Skip to content

Repository files navigation

README

Overview

An orchestrated deployment of a sample web app and reverse proxy with generated Let's Encrypt certificates.

It creates the following containers:

  • Ephemeral Git clone container to fetch an example web app https://github.com/dockersamples/linux_tweet_app.
  • Ephemeral Certbot (Let's Encrypt client) container to generate certificates for the given domain name and email address.
  • Sidecar Cerbot monitor container to renew certificates when expiration time approaches.
  • Sample Web app bound to localhost with healthcheck.
  • Nginx proxy listening on public socket. Redirects port 80 to 443 and enables SSL using the Certbot-provided certificates with healthcheck.
  • Basic E2E functional tests to verify successful connection, 80-to-443 redirection and matching certificate CN.

Prerequisites

The environment can be spun up on any host that supports the bash shell and runs a Docker server. All actions runs within Docker containers so there are no other external dependencies at the host level. The host must be accessible over public internet on ports 80 and 443 with a valid public DNS record.

Manual Usage

The following scripts can be used to start, test and stop the deployment:

  • start-services.sh: Expects -d domain and -e email parameters. Deploys all services in the environment and calls e2e tests.

    Usage example:

    ./start-services.sh -d example.com -e admin@example.com
    

    Note:Certbot (Let's Encrypt client) will not issue certificates for private or invalid domains. A real domain name is expected and the host that its DNS record resolves to is challenged. The system that runs this environment must be publicly accessible on the published address from Let's Encrypt systems.

  • stop-services.sh: Stops all docker containers which were spun up by start-services.sh.

    Note: Artifacts such as container layers, images and networks will remain on the Docker host even after executing the stop script. The command docker system prune can be used to clean up storage space.

  • e2e-tests.sh: Expects parameter -d domain and runs basic tests against the target domain/web service that validate the environment's functionality: response code, redirection and matching certificate CN.

Automated Deployment

The environment can be deployed on a target host via SSH using the included Ansible playbook.

ansible-playbook playbook.yml --private-key=/path/to/reverse-proxy.pem -u username -i DOMAIN, --extra-vars "email=EMAIL"

DOMAIN is the hostname of the web server to be used as deployment target and certificate CN. EMAIL is the mailbox address to be associated with the certificate.

Runtime State

The gitclone, certbot and e2etests containers only run ephemerally. The persistent containers that can be found in the docker ps output once the environment is fully initiallized are:

  • nginx: Serves the public endpoint and acts as reverse proxy to the linux_tweet_app. Reloads periodically to pick up new certificates if needed.
  • linux_tweet_app: Binds on local endpoint and serves the app site.
  • certbot_renew: Monitors certificate validity and renews them if needed.
% docker ps
CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES
9092794a430e test-nginx "/docker-entrypoint.…" 57 minutes ago Up 52 seconds (healthy) 0.0.0.0:80->80/tcp, 0.0.0.0:443->443/tcp test-nginx-1
405c6c3d92da test-linux_tweet_app "/docker-entrypoint.…" 57 minutes ago Up 53 seconds (healthy) 443/tcp, 127.0.0.1:8080->80/tcp test-linux_tweet_app-1
38dfc2d9c054 test-certbot_renew "/bin/sh /renewloop.…" 57 minutes ago Up 53 seconds 80/tcp, 443/tcp test-certbot_renew-1

Diagram

diagram

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
GitHub - kostasb/reverse-proxy · GitHub
Skip to content

Repository files navigation

README

Overview

An orchestrated deployment of a sample web app and reverse proxy with generated Let's Encrypt certificates.

It creates the following containers:

  • Ephemeral Git clone container to fetch an example web app https://github.com/dockersamples/linux_tweet_app.
  • Ephemeral Certbot (Let's Encrypt client) container to generate certificates for the given domain name and email address.
  • Sidecar Cerbot monitor container to renew certificates when expiration time approaches.
  • Sample Web app bound to localhost with healthcheck.
  • Nginx proxy listening on public socket. Redirects port 80 to 443 and enables SSL using the Certbot-provided certificates with healthcheck.
  • Basic E2E functional tests to verify successful connection, 80-to-443 redirection and matching certificate CN.

Prerequisites

The environment can be spun up on any host that supports the bash shell and runs a Docker server. All actions runs within Docker containers so there are no other external dependencies at the host level. The host must be accessible over public internet on ports 80 and 443 with a valid public DNS record.

Manual Usage

The following scripts can be used to start, test and stop the deployment:

  • start-services.sh: Expects -d domain and -e email parameters. Deploys all services in the environment and calls e2e tests.

    Usage example:

    ./start-services.sh -d example.com -e admin@example.com
    

    Note:Certbot (Let's Encrypt client) will not issue certificates for private or invalid domains. A real domain name is expected and the host that its DNS record resolves to is challenged. The system that runs this environment must be publicly accessible on the published address from Let's Encrypt systems.

  • stop-services.sh: Stops all docker containers which were spun up by start-services.sh.

    Note: Artifacts such as container layers, images and networks will remain on the Docker host even after executing the stop script. The command docker system prune can be used to clean up storage space.

  • e2e-tests.sh: Expects parameter -d domain and runs basic tests against the target domain/web service that validate the environment's functionality: response code, redirection and matching certificate CN.

Automated Deployment

The environment can be deployed on a target host via SSH using the included Ansible playbook.

ansible-playbook playbook.yml --private-key=/path/to/reverse-proxy.pem -u username -i DOMAIN, --extra-vars "email=EMAIL"

DOMAIN is the hostname of the web server to be used as deployment target and certificate CN. EMAIL is the mailbox address to be associated with the certificate.

Runtime State

The gitclone, certbot and e2etests containers only run ephemerally. The persistent containers that can be found in the docker ps output once the environment is fully initiallized are:

  • nginx: Serves the public endpoint and acts as reverse proxy to the linux_tweet_app. Reloads periodically to pick up new certificates if needed.
  • linux_tweet_app: Binds on local endpoint and serves the app site.
  • certbot_renew: Monitors certificate validity and renews them if needed.
% docker ps
CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES
9092794a430e test-nginx "/docker-entrypoint.…" 57 minutes ago Up 52 seconds (healthy) 0.0.0.0:80->80/tcp, 0.0.0.0:443->443/tcp test-nginx-1
405c6c3d92da test-linux_tweet_app "/docker-entrypoint.…" 57 minutes ago Up 53 seconds (healthy) 443/tcp, 127.0.0.1:8080->80/tcp test-linux_tweet_app-1
38dfc2d9c054 test-certbot_renew "/bin/sh /renewloop.…" 57 minutes ago Up 53 seconds 80/tcp, 443/tcp test-certbot_renew-1

Diagram

diagram

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - kostasb/reverse-proxy · GitHub
Skip to content

Repository files navigation

README

Overview

An orchestrated deployment of a sample web app and reverse proxy with generated Let's Encrypt certificates.

It creates the following containers:

  • Ephemeral Git clone container to fetch an example web app https://github.com/dockersamples/linux_tweet_app.
  • Ephemeral Certbot (Let's Encrypt client) container to generate certificates for the given domain name and email address.
  • Sidecar Cerbot monitor container to renew certificates when expiration time approaches.
  • Sample Web app bound to localhost with healthcheck.
  • Nginx proxy listening on public socket. Redirects port 80 to 443 and enables SSL using the Certbot-provided certificates with healthcheck.
  • Basic E2E functional tests to verify successful connection, 80-to-443 redirection and matching certificate CN.

Prerequisites

The environment can be spun up on any host that supports the bash shell and runs a Docker server. All actions runs within Docker containers so there are no other external dependencies at the host level. The host must be accessible over public internet on ports 80 and 443 with a valid public DNS record.

Manual Usage

The following scripts can be used to start, test and stop the deployment:

  • start-services.sh: Expects -d domain and -e email parameters. Deploys all services in the environment and calls e2e tests.

    Usage example:

    ./start-services.sh -d example.com -e admin@example.com
    

    Note:Certbot (Let's Encrypt client) will not issue certificates for private or invalid domains. A real domain name is expected and the host that its DNS record resolves to is challenged. The system that runs this environment must be publicly accessible on the published address from Let's Encrypt systems.

  • stop-services.sh: Stops all docker containers which were spun up by start-services.sh.

    Note: Artifacts such as container layers, images and networks will remain on the Docker host even after executing the stop script. The command docker system prune can be used to clean up storage space.

  • e2e-tests.sh: Expects parameter -d domain and runs basic tests against the target domain/web service that validate the environment's functionality: response code, redirection and matching certificate CN.

Automated Deployment

The environment can be deployed on a target host via SSH using the included Ansible playbook.

ansible-playbook playbook.yml --private-key=/path/to/reverse-proxy.pem -u username -i DOMAIN, --extra-vars "email=EMAIL"

DOMAIN is the hostname of the web server to be used as deployment target and certificate CN. EMAIL is the mailbox address to be associated with the certificate.

Runtime State

The gitclone, certbot and e2etests containers only run ephemerally. The persistent containers that can be found in the docker ps output once the environment is fully initiallized are:

  • nginx: Serves the public endpoint and acts as reverse proxy to the linux_tweet_app. Reloads periodically to pick up new certificates if needed.
  • linux_tweet_app: Binds on local endpoint and serves the app site.
  • certbot_renew: Monitors certificate validity and renews them if needed.
% docker ps
CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES
9092794a430e test-nginx "/docker-entrypoint.…" 57 minutes ago Up 52 seconds (healthy) 0.0.0.0:80->80/tcp, 0.0.0.0:443->443/tcp test-nginx-1
405c6c3d92da test-linux_tweet_app "/docker-entrypoint.…" 57 minutes ago Up 53 seconds (healthy) 443/tcp, 127.0.0.1:8080->80/tcp test-linux_tweet_app-1
38dfc2d9c054 test-certbot_renew "/bin/sh /renewloop.…" 57 minutes ago Up 53 seconds 80/tcp, 443/tcp test-certbot_renew-1

Diagram

diagram

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - kostasb/reverse-proxy · GitHub
Skip to content

Repository files navigation

README

Overview

An orchestrated deployment of a sample web app and reverse proxy with generated Let's Encrypt certificates.

It creates the following containers:

  • Ephemeral Git clone container to fetch an example web app https://github.com/dockersamples/linux_tweet_app.
  • Ephemeral Certbot (Let's Encrypt client) container to generate certificates for the given domain name and email address.
  • Sidecar Cerbot monitor container to renew certificates when expiration time approaches.
  • Sample Web app bound to localhost with healthcheck.
  • Nginx proxy listening on public socket. Redirects port 80 to 443 and enables SSL using the Certbot-provided certificates with healthcheck.
  • Basic E2E functional tests to verify successful connection, 80-to-443 redirection and matching certificate CN.

Prerequisites

The environment can be spun up on any host that supports the bash shell and runs a Docker server. All actions runs within Docker containers so there are no other external dependencies at the host level. The host must be accessible over public internet on ports 80 and 443 with a valid public DNS record.

Manual Usage

The following scripts can be used to start, test and stop the deployment:

  • start-services.sh: Expects -d domain and -e email parameters. Deploys all services in the environment and calls e2e tests.

    Usage example:

    ./start-services.sh -d example.com -e admin@example.com
    

    Note:Certbot (Let's Encrypt client) will not issue certificates for private or invalid domains. A real domain name is expected and the host that its DNS record resolves to is challenged. The system that runs this environment must be publicly accessible on the published address from Let's Encrypt systems.

  • stop-services.sh: Stops all docker containers which were spun up by start-services.sh.

    Note: Artifacts such as container layers, images and networks will remain on the Docker host even after executing the stop script. The command docker system prune can be used to clean up storage space.

  • e2e-tests.sh: Expects parameter -d domain and runs basic tests against the target domain/web service that validate the environment's functionality: response code, redirection and matching certificate CN.

Automated Deployment

The environment can be deployed on a target host via SSH using the included Ansible playbook.

ansible-playbook playbook.yml --private-key=/path/to/reverse-proxy.pem -u username -i DOMAIN, --extra-vars "email=EMAIL"

DOMAIN is the hostname of the web server to be used as deployment target and certificate CN. EMAIL is the mailbox address to be associated with the certificate.

Runtime State

The gitclone, certbot and e2etests containers only run ephemerally. The persistent containers that can be found in the docker ps output once the environment is fully initiallized are:

  • nginx: Serves the public endpoint and acts as reverse proxy to the linux_tweet_app. Reloads periodically to pick up new certificates if needed.
  • linux_tweet_app: Binds on local endpoint and serves the app site.
  • certbot_renew: Monitors certificate validity and renews them if needed.
% docker ps
CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES
9092794a430e test-nginx "/docker-entrypoint.…" 57 minutes ago Up 52 seconds (healthy) 0.0.0.0:80->80/tcp, 0.0.0.0:443->443/tcp test-nginx-1
405c6c3d92da test-linux_tweet_app "/docker-entrypoint.…" 57 minutes ago Up 53 seconds (healthy) 443/tcp, 127.0.0.1:8080->80/tcp test-linux_tweet_app-1
38dfc2d9c054 test-certbot_renew "/bin/sh /renewloop.…" 57 minutes ago Up 53 seconds 80/tcp, 443/tcp test-certbot_renew-1

Diagram

diagram

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' GitHub - kostasb/reverse-proxy · GitHub
Skip to content

Repository files navigation

README

Overview

An orchestrated deployment of a sample web app and reverse proxy with generated Let's Encrypt certificates.

It creates the following containers:

  • Ephemeral Git clone container to fetch an example web app https://github.com/dockersamples/linux_tweet_app.
  • Ephemeral Certbot (Let's Encrypt client) container to generate certificates for the given domain name and email address.
  • Sidecar Cerbot monitor container to renew certificates when expiration time approaches.
  • Sample Web app bound to localhost with healthcheck.
  • Nginx proxy listening on public socket. Redirects port 80 to 443 and enables SSL using the Certbot-provided certificates with healthcheck.
  • Basic E2E functional tests to verify successful connection, 80-to-443 redirection and matching certificate CN.

Prerequisites

The environment can be spun up on any host that supports the bash shell and runs a Docker server. All actions runs within Docker containers so there are no other external dependencies at the host level. The host must be accessible over public internet on ports 80 and 443 with a valid public DNS record.

Manual Usage

The following scripts can be used to start, test and stop the deployment:

  • start-services.sh: Expects -d domain and -e email parameters. Deploys all services in the environment and calls e2e tests.

    Usage example:

    ./start-services.sh -d example.com -e admin@example.com
    

    Note:Certbot (Let's Encrypt client) will not issue certificates for private or invalid domains. A real domain name is expected and the host that its DNS record resolves to is challenged. The system that runs this environment must be publicly accessible on the published address from Let's Encrypt systems.

  • stop-services.sh: Stops all docker containers which were spun up by start-services.sh.

    Note: Artifacts such as container layers, images and networks will remain on the Docker host even after executing the stop script. The command docker system prune can be used to clean up storage space.

  • e2e-tests.sh: Expects parameter -d domain and runs basic tests against the target domain/web service that validate the environment's functionality: response code, redirection and matching certificate CN.

Automated Deployment

The environment can be deployed on a target host via SSH using the included Ansible playbook.

ansible-playbook playbook.yml --private-key=/path/to/reverse-proxy.pem -u username -i DOMAIN, --extra-vars "email=EMAIL"

DOMAIN is the hostname of the web server to be used as deployment target and certificate CN. EMAIL is the mailbox address to be associated with the certificate.

Runtime State

The gitclone, certbot and e2etests containers only run ephemerally. The persistent containers that can be found in the docker ps output once the environment is fully initiallized are:

  • nginx: Serves the public endpoint and acts as reverse proxy to the linux_tweet_app. Reloads periodically to pick up new certificates if needed.
  • linux_tweet_app: Binds on local endpoint and serves the app site.
  • certbot_renew: Monitors certificate validity and renews them if needed.
% docker ps
CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES
9092794a430e test-nginx "/docker-entrypoint.…" 57 minutes ago Up 52 seconds (healthy) 0.0.0.0:80->80/tcp, 0.0.0.0:443->443/tcp test-nginx-1
405c6c3d92da test-linux_tweet_app "/docker-entrypoint.…" 57 minutes ago Up 53 seconds (healthy) 443/tcp, 127.0.0.1:8080->80/tcp test-linux_tweet_app-1
38dfc2d9c054 test-certbot_renew "/bin/sh /renewloop.…" 57 minutes ago Up 53 seconds 80/tcp, 443/tcp test-certbot_renew-1

Diagram

diagram

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - kostasb/reverse-proxy · GitHub
Skip to content

Repository files navigation

README

Overview

An orchestrated deployment of a sample web app and reverse proxy with generated Let's Encrypt certificates.

It creates the following containers:

  • Ephemeral Git clone container to fetch an example web app https://github.com/dockersamples/linux_tweet_app.
  • Ephemeral Certbot (Let's Encrypt client) container to generate certificates for the given domain name and email address.
  • Sidecar Cerbot monitor container to renew certificates when expiration time approaches.
  • Sample Web app bound to localhost with healthcheck.
  • Nginx proxy listening on public socket. Redirects port 80 to 443 and enables SSL using the Certbot-provided certificates with healthcheck.
  • Basic E2E functional tests to verify successful connection, 80-to-443 redirection and matching certificate CN.

Prerequisites

The environment can be spun up on any host that supports the bash shell and runs a Docker server. All actions runs within Docker containers so there are no other external dependencies at the host level. The host must be accessible over public internet on ports 80 and 443 with a valid public DNS record.

Manual Usage

The following scripts can be used to start, test and stop the deployment:

  • start-services.sh: Expects -d domain and -e email parameters. Deploys all services in the environment and calls e2e tests.

    Usage example:

    ./start-services.sh -d example.com -e admin@example.com
    

    Note:Certbot (Let's Encrypt client) will not issue certificates for private or invalid domains. A real domain name is expected and the host that its DNS record resolves to is challenged. The system that runs this environment must be publicly accessible on the published address from Let's Encrypt systems.

  • stop-services.sh: Stops all docker containers which were spun up by start-services.sh.

    Note: Artifacts such as container layers, images and networks will remain on the Docker host even after executing the stop script. The command docker system prune can be used to clean up storage space.

  • e2e-tests.sh: Expects parameter -d domain and runs basic tests against the target domain/web service that validate the environment's functionality: response code, redirection and matching certificate CN.

Automated Deployment

The environment can be deployed on a target host via SSH using the included Ansible playbook.

ansible-playbook playbook.yml --private-key=/path/to/reverse-proxy.pem -u username -i DOMAIN, --extra-vars "email=EMAIL"

DOMAIN is the hostname of the web server to be used as deployment target and certificate CN. EMAIL is the mailbox address to be associated with the certificate.

Runtime State

The gitclone, certbot and e2etests containers only run ephemerally. The persistent containers that can be found in the docker ps output once the environment is fully initiallized are:

  • nginx: Serves the public endpoint and acts as reverse proxy to the linux_tweet_app. Reloads periodically to pick up new certificates if needed.
  • linux_tweet_app: Binds on local endpoint and serves the app site.
  • certbot_renew: Monitors certificate validity and renews them if needed.
% docker ps
CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES
9092794a430e test-nginx "/docker-entrypoint.…" 57 minutes ago Up 52 seconds (healthy) 0.0.0.0:80->80/tcp, 0.0.0.0:443->443/tcp test-nginx-1
405c6c3d92da test-linux_tweet_app "/docker-entrypoint.…" 57 minutes ago Up 53 seconds (healthy) 443/tcp, 127.0.0.1:8080->80/tcp test-linux_tweet_app-1
38dfc2d9c054 test-certbot_renew "/bin/sh /renewloop.…" 57 minutes ago Up 53 seconds 80/tcp, 443/tcp test-certbot_renew-1

Diagram

diagram

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); })(); GitHub - kostasb/reverse-proxy · GitHub
Skip to content

Repository files navigation

README

Overview

An orchestrated deployment of a sample web app and reverse proxy with generated Let's Encrypt certificates.

It creates the following containers:

  • Ephemeral Git clone container to fetch an example web app https://github.com/dockersamples/linux_tweet_app.
  • Ephemeral Certbot (Let's Encrypt client) container to generate certificates for the given domain name and email address.
  • Sidecar Cerbot monitor container to renew certificates when expiration time approaches.
  • Sample Web app bound to localhost with healthcheck.
  • Nginx proxy listening on public socket. Redirects port 80 to 443 and enables SSL using the Certbot-provided certificates with healthcheck.
  • Basic E2E functional tests to verify successful connection, 80-to-443 redirection and matching certificate CN.

Prerequisites

The environment can be spun up on any host that supports the bash shell and runs a Docker server. All actions runs within Docker containers so there are no other external dependencies at the host level. The host must be accessible over public internet on ports 80 and 443 with a valid public DNS record.

Manual Usage

The following scripts can be used to start, test and stop the deployment:

  • start-services.sh: Expects -d domain and -e email parameters. Deploys all services in the environment and calls e2e tests.

    Usage example:

    ./start-services.sh -d example.com -e admin@example.com
    

    Note:Certbot (Let's Encrypt client) will not issue certificates for private or invalid domains. A real domain name is expected and the host that its DNS record resolves to is challenged. The system that runs this environment must be publicly accessible on the published address from Let's Encrypt systems.

  • stop-services.sh: Stops all docker containers which were spun up by start-services.sh.

    Note: Artifacts such as container layers, images and networks will remain on the Docker host even after executing the stop script. The command docker system prune can be used to clean up storage space.

  • e2e-tests.sh: Expects parameter -d domain and runs basic tests against the target domain/web service that validate the environment's functionality: response code, redirection and matching certificate CN.

Automated Deployment

The environment can be deployed on a target host via SSH using the included Ansible playbook.

ansible-playbook playbook.yml --private-key=/path/to/reverse-proxy.pem -u username -i DOMAIN, --extra-vars "email=EMAIL"

DOMAIN is the hostname of the web server to be used as deployment target and certificate CN. EMAIL is the mailbox address to be associated with the certificate.

Runtime State

The gitclone, certbot and e2etests containers only run ephemerally. The persistent containers that can be found in the docker ps output once the environment is fully initiallized are:

  • nginx: Serves the public endpoint and acts as reverse proxy to the linux_tweet_app. Reloads periodically to pick up new certificates if needed.
  • linux_tweet_app: Binds on local endpoint and serves the app site.
  • certbot_renew: Monitors certificate validity and renews them if needed.
% docker ps
CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES
9092794a430e test-nginx "/docker-entrypoint.…" 57 minutes ago Up 52 seconds (healthy) 0.0.0.0:80->80/tcp, 0.0.0.0:443->443/tcp test-nginx-1
405c6c3d92da test-linux_tweet_app "/docker-entrypoint.…" 57 minutes ago Up 53 seconds (healthy) 443/tcp, 127.0.0.1:8080->80/tcp test-linux_tweet_app-1
38dfc2d9c054 test-certbot_renew "/bin/sh /renewloop.…" 57 minutes ago Up 53 seconds 80/tcp, 443/tcp test-certbot_renew-1

Diagram

diagram

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages