically, and thus run dehydrated instead of certbot, but running apt install nginx certbot and some certbot incantation to make it bootstrap your domains is not really any more bothersome, than having to figure out how docker works, and how to manage changes to my nginx config with it over time, etc..
- readingnews 5y agoI totally disagree with this reply, and agree with the thread starter... I really, really do not see the point of this. One command? Did you read the github page? At the end, this doc even has you hand editing your nginx for SSL?!? Why on earth... why not just use certbot automation? This seems totally counter to the idea. Again, am I being dense? Is this just "look what I can do with docker that makes my life more complicated"? Honestly, at this point it feels like more work for less output. This seems way harder than installing nginx and certbot, and now I have a hard dependency on docker and whatever else you pulled in.
- ThinkBeat 5y agoDo it 90s style. Install apache (or nginx or lighttpd) on your box using your distros package manager of choice. Configure https on apache.
- LeoPanthera 5y agoSeriously. Adding a docker layer to a device as lightweight as a Raspberry Pi just seems like insanity.
- 404mm 5y agoIt doesn’t really. Don’t confuse docker with a virtualization layer. Well made containers bring just the processes you’d be running anyway. I run a few containers on my RPi and cannot tell a difference in performance.
- SahAssar 5y agoI agree if the container brings any benefits. In this case there is nothing that a standard distro-packaged apache/nginx wouldn't do. There is no automation of build steps, lets-encrypt or similar. Installing docker and running that daemon for just this is not the right way.
- nuerow 5y ago> Seriously. Adding a docker layer to a device as lightweight as a Raspberry Pi just seems like insanity. Your definition of insanity is perplexing. Docker in this context is pretty trivial to setup and run, and it's used mainly to manage packaging and deployment. Do you happen to have any experience at all with Docker?
- patrakov 5y agoIt still does have a non-zero cost, especially in the long run, when security vulnerabilities pop up. With distribution package management, on Ubuntu, you can rely on your Nginx being updated and restarted automatically while you sleep. With Docker, you need to subscribe to a security mailing list in order to know about the vulnerability in the first place, and then run some commands manually that re-create the container.
- jsisto 5y agoI accomplish this with raspberry pi + docker + swag https://docs.linuxserver.io/general/swag https://docs.linuxserver.io/general/swag
- tragictrash 5y agoThis is a bad guide and should be recognized as such. They should be using certbot or some other utility, not creating their own CA.
- alsobrsp 5y agoWhy in the absolute hell does a static site need docker? I don't get it, it is not that hard to properly configure software.
- rain1 5y agothe goal was to run nginx in docker, if you want to run nginx without docker you can just not do the docker parts. not sure what you mean about properly configure software - you can configure nginx the same whether you use docker or not?
- Gigachad 5y agoWhy does a static site even need hardware? Just drop it on GitHub/lab pages and call it a day.