Setting up a static HTTPS website on your Raspberry Pi using Docker and Nginx
gist.github.com
gist.github.com
> Now if you go into Chromium browser settings and search "certificates", in the Security tab, Manage Certificates, you can add an Authority. Import 'ca.pem'. Tell the browser to Trust this certificate for identifying websites. This should add 'org-test-ca' to your browser. This allows HTTPS certificates signed by that to be seen as valid in your browser.https://git.inportb.com/jyio/docker-nginx-auto
Basically, inotifywait on the config directory and request new certificates as needed. Grep the config files for hostnames (and ignore if labeled NOSSL). And a configuration snippet to include the same SSL config for anything that needs SSL (including the .well-known/acme-challenge directory). Oh, and use cron to renew periodically.
I like this idea. I'm going to start using this.
Though... I think I'd still include the snake oil cert and serve everything over SSL, because it simplifies the configuration.
Agreed. Not sure why you'd go through the trouble of importing a self-signed CA when you can provision certs for any internal service with LE. I dont use self-signed and instead have been using LE certs provisioned for internal services for the last couple years. Extra nice to be able to leverage DNS challenge for cert provisioning at home to get around overloading common ports.
I know a lot of people mention Caddy but I find Traefik [0] (pronounced "traffic") more flexible. It's routing and middleware configurations are fantastic. Especially when you want to stick a reverse proxy in front of things that are a pain to provision certs into (switches, routers, old embedded web interfaces, etc).
Install apache (or nginx or lighttpd) on your box using your distros package manager of choice.
Configure https on apache.
I run a few containers on my RPi and cannot tell a difference in performance.
Installing docker and running that daemon for just this is not the right way.
Your definition of insanity is perplexing. Docker in this context is pretty trivial to setup and run, and it's used mainly to manage packaging and deployment. Do you happen to have any experience at all with Docker?
No, not really. With Docker, packaging is a solved problem, and you also get for free a deployment history which you can roll back and forward at will. You also get introspection and blue/green deployments, and if you really want to you can also setup a cluster of nodes for free where you can run whole application stacks with a one-liner.
There is really no excuse to do things the hard way.
It really doesn't. Unless you were planning on doing a one-and-done deployment, it's trivial to update and redeploy Docker images. Even in my side projects I have CI/CD pipelines updating and redeploying Docker images daily.
> With distribution package management, on Ubuntu, you can rely on your Nginx being updated and restarted automatically while you sleep.
Whatever you can do with Ubuntu, you can do precisely the same with Docker when running a base image of Ubuntu.
> With Docker, you need to subscribe to a security mailing list in order to know about the vulnerability in the first place, and then run some commands manually that re-create the container.
No, you really don't. Just pull the latest base image, build your images by calling apt to update your dependencies, and you're done.
Whatever you can do with a bare metal/VM install, you can do with Docker.
There is nothing magical stopping you from doing the basic stuff with Docker.
ok fun guy
One command? Did you read the github page?
At the end, this doc even has you hand editing your nginx for SSL?!? Why on earth... why not just use certbot automation? This seems totally counter to the idea. Again, am I being dense? Is this just "look what I can do with docker that makes my life more complicated"? Honestly, at this point it feels like more work for less output.
This seems way harder than installing nginx and certbot, and now I have a hard dependency on docker and whatever else you pulled in.
Sure, I could install lighttpd myself, but docker-compose gives me a common configuration file format.
Which I assume means something like "This product is limited to 1 per customer"
You might want to also grab the sd card from there.
I recommend getting the power supply, case and fan from Digikey.
It's not super dangerous, just make sure you keep everything updated (your linux OS, your server software). And make sure that you only open the ports you need to.
They're great little machines for this exact purpose. No need to have a full blown PC serving trivial stuff. Only problem is, they use SD cards and eventually. I've had a quality 128GB card in mine that has died/been corrupted about 3 times in 4 years. That's my biggest issue with these amazing little machines