3 ms·
Nice to know, thanks! > certbot does not like it so it needs a dedicated backend with a rule. What exactly fails in the certbot when you use proxy protocol by
by Snawoot 4y ago
Nice to know, thanks!
> certbot does not like it so it needs a dedicated backend with a rule.
What exactly fails in the certbot when you use proxy protocol by the way? Are you using certbot in standalone mode, making it listen socket on its own? I usually pass acme paths with Nginx to certbot workdir and use webroot mode.
Speaking about synchronization, on some job I had configs in SVN repo which were checked out with fabric job - it worked nicely. But afterwards I moved configs to git and made small daemon to listen webhooks for repo update to checkout and reload loadbalancers. Sort of gitops.
- gandalfk7 4y agoIt looks like unknowingly we followed a very similar route :D For the git repo I am not using webhooks but wrote a script that checks if the repo has been updated, downloads the new configfile, tests the syntax and if ok copies it and reloads haproxy. I use certbot in standalone mode, I want to review that approach and integrate it with nginx in the near future. But yes, in standalone mode proxy-protocol is not working with certbot, I think it's due HTTP01 challenge [0] but I have to look into that with more time at hand. I am now using these lines in haproxy config to route it to the correct backend (which just won't have "send-proxy" in the server options): acl letsenc_example path_beg /.well-known/acme-challenge/ hdr_dom(host) -m end example.org use_backend bk_http_letsenc if letsenc_example thanks for the ideas for improvement! [0]: https://github.com/cert-manager/cert-manager/issues/466 https://github.com/cert-manager/cert-manager/issues/466