HTTPS for a container: a certificate and a domain

For an application running in a container to show the padlock, you need a domain pointing at the VPS and a certificate. The most common route is nginx in front of the container (here is how to set it up) and certbot asking Let’s Encrypt for a free certificate and renewing it. On a VPS running Ubuntu and Docker there is no cPanel AutoSSL: the certificate and its renewal are yours.

With nginx and certbot

1 Check the DNS. The name (say app.yourcompany.com) must point to the VPS IP, and to no other: if there is also an AAAA record (IPv6) pointing elsewhere, validation fails. See how to check a domain’s DNS.
2 Open ports 80 and 443. Validation runs over port 80, so it has to be reachable from outside even if everything moves to 443 afterwards. See ports and firewall.
3 Install certbot with the nginx plugin. On Ubuntu 22.04: sudo apt install certbot python3-certbot-nginxThe certbot site (certbot.eff.org) also gives the method they recommend for each system; follow whatever it says there.
4 Request the certificate: sudo certbot --nginx -d app.yourcompany.comCertbot asks for an e-mail, validates the domain, edits the nginx file to use the certificate, and asks whether to redirect HTTP to HTTPS. Accept the redirect.
5 Test the renewal. Short-lived certificates are by design. Renewal is automatic, but prove it: sudo certbot renew --dry-runIf it finishes without errors, it is sorted. To see when each certificate ends: sudo certbot certificates.
6 Tell the application it sits behind HTTPS. nginx already sends the X-Forwarded-Proto header. The application has to respect it, or it will build http:// addresses and the padlock is lost to mixed content.

Other ways to get HTTPS

Option How it works Worth knowing
nginx + certbot on the server Certbot runs on the VPS and edits nginx. The most common and best documented. Renewal is a system timer.
Caddy A web server that obtains and renews certificates by itself. Less configuration, but one more program to learn and maintain.
Traefik A proxy that reads your containers and handles certificates. Built for many containers. The configuration is yours.
Cloudflare in front The visitor speaks HTTPS to Cloudflare. You still need HTTPS between Cloudflare and the VPS: see SSL at Cloudflare.
If validation fails, do not retry in a loop. Let’s Encrypt limits failed attempts. Fix the cause (DNS not propagated yet, port 80 closed, another service using 80 or 443) and, while you rehearse, use --dry-run, which does not spend your allowance. A domain you have only just pointed can take a while to propagate: how long DNS changes take to propagate.
A container listening on 80 or 443 breaks nginx. If nginx will not start with “address already in use”, another program has that port. Find out who: sudo ss -tlnp. And if your main site at yourcompany.com lives somewhere else, do not touch the nameservers of the whole domain: create just the subdomain, as in domain with us, site somewhere else.

Domain with us and the A record does not seem to work? Tell us the name and the VPS IP, and we will check the DNS.

Open a support ticket

SEE ALSO

Nginx as a reverse proxy in front of a container

DNS records explained: A, CNAME, MX, TXT and TTL

How long DNS changes take to propagate

SSL certificates

RECOMMENDED PRODUCT

Register your .com domain

Secure your company name before someone else registers it. from £13.60/yr

Search a domain
  • 0 Users Found This Useful
Was this answer helpful?