# Certbot --nginx generate and install but my container is restarting in loop with nginx: \[emerg\] bind() to 0.0.0.0:443 failed (98: Address in use) and nginx: \[emerg\] bind() to 0.0.0.0:80 failed (98: Address in use)

**URL:** <https://community.letsencrypt.org/t/certbot-nginx-generate-and-install-but-my-container-is-restarting-in-loop-with-nginx-emerg-bind-to-0-0-0-0-443-failed-98-address-in-use-and-nginx-emerg-bind-to-0-0-0-0-80-failed-98-address-in-use/169973>\
**Category:** Help\
**Created:** [January 18, 2022, 9:49pm UTC](https://community.letsencrypt.org/t/certbot-nginx-generate-and-install-but-my-container-is-restarting-in-loop-with-nginx-emerg-bind-to-0-0-0-0-443-failed-98-address-in-use-and-nginx-emerg-bind-to-0-0-0-0-80-failed-98-address-in-use/169973 "2022-01-18T21:49:57Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![netogildo](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/netogildo/32/57577_2.png) [@netogildo](https://community.letsencrypt.org/u/netogildo)\
**Post date:** [January 18, 2022, 9:49pm UTC](https://community.letsencrypt.org/t/certbot-nginx-generate-and-install-but-my-container-is-restarting-in-loop-with-nginx-emerg-bind-to-0-0-0-0-443-failed-98-address-in-use-and-nginx-emerg-bind-to-0-0-0-0-80-failed-98-address-in-use/169973/1 "2022-01-18T21:49:57Z")

</div>

I've tried this solution [https://geko.cloud/en/nginx-letsencrypt-certbot-docker-alpine](https://geko.cloud/en/nginx-letsencrypt-certbot-docker-alpine) , but get an error on nginx and is restarting always.

The error reported is:  
app-client\_1 | 2022/01/18 21:21:55 [emerg] 22#22: bind() to 0.0.0.0:443 failed (98: Address in use)  
app-client\_1 | nginx: [emerg] bind() to 0.0.0.0:443 failed (98: Address in use)  
app-client\_1 | 2022/01/18 21:21:55 [emerg] 22#22: bind() to 0.0.0.0:80 failed (98: Address in use)  
app-client\_1 | nginx: [emerg] bind() to 0.0.0.0:80 failed (98: Address in use)

The ssl works, but my docker container is restarting in loop.

In my nginx container, when I set in my entrypoint.sh to run the certbot command, still doing the restart, mas but if I remove and run the same command after the container start, it works.

nginx.conf:

```nohighlight
user nginx;

# auto detects a good number of processes to run
worker_processes auto;

#Provides the configuration file context in which the directives that affect connection processing are specified.
events {
    # Sets the maximum number of simultaneous connections that can be opened by a worker process.
    worker_connections 8000;
    # Tells the worker to accept multiple connections at a time
    multi_accept on;
}

http {

    server {
        listen 80;
        server_name teste-4.codepec.com;

        location / {
            root /var/www;
            index index.html index.htm;
        }

        error_page 500 502 503 504 /50x.html;
        location = /50x.html {
            root /usr/share/nginx/html;
        }

        location /api/ {
            proxy_read_timeout 300;
            proxy_connect_timeout 300;
            proxy_redirect off;

            proxy_http_version 1.1;

            proxy_set_header Host $http_host;
            proxy_set_header X-Real-IP $remote_addr;
            proxy_set_header X-Forwarded-Ssl on;
            proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
            proxy_set_header X-Forwarded-Proto $scheme;

            # redirect api calls to the api container, running on the same docker-compose
            proxy_pass http://app-server:8380/;
        }
    }

}

```

entrypoint.sh:

```nohighlight
#!/usr/bin/env bash

envsubst < /etc/nginx/templates/nginx.conf.template > /etc/nginx/nginx.conf
certbot --nginx -d ${DOMAIN} --agree-tos -n -m "${CERTBOT_EMAIL}"
crond -f -d 8 &
nginx -g "daemon off;"

```

 ![Captura de Tela 2022-01-18 às 18.45.56](https://global.discourse-cdn.com/letsencrypt/original/3X/8/e/8e56de00e53b5cab597fc6991349812d0f73913d.png)

My domain is: [codepec.com](http://codepec.com)

The client container is running nginx:1.21.5-alpine

The gerenation of the certs works, but the restart I'cat resolve.

---

<div class="post-metadata">

**Author:** ![orangepizza](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/orangepizza/32/19597_2.png) [@orangepizza](https://community.letsencrypt.org/u/orangepizza)\
**Post date:** [January 18, 2022, 10:03pm UTC](https://community.letsencrypt.org/t/certbot-nginx-generate-and-install-but-my-container-is-restarting-in-loop-with-nginx-emerg-bind-to-0-0-0-0-443-failed-98-address-in-use-and-nginx-emerg-bind-to-0-0-0-0-80-failed-98-address-in-use/169973/2 "2022-01-18T22:03:42Z")

</div>

something already running on that port (probably another nginx process) inside your docker image

---

<div class="post-metadata">

**Author:** ![netogildo](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/netogildo/32/57577_2.png) [@netogildo](https://community.letsencrypt.org/u/netogildo)\
**Post date:** [January 18, 2022, 10:19pm UTC](https://community.letsencrypt.org/t/certbot-nginx-generate-and-install-but-my-container-is-restarting-in-loop-with-nginx-emerg-bind-to-0-0-0-0-443-failed-98-address-in-use-and-nginx-emerg-bind-to-0-0-0-0-80-failed-98-address-in-use/169973/3 "2022-01-18T22:19:58Z")

</div>

What I don't understand is why it works if I remove the line of certbot from my entrypoint.sh and run the same after my container is up.

If I change my entrypoint.sh to this..

```nohighlight
#!/usr/bin/env bash

envsubst < /etc/nginx/templates/nginx.conf.template > /etc/nginx/nginx.conf
#certbot --nginx -d ${DOMAIN} --agree-tos -n -m "${CERTBOT_EMAIL}"
crond -f -d 8 &
nginx -g "daemon off;"

```

and after start I enter in the container with docker exec -it ... bash and run mannualy:

```nohighlight
certbot --nginx -d teste-4.codepec.com --agree-tos -n -m "myemail@email.com"

```

just works and container not restarts:

 ![Captura de Tela 2022-01-18 às 19.18.10](https://global.discourse-cdn.com/letsencrypt/original/3X/4/1/416a29d0e58668f2f51d5b6b329c4bb03b83bd2a.png)

my container image is very simple:

```nohighlight
#### Stage 1: Build the react application
FROM node:16.13.2-alpine as build

# Configure the main working directory inside the docker image.
# This is the base directory used in any further RUN, COPY, and ENTRYPOINT
# commands.
WORKDIR /app

# Copy the package.json as well as the yarn-lock.json and install
# the dependencies. This is a separate step so the dependencies
# will be cached unless changes to one of those two files
# are made.
COPY package.json yarn.lock ./
RUN yarn install --network-timeout 1000000000

# Copy the main application
COPY . ./

ARG PROFILE
# Build the application
RUN yarn $PROFILE

#### Stage 2: Serve the React application from Nginx
FROM nginx:1.21.5-alpine

# Install certbot
RUN apk add --no-cache bash curl && \
    apk add --no-cache certbot certbot-nginx

# Copy the react build from Stage 1
COPY --from=build /app/build /var/www

# Copy renew cron script
COPY nginx/renew /etc/periodic/daily/renew
RUN chmod +x /etc/periodic/daily/renew

RUN mkdir /etc/letsencrypt

# Copy nginx script to set envsubst
COPY nginx/scripts/entrypoint.sh /entrypoint.sh
RUN chmod +x /entrypoint.sh

# Copy our custom nginx template config
COPY nginx/templates /etc/nginx/templates/

VOLUME /etc/letsencrypt

ENTRYPOINT ["/entrypoint.sh"]

```

---

<div class="post-metadata">

**Author:** ![orangepizza](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/orangepizza/32/19597_2.png) [@orangepizza](https://community.letsencrypt.org/u/orangepizza)\
**Post date:** [January 18, 2022, 10:44pm UTC](https://community.letsencrypt.org/t/certbot-nginx-generate-and-install-but-my-container-is-restarting-in-loop-with-nginx-emerg-bind-to-0-0-0-0-443-failed-98-address-in-use-and-nginx-emerg-bind-to-0-0-0-0-80-failed-98-address-in-use/169973/4 "2022-01-18T22:44:16Z")

</div>

that sounds like init script ran too early to run certbot, and containers internal script didn't expect nginx to be already started. put certbot command after nginx -g

> -------- 원본 이메일 --------  
> 발신: Gildo Neto via Let's Encrypt Community Support [letsencrypt@discoursemail.com](mailto:letsencrypt@discoursemail.com)  
> 날짜: 22/1/19 07:30 (GMT+09:00)  
> 받은 사람: [tjtncks@gmail.com](mailto:tjtncks@gmail.com)  
> 제목: [Let's Encrypt Community Support] [Help] Certbot --nginx generate and install but my container is restarting in loop with nginx: [emerg] bind() to 0.0.0.0:443 failed (98: Address in use) and nginx: [emerg] bind() to 0.0.0.0:80 failed (98: Address in use)
> 
> > ![](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/netogildo/45/57577_2.png "netogildo") | [netogildo](https://community.letsencrypt.org/u/netogildo)  
> > January 18 |
> > 
> > - | - |
> 
> What I don't understand is why it works if I remove the line of certbot from my entrypoint.sh and run the same after my container is up.
> 
> If I change my entrypoint.sh to this..
> 
> ```nohighlight
> #!/usr/bin/env bash
> 
> envsubst < /etc/nginx/templates/nginx.conf.template > /etc/nginx/nginx.conf
> 
> #certbot --nginx -d ${DOMAIN} --agree-tos -n -m "${CERTBOT_EMAIL}"
> 
> crond -f -d 8 &
> 
> nginx -g "daemon off;"
> 
> ```
> 
> and after start I enter in the container with docker exec -it ... bash and run mannualy:
> 
> ```nohighlight
> certbot --nginx -d teste-4.codepec.com --agree-tos -n -m "myemail@email.com"
> 
> ```
> 
> just works and container not restarts:
> 
> my container image is very simple:
> 
> ```nohighlight
> #### Stage 1: Build the react application
> 
> FROM node:16.13.2-alpine as build
> 
> # Configure the main working directory inside the docker image.
> 
> # This is the base directory used in any further RUN, COPY, and ENTRYPOINT
> 
> # commands.
> 
> WORKDIR /app
> 
> # Copy the package.json as well as the yarn-lock.json and install
> 
> # the dependencies. This is a separate step so the dependencies
> 
> # will be cached unless changes to one of those two files
> 
> # are made.
> 
> COPY package.json yarn.lock ./
> 
> RUN yarn install --network-timeout 1000000000
> 
> # Copy the main application
> 
> COPY . ./
> 
> ARG PROFILE
> 
> # Build the application
> 
> RUN yarn $PROFILE
> 
> #### Stage 2: Serve the React application from Nginx
> 
> FROM nginx:1.21.5-alpine
> 
> # Install certbot
> 
> RUN apk add --no-cache bash curl && \
> 
> apk add --no-cache certbot certbot-nginx
> 
> # Copy the react build from Stage 1
> 
> COPY --from=build /app/build /var/www
> 
> # Copy renew cron script
> 
> COPY nginx/renew /etc/periodic/daily/renew
> 
> RUN chmod +x /etc/periodic/daily/renew
> 
> RUN mkdir /etc/letsencrypt
> 
> # Copy nginx script to set envsubst
> 
> COPY nginx/scripts/entrypoint.sh /entrypoint.sh
> 
> RUN chmod +x /entrypoint.sh
> 
> # Copy our custom nginx template config
> 
> COPY nginx/templates /etc/nginx/templates/
> 
> VOLUME /etc/letsencrypt
> 
> ENTRYPOINT ["/entrypoint.sh"]
> 
> ```

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [January 19, 2022, 12:29am UTC](https://community.letsencrypt.org/t/certbot-nginx-generate-and-install-but-my-container-is-restarting-in-loop-with-nginx-emerg-bind-to-0-0-0-0-443-failed-98-address-in-use-and-nginx-emerg-bind-to-0-0-0-0-80-failed-98-address-in-use/169973/5 "2022-01-19T00:29:58Z")

</div>

> [@orangepizza](#):
>
> What I don't understand is why it works if I remove the line of certbot from my entrypoint.sh and run the same after my container is up.

Does it require a delay?

---

<div class="post-metadata">

**Author:** ![orangepizza](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/orangepizza/32/19597_2.png) [@orangepizza](https://community.letsencrypt.org/u/orangepizza)\
**Post date:** [January 19, 2022, 2:07am UTC](https://community.letsencrypt.org/t/certbot-nginx-generate-and-install-but-my-container-is-restarting-in-loop-with-nginx-emerg-bind-to-0-0-0-0-443-failed-98-address-in-use-and-nginx-emerg-bind-to-0-0-0-0-80-failed-98-address-in-use/169973/6 "2022-01-19T02:07:36Z")

</div>

not a delay but reorder. I think this may work. but it shouldn't run in container anyway: probably meet duplicate certificate rate limit fast. (look at that it needed to register new account each time)

```nohighlight
#!/usr/bin/env bash

envsubst < /etc/nginx/templates/nginx.conf.template > /etc/nginx/nginx.conf
crond -f -d 8 &
nginx -g "daemon off;"
certbot --nginx -d ${DOMAIN} --agree-tos -n -m "${CERTBOT_EMAIL}"

```

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [February 18, 2022, 2:07am UTC](https://community.letsencrypt.org/t/certbot-nginx-generate-and-install-but-my-container-is-restarting-in-loop-with-nginx-emerg-bind-to-0-0-0-0-443-failed-98-address-in-use-and-nginx-emerg-bind-to-0-0-0-0-80-failed-98-address-in-use/169973/7 "2022-02-18T02:07:47Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
