Hello, I wan’t to ask if anyone knows of a good alternative for certbot for acquiring ssl certificates for nginx.
Certbot isn’t good anymore for me since I started using crowdsec with nginx bouncer that uses lua block’s inside nginx config that cerbot can’t parse, making it not work anymore.
I use nginx because it’s the one I know the best and for my use case work’s the best. ( Hosting both program’s directly on metal and docker container’s )
if you are open to learn something new: Caddy webserver has a dead simple config, fetches tls certs by default for you and works with crowdsec too
Caddy is fantastic, incredibly easy to configure and just works out of the box beautifully.
Do you have it on host or container. I’m thinking abour switching to caddy on my host and replacing nginx with it but just wan’t to hear your experience with it.
I’m open to using sothing like caddy or traefic, but my issue is I have a mix of packages hosted directly on system and in docker container’s and as such need to proxy them all.
That’s why I’m not using caddy or traefic.
Edit: rn my mix consists of about 16 diff containeraized stuff and another 4-5 not containerized stuff.
Edit2: Just now realized that they can be used on the host system’s also. Would you recommend traefic or caddy?
I’m using Caddy (sometimes in a container or most of the time as system package) as reverse proxy mostly for containers
I try to minimize non-container services but they work well with Caddy too
Traefik is a tad more complex (still nowhere near Apache2 levels though) but scales more easily espcially if you only run containers and start/stop them programatically
Update: I have moved to caddy, planned a switch either way and this just pushed me to do it.
Acronyms, initialisms, abbreviations, contractions, and other phrases which expand to something larger, that I’ve seen in this thread:
Fewer Letters | More Letters |
---|---|
CA | (SSL) Certificate Authority |
DNS | Domain Name Service/System |
HTTP | Hypertext Transfer Protocol, the Web |
SSL | Secure Sockets Layer, for transparent encryption |
nginx | Popular HTTP server |
3 acronyms in this thread; the most compressed thread commented on today has 14 acronyms.
[Thread #452 for this sub, first seen 24th Jan 2024, 12:25] [FAQ] [Full list] [Contact] [Source code]
You could not use the dns challenge?
Requires me to add cname record’s, which beats the purpose of automation honestly. Will most likelly move to caddy.
I thought acme or certbot could handle the DNS entries with an API call to your DNS provider.
It may require another plugin though. Googling some variation of certbot acme automate DNS challenge will give you a dozen tutorials.
Certbot has no support for vultr dns, not even with plugins. Already check.