Replies: 1 comment
|
You don't need acme.sh inside the wallarm/nginx container -- use acme.sh's built-in Label the target container (in your compose), e.g.: wallarm-node:
labels:
sh.acme.autoload.domain: example.tldRun the acme.sh container with the socket: acme:
image: neilpang/acme.sh
command: daemon
volumes:
- /var/run/docker.sock:/var/run/docker.sock
- ./acme:/acme.shIssue (DNS or webroot), then deploy -- once per cert: docker exec acme \
acme.sh --deploy -d example.tld --deploy-hook dockerwith these set on the deploy: export DEPLOY_DOCKER_CONTAINER_LABEL="sh.acme.autoload.domain=example.tld"
export DEPLOY_DOCKER_CONTAINER_KEY_FILE="/etc/nginx/ssl/example.tld/key.pem"
export DEPLOY_DOCKER_CONTAINER_CERT_FILE="/etc/nginx/ssl/example.tld/cert.pem"
export DEPLOY_DOCKER_CONTAINER_CA_FILE="/etc/nginx/ssl/example.tld/ca.pem"
export DEPLOY_DOCKER_CONTAINER_FULLCHAIN_FILE="/etc/nginx/ssl/example.tld/full.pem"
export DEPLOY_DOCKER_CONTAINER_RELOAD_CMD="nginx -s reload"For |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Currently I'm using https://github.com/wallarm/docker-wallarm-node as a reverse proxy (this runs nginx) and I have several conf files each with their own config for the domains example.tld, www.example.tld, and mail.example.tld I'm trying to automate the management of said certificates. for now I've just been using the certbot/certbot container but it's modified and the renewal is triggered via a cron job. I would love to see if there was a way to have an acme.sh container manage this and reload the nginx process running inside of the wallarm/node container
All reactions