6 ms·
And, come to think of it, some additional great features would be automatic TLS certs via Let's Encrypt and maybe even being able to use a shared cache with mul
by heipei 3y ago
And, come to think of it, some additional great features would be automatic TLS certs via Let's Encrypt and maybe even being able to use a shared cache with multiple instances of nginx.
- dangerlibrary 3y agoI put off adding TLS certs to my personal website for years. It's just a few static files served by nginx on a server - there wasn't a great reason to bother, I thought. It took me almost exactly 3 minutes start to finish with letsencypt. Where 'start' was "I should stop putting that off" and typing "letsencrypt.com" into a browser, and 'finish' was nginx serving up https:// https:// on all my domains. I'm genuinely curious what nginx could possibly do to improve the situation there.
- joseph_grobbles 3y ago[dead]
- fs111 3y agoCheck what caddy does. I think that is what op is after
- guraf 3y agoIt's true that setup is simple enough but what other servers like Caddy provide is automated renewals. You don't have to mess with having a .well-known always accessible on each domain, for example. Caddy does it for you and only when it's needed.
- bombcar 3y agoCaddy does it all automatically and you don’t have to remember to do things by hand.
- adobrawy 3y agoCaddy targets single instances. No coordination is required to avoid receiving receive multiple certificates for multiple instances for same domain. Nginx has a profit from big business that would require coordination to avoid multiple certificates. For comparison, it is worth noting that to ensure such coordination, Traefik requires an Enterprise plan and a separate agent. Such a business also often has mechanisms for storing certificates, so they do not necessarily want to integrate it into Nginx.
- francislavoie 3y agoWith Caddy, you can cluster easily by either sharing its filesystem data storage across machines, or configuring a different storage driver (redis, consul, db, etc.) and they will automatically coordinate for cert issuance. Caddy writes a lock file to the storage which prevents multiple instances from stepping on eachother's toes.
- bg24 3y agoI recently moved to Caddy. Out-of-the-box TLS, HTTP3, Dumbed-down simple configuration, static files... it has been a breath of fresh air.
- rekoil 3y agoCaddy is amazing. Still irritated that they ship it with an unprotected admin endpoint enabled by default on localhost:2019 that eats JSON and allows reconfiguration of the webserver like adding new sites that enable further attacks. Put "{ admin off }" as a separate block in the root Caddyfile to disable it.
- francislavoie 3y agoOur view is that localhost:2019 is inherently protected though - that only allows requests from the same machine. If you're running the machine with shared users, then of course it's up to you to further secure things. That said, see https://github.com/caddyserver/caddy/issues/5317 https://github.com/caddyserver/caddy/issues/5317, we are considering changing the default, but that would be a breaking change although it would likely be a transparent change for most users. The default that makes the most sense depends on the platform and installation method, which is why it's complicated.
- rekoil 3y agoSSRF is a thing, just because you trust the code doesn't mean you've eliminated all security risks. The tools we use in the industry should all have secure defaults. Glad to hear you're considering changing the default! It would be enough for me if Caddy generated a password (that's hard for attackers to predict) on first launch, set that in a config file it has write access to (autosave.json for example), and then required Basic auth using this password unless the configuration specified otherwise. My problem is that this endpoint is entirely unauthenticated.
- Gordonjcp 3y agoLots of folk have mentioned Caddy, but I'd like to also mention Traefik which kind of does the same thing but I found it to be less of a pain in the arse.
- berkle4455 3y agoTraefik has a very verbose config with non-sensible defaults; Caddy works out of the box with 1-3 lines to setup your domain and sensible defaults. What's the pain?
- v3ss0n 3y agoTarefik because it is better architectured, auto discovery of docker services , battle tested
- fulafel 3y agoLink for others curious about the discovery: https://doc.traefik.io/traefik/providers/docker/ https://doc.traefik.io/traefik/providers/docker/ (but preferring Caddy so far)
- francislavoie 3y agoThat can be done with Caddy as well: https://github.com/lucaslorentz/caddy-docker-proxy https://github.com/lucaslorentz/caddy-docker-proxy
- Gordonjcp 3y agoThis didn't work when I tried Caddy before, and it was the entire thing I needed to do. I should revisit Caddy and see how it gets on.
- Gordonjcp 3y agoIt didn't cope with services starting and stopping well, and couldn't provision services from docker (at least when I looked at it).
- madspindel 3y agoTry Caddy. I was mind blown when I fired up a simple Caddyfile + Docker and got SSL out of the box.
- mschuster91 3y agoLE is dead easy to integrate using Docker, the work related to integrating it into webservers themselves (IMO) isn't worth it.
- francislavoie 3y agoThere's literally zero work with Caddy. I'm not sure I understand what you're trying to say. Also, there's massive advantages to having TLS issuance built into the webserver, such as proper OCSP stapling, having an active process to trigger renewals as soon as a revocation happens (hearing about it via OCSP), solving the ACME TLS-ALPN challenge without extra steps, and unique features like On-Demand TLS that many SaaS companies are relying on to provide a custom domains feature to their customers. None of those things are possible unless it's tightly integrated in the webserver.
- eyegor 3y agoCertbot is practically a one liner in a cron job once you fill out the config.
- throwaway2990 3y agoBlocked by that stupid snap crap :(
- Taywee 3y agoYou don't need snap. Follow the Pip instructions: https://certbot.eff.org/instructions?ws=nginx&os=pip https://certbot.eff.org/instructions?ws=nginx&os=pip Or docker: https://eff-certbot.readthedocs.io/en/stable/install.html#running-with-docker https://eff-certbot.readthedocs.io/en/stable/install.html#ru...
- account42 3y agoUbuntu on a server? Just use Debian lol.
- muppetman 3y agoDoes Certbot still pull in 40 odd dependancies? I wanted to use it but ugh, the amount of extra libraries it wanted to pull in. acme.sh does it all with a single bash script (plus a few supporting binaries, to be fair)
- eyegor 3y agoNot sure, I think I've only used the version they distribute on pip. Which can be a bit obnoxious if you have to build the python cryptography package for your target os/platform but if you don't it's a fairly minor install. There are quite a few other options besides certbot, I was just suggesting it as a "install + one liner" for adding auto renewing ssl certs to a server. https://letsencrypt.org/docs/client-options/ https://letsencrypt.org/docs/client-options/
- ivlad 3y agoYou just want to get a free ride, and they want to feed their kids.
- KronisLV 3y ago> And, come to think of it, some additional great features would be automatic TLS certs via Let's Encrypt and maybe even being able to use a shared cache with multiple instances of nginx. Well, for what it's worth, certbot is still pretty good: https://certbot.eff.org/ https://certbot.eff.org/ That said, with servers like Caddy supporting automatic TLS and even Apache httpd having built in support now with mod_md, Nginx feels more like an outlier for not supporting ACME out of the box: https://httpd.apache.org/docs/2.4/mod/mod_md.html https://httpd.apache.org/docs/2.4/mod/mod_md.html For my personal sites I actually use Apache because it's pretty good and has lots of modules (including OpenID Connect support for Keycloak etc.), but Nginx has always been really easy to install and setup, especially for serving static files (e.g. built front end apps) or being a basic reverse proxy. Here's a bit more about how I use Apache: https://blog.kronis.dev/tutorials/how-and-why-to-use-apache-httpd-in-2022 https://blog.kronis.dev/tutorials/how-and-why-to-use-apache-... And a little bit about some of the occasional warts of Nginx: https://blog.kronis.dev/everything%20is%20broken/nginx-configuration-is-broken https://blog.kronis.dev/everything%20is%20broken/nginx-confi... (though otherwise it's fine) That said using HTTP-01 instead of DNS-01 across multiple nodes with the same hostname is needlessly complex in most cases and DNS-01 doesn't always have the best support in web servers (Apache in particular is just like: "Yeah, we can run whatever script you want, but the contents and integrating with your DNS server is up to you").