Compare commits
6 commits
| Author | SHA1 | Date | |
|---|---|---|---|
| a6af2b5f55 | |||
| 217b8c2e95 | |||
| 837887a66c | |||
| 3ae07d4598 | |||
|
|
2c03ff46f0 | ||
|
|
43672378fb |
4 changed files with 23 additions and 8 deletions
|
|
@ -1,10 +1,10 @@
|
||||||
FROM nginx:1.21.4-alpine
|
FROM nginx:1.21.4-alpine
|
||||||
|
|
||||||
RUN mkdir -p /nginx
|
RUN mkdir -p /nginx /www_http
|
||||||
COPY nginx-http-redir.conf /nginx/default.conf
|
COPY nginx-http-redir.conf /nginx/default.conf
|
||||||
|
|
||||||
# For renewing the certificates
|
# For renewing the certificates
|
||||||
COPY renew_cert.sh /etc/periodic/daily/
|
COPY renew_cert.sh /etc/periodic/daily/renew_cert
|
||||||
|
|
||||||
RUN apk update && apk add certbot bind-tools
|
RUN apk update && apk add certbot bind-tools
|
||||||
|
|
||||||
|
|
|
||||||
11
README.md
11
README.md
|
|
@ -128,6 +128,17 @@ Added support for nginx webserver, based on official nginx image
|
||||||
|
|
||||||
- Add missing crond invocation
|
- Add missing crond invocation
|
||||||
|
|
||||||
|
### 1.1.3
|
||||||
|
|
||||||
|
- Add missing http directory
|
||||||
|
|
||||||
|
### 1.1.4
|
||||||
|
|
||||||
|
- change renew_cert.sh file name for run-parts
|
||||||
|
|
||||||
|
### 1.1.5
|
||||||
|
|
||||||
|
- update renew_cert.sh for periodic renew
|
||||||
|
|
||||||
## Kubernetes
|
## Kubernetes
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -3,10 +3,10 @@ server {
|
||||||
listen [::]:80;
|
listen [::]:80;
|
||||||
|
|
||||||
server_name _;
|
server_name _;
|
||||||
root /var/www/html/;
|
root /www_http;
|
||||||
|
|
||||||
location /.well-known/acme-challenge/ {
|
location /.well-known/acme-challenge/ {
|
||||||
root /var/www/html;
|
root /www_http;
|
||||||
}
|
}
|
||||||
|
|
||||||
# Everything else -> ssl
|
# Everything else -> ssl
|
||||||
|
|
|
||||||
|
|
@ -2,10 +2,11 @@
|
||||||
|
|
||||||
if [ "$NO_NGINX" ]; then
|
if [ "$NO_NGINX" ]; then
|
||||||
/usr/bin/certbot renew --standalone
|
/usr/bin/certbot renew --standalone
|
||||||
|
elif [ -n "`grep -r standalone /etc/letsencrypt/renewal`" ]; then
|
||||||
|
/usr/bin/certbot renew --standalone
|
||||||
|
/usr/bin/certbot renew --force-renew --webroot --webroot-path /www_http
|
||||||
else
|
else
|
||||||
/usr/bin/certbot renew --webroot --webroot-path /var/www/html
|
/usr/bin/certbot renew --webroot --webroot-path /www_http
|
||||||
# Reload nginx
|
|
||||||
pkill -1 nginx
|
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# Correct permissions if not told otherwise
|
# Correct permissions if not told otherwise
|
||||||
|
|
@ -14,4 +15,7 @@ if [ -z "$LEAVE_PERMISSIONS_AS_IS" ]; then
|
||||||
find /etc/letsencrypt -type f -exec chmod 0644 {} \;
|
find /etc/letsencrypt -type f -exec chmod 0644 {} \;
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
# Reload certs
|
||||||
|
pkill -1 nginx
|
||||||
|
|
||||||
echo "Last renew: $(date)" > /tmp/last_renew
|
echo "Last renew: $(date)" > /tmp/last_renew
|
||||||
Loading…
Add table
Add a link
Reference in a new issue