Skip to content

letsencrypt / SWAG

Logo

Description

This container sets up an Nginx webserver and reverse proxy with php support and a built-in letsencrypt client that automates free SSL server certificate generation and renewal processes. It also contains fail2ban for intrusion prevention.

Notes

Before running this container, make sure that the url and subdomains are properly forwarded to this container's host.* - Port 443 on the internet side of the router should be forwarded to this container's port 443.

  • - If you need a dynamic dns provider, you can use the free provider duckdns.org where the url will be yoursubdomain.duckdns.org and the subdomains can be www,ftp,cloud
  • - The container detects changes to url and subdomains, revokes existing certs and generates new ones during start.
  • - It also detects changes to the DHLEVEL parameter and replaces the dhparams file.
  • - If you'd like to password protect your sites, you can use htpasswd. Run the following command on your host to generate the htpasswd file docker exec -it letsencrypt htpasswd -c /config/nginx/.htpasswd <username>

Image

linuxserver/swag:latest

Categories

  • Proxyserver

Ports

  • 80/tcp
  • 443/tcp

Volumes

ContainerBind
/config/opt/appdata/letsencrypt

Environment Variables

NameLabelDefaultDescription
EMAILEMAIL````````````
URLURL````````````
SUBDOMAINSSUBDOMAINS````````````
ONLY_SUBDOMAINSONLY_SUBDOMAINS````````````
DHLEVELDHLEVEL````````````
PUIDPUID1000``````
PGIDPGID100``````
VALIDATIONVALIDATION````````````
DNSPLUGINDNSPLUGIN````````````

Labels

KeyValue
traefik.enabletrue
traefik.http.routers.letsencryptswag.ruleHost(`letsencryptswag.{$TRAEFIK_INGRESS_DOMAIN}`)
traefik.http.routers.letsencryptswag.entrypointshttps
traefik.http.services.letsencryptswag.loadbalancer.server.port5299
traefik.http.routers.letsencryptswag.tlstrue
traefik.http.routers.letsencryptswag.tls.certresolverdefault
traefik.http.routers.letsencryptswag.middlewarestraefik-forward-auth
mafl.enabletrue
mafl.titleLet's Encrypt / SWAG
mafl.descriptionThis container sets up an Nginx webserver and reverse proxy with php support and a built-in letsencrypt client that automates free SSL server certificate generation and renewal processes.
mafl.linkhttps://letsencryptswag.{$TRAEFIK_INGRESS_DOMAIN}
mafl.icon.wraptrue
mafl.icon.color#007acc
mafl.status.enabledtrue
mafl.status.interval60
mafl.groupProxyserver
mafl.icon.urlhttps://raw.githubusercontent.com/Qballjos/portainer_templates/master/Images/letsencrypt.png

Licensed under the MIT License. Free for all use cases. For enterprise or academic support, please reach out to us.