基于certbot为站点自动续期SSL证书
由于公司官网是基于Docker进行部署的,所以此次部署的文档都是基于Docker进行的
一、创建对应的文件夹
在宿主机的/目录下创建以下文件夹.
1 2 3
| mkdir -p /data/certbot/conf mkdir -p /data/certbot/www mkdir -p /daya/certbot/nginx-certbot
|
在/data/certbot/nginx-certbot文件夹下创建docker-compose.yml文件和nginx.conf文件
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26
| version: "3"
services: nginx: image: registry.cn-shanghai.aliyuncs.com/jellybeans_company/jellybeans_portal:latest container_name: jellybeans_portal ports: - "80:80" - "443:443" volumes: - ./nginx.conf:/etc/nginx/conf.d/default.conf - /data/certbot/conf:/etc/letsencrypt - /data/certbot/www:/var/www/certbot restart: always
certbot: image: certbot/certbot container_name: certbot volumes: - /data/certbot/conf:/etc/letsencrypt - /data/certbot/www:/var/www/certbot entrypoint: > sh -c "while true; do certbot renew --webroot -w /var/www/certbot; sleep 12h; done"
|
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43
|
server { listen 80; server_name jellybeans.com.cn;
location /.well-known/acme-challenge/ { root /var/www/certbot; }
location / { return 301 https://$host$request_uri; } }
server { listen 443 ssl; server_name jellybeans.com.cn;
ssl_certificate /etc/letsencrypt/live/jellybeans.com.cn/fullchain.pem; ssl_certificate_key /etc/letsencrypt/live/jellybeans.com.cn/privkey.pem;
ssl_protocols TLSv1.2 TLSv1.3; ssl_ciphers HIGH:!aNULL:!MD5;
location / { root /usr/share/nginx/html; index index.html; }
location ~* \.(js|css|png|jpg|jpeg|gif|ico|svg)$ { expires 30d; } }
|
二、申请证书
新申请证书
1 2 3 4 5 6 7 8 9
| docker run --rm -v /data/certbot/conf:/etc/letsencrypt -v /data/certbot/www:/var/www/certbot certbot/certbot certonly --webroot --webroot-path=/var/www/certbot -d jellybeans.com.cn --email xueyinghao@jellybeans.com.cn --agree-tos --no-eff-email
|
追加申请证书
1 2 3 4 5 6 7 8 9 10 11 12
| docker run --rm -v /data/certbot/conf:/etc/letsencrypt -v /data/certbot/www:/var/www/certbot certbot/certbot certonly --webroot --webroot-path=/var/www/certbot -d jellybeans.com.cn -d www.jellybeans.com.cn --email xueyinghao@jellybeans.com.cn --agree-tos --no-eff-email --expand
|
证书生成的位置:
/data/certbot/conf/live/jellybeans.com.cn/文件夹下,里面包含:
fullchain.pem
privkey.pem
三、自动续期
再ECS中执行以下shell命令:
再crontab中填写如下命令:
1
| 0 3 * * * docker run --rm -v /data/certbot/conf:/etc/letsencrypt -v /data/certbot/www:/var/www/certbot certbot/certbot renew --quiet --deploy-hook "docker exec my-nginx nginx -s reload"
|
四、修改完Nginx配置文件重启
1
| docker exec jellybeans_portal nginx -s reload
|