Fully automated dockerized Let's Encrypt reverse proxy
advancedweb.hu
advancedweb.hu
[1]: https://github.com/xenolf/lego
[2]: https://disjoint.ca/til/2016/03/26/lets-encrypt-tls-certific...
However, people already made hooks that take care of that for you for some providers, for example, the CloudFlare one I experimented with:
Some things don't work all that well behind a TLS proxy. For those systems you need to generate a new outgoing TLS session. You don't need to check the validity of the certificate in most cases and can just use something self signed. I use a never renewed LE cert for convenience.
In general, all the trust for all the domains would have to rest in the proxy.
This is a great idea!
https://github.com/jwilder/nginx-proxy
https://github.com/JrCs/docker-letsencrypt-nginx-proxy-compa...
Since both are long running processes, it makes sense to keep them in separate containers.
The thing I like about this setup is that it seamlessly supports multiple vhosts, including SNI for the SSL. I can just create a new container that serves a new domain and set a few environment variables (VIRTUAL_HOST=mydomain.com and LETSENCRYPT_HOST=mydomain.com) and within a few seconds there's a new cert and all requests on that domain are proxied appropriately.
My setup script is here [1] for anyone who wants to do the same.
[1] https://github.com/cfallin/dot/blob/master/doc/setup-grey.c1...
I also wrote a tool for deploying and managing static servers and application servers during development[2][3], but it's not ready for a Show HN yet. But the idea is ...
b3cmd --project foo static-scaffold
b3cmd --project foo static-put public/ /
... and you'll have a docker-compose project accessible at "foo--master.example.com" and a static server at "foo--master--static.example.com", all HTTPS ready.[1]: https://github.com/mikew/docker-gen-letsencrypt
That violates the one container, one process design principle, if that's a concern.
Caddy[1] is an interesting single binary cross-platform web server and reverse proxy with built-in Lets Encrypt support.
Traffic to an "SSL protected appliction" actually stops to be protected at the edge of the web server. Inside everything is in cleartext. An SSL proxy just breaks this cleartext part between two servers.
Of course you need to control both of them and ensure trust between them.