# Certification for a docker container

**URL:** <https://community.letsencrypt.org/t/certification-for-a-docker-container/208508>\
**Category:** Help\
**Created:** [November 17, 2023, 8:13pm UTC](https://community.letsencrypt.org/t/certification-for-a-docker-container/208508 "2023-11-17T20:13:21Z")\
**Posts on this page:** 16\
**Page:** 1

<div class="post-metadata">

**Author:** ![wisdomlight](https://avatars.discourse-cdn.com/v4/letter/w/b4bc9f/32.png) [@wisdomlight](https://community.letsencrypt.org/u/wisdomlight)\
**Post date:** [November 17, 2023, 8:13pm UTC](https://community.letsencrypt.org/t/certification-for-a-docker-container/208508/1 "2023-11-17T20:13:21Z")

</div>

[educc.duckdns.org](http://educc.duckdns.org)

Apache/2.4.57 (Debian)

OS 6.1.0-rpi6-rpi-v8

Root shell access - yes  
**Explanation of querry:**  
Currently, I have Nextcloud installed on rpi and it uses ports 80 and 443  
I want to install a service with docker container and this service needs to be certified for its web connection.  
Any advice please or recommended resources?

---

<div class="post-metadata">

**Author:** ![9peppe](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/9peppe/32/31596_2.png) [@9peppe](https://community.letsencrypt.org/u/9peppe)\
**Post date:** [November 17, 2023, 9:01pm UTC](https://community.letsencrypt.org/t/certification-for-a-docker-container/208508/2 "2023-11-17T21:01:09Z")

</div>

Only one service at a time can bind a port.

I have no idea what your system is currently doing. You can have multiple services on the same port by using a reverse proxy with multiple virtualhosts.

---

<div class="post-metadata">

**Author:** ![wisdomlight](https://avatars.discourse-cdn.com/v4/letter/w/b4bc9f/32.png) [@wisdomlight](https://community.letsencrypt.org/u/wisdomlight)\
**Post date:** [November 17, 2023, 9:08pm UTC](https://community.letsencrypt.org/t/certification-for-a-docker-container/208508/3 "2023-11-17T21:08:01Z")

</div>

Thanks  
For clarification - Nextcloud (without docker) installed and certified.  
Now I am trying to add a docker service which will need certification - all the online solutions explain the usage of nginx reverse proxy with various docker containers.  
I am trying to avoid the need to reinstall nextcloud within a docker container.

---

<div class="post-metadata">

**Author:** ![9peppe](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/9peppe/32/31596_2.png) [@9peppe](https://community.letsencrypt.org/u/9peppe)\
**Post date:** [November 17, 2023, 9:11pm UTC](https://community.letsencrypt.org/t/certification-for-a-docker-container/208508/4 "2023-11-17T21:11:53Z")

</div>

Please ignore whatever nginx proxy manager story they're selling you. That's usually a mess.

You can have your current webserver proxy a different fqdn to a different service. Just add a virtualhost (Apache) or a server block (nginx) and follow documentation/examples on how to reverse proxy another service.

---

<div class="post-metadata">

**Author:** ![wisdomlight](https://avatars.discourse-cdn.com/v4/letter/w/b4bc9f/32.png) [@wisdomlight](https://community.letsencrypt.org/u/wisdomlight)\
**Post date:** [November 17, 2023, 9:21pm UTC](https://community.letsencrypt.org/t/certification-for-a-docker-container/208508/5 "2023-11-17T21:21:47Z")

</div>

ok  
thnak you

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [November 17, 2023, 9:45pm UTC](https://community.letsencrypt.org/t/certification-for-a-docker-container/208508/6 "2023-11-17T21:45:08Z")

</div>

To clarify a little bit more: you'd run your services in Docker on different ports than your current Nextcloud webserver is running (80 and 443). I'm not that familiar with Docker, but I believe you can map external "listening" ports in Docker to different "internal" ports.

E.g., on the "outside" of docker, you could have:

- Nextcloud listening on 80 and 443;
- Docker service A listening externally on 81 and 444, mapped to internally 80 and 443 respectively;
- Docker service B listening externally on 82 and 445, mapped to internally 80 and 443 respectively;
- Et c.

Then, you could add a reverse proxy virtualhost in your Apache (which would be running your Nextcloud I assume) for those Docker services A and B, reverse proxying to `localhost:81` and `localhost:82` respectively.

Note that for connections to `localhost`, it's usually not required to have HTTPS. That's usually handled by the reverse proxy. So you could leave out the "444 -\> 443" and "445 -\> 443" stuff and just use the HTTP ports.

---

<div class="post-metadata">

**Author:** ![9peppe](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/9peppe/32/31596_2.png) [@9peppe](https://community.letsencrypt.org/u/9peppe)\
**Post date:** [November 17, 2023, 9:51pm UTC](https://community.letsencrypt.org/t/certification-for-a-docker-container/208508/7 "2023-11-17T21:51:00Z")

</div>

NB, if you want the service _not_ to be exposed on 81, 82, etc... bind ports and IP addresses (you have all 127.0.0.0/8 to play with, you can use 80 and 443 if the IP is different) and then reverse proxy using ip and port.

---

<div class="post-metadata">

**Author:** ![wisdomlight](https://avatars.discourse-cdn.com/v4/letter/w/b4bc9f/32.png) [@wisdomlight](https://community.letsencrypt.org/u/wisdomlight)\
**Post date:** [November 17, 2023, 9:51pm UTC](https://community.letsencrypt.org/t/certification-for-a-docker-container/208508/8 "2023-11-17T21:51:36Z")

</div>

> [@9peppe](#):
>
> You can have your current webserver proxy a different fqdn to a different service. Just add a virtualhost (Apache) or a server block (nginx) and follow documentation/examples on how to reverse proxy another service.

Really appreciate the details  
I am working on it  
thank you v much

---

<div class="post-metadata">

**Author:** ![wisdomlight](https://avatars.discourse-cdn.com/v4/letter/w/b4bc9f/32.png) [@wisdomlight](https://community.letsencrypt.org/u/wisdomlight)\
**Post date:** [November 17, 2023, 9:52pm UTC](https://community.letsencrypt.org/t/certification-for-a-docker-container/208508/9 "2023-11-17T21:52:01Z")

</div>

many many thanks  
very much appreciated

---

<div class="post-metadata">

**Author:** ![wisdomlight](https://avatars.discourse-cdn.com/v4/letter/w/b4bc9f/32.png) [@wisdomlight](https://community.letsencrypt.org/u/wisdomlight)\
**Post date:** [November 17, 2023, 9:56pm UTC](https://community.letsencrypt.org/t/certification-for-a-docker-container/208508/10 "2023-11-17T21:56:12Z")

</div>

> [@Osiris](#):
>
> Docker service A listening externally on 81 and 444, mapped to internally 80 and 443 respectively;

so it is the docker's 81 444 listening to the hosts 80 443 ?

---

<div class="post-metadata">

**Author:** ![wisdomlight](https://avatars.discourse-cdn.com/v4/letter/w/b4bc9f/32.png) [@wisdomlight](https://community.letsencrypt.org/u/wisdomlight)\
**Post date:** [November 17, 2023, 10:01pm UTC](https://community.letsencrypt.org/t/certification-for-a-docker-container/208508/11 "2023-11-17T22:01:55Z")

</div>

so I added this

```plaintext
<VirtualHost *:80>
        ServerName sherab.duckdns.org
        ProxyPass / http://localhost:xxxx/
        ProxyPassReverse / http://localhost:xxxx/

        ErrorLog ${APACHE_LOG_DIR}/sherab_error.log
        CustomLog ${APACHE_LOG_DIR}/sherab_access.log combined
</VirtualHost>

```

and I get to the docker service just fine  
now my problem is that the lockpad in firefox indicates the traffic is not secured  
I run  
`sudo /snap/bin/certbot certonly --standalone -d sherab.duckdns.org`  
and it seemed to work fine  
then I added this in /etc/apache2/sitesavailable/sherab.duckdns.org.conf

```plaintext
    ServerName sherab.duckdns.org

    SSLEngine on
    SSLCertificateFile /etc/letsencrypt/live/sherab.duckdns.org/fullchain.pem
    SSLCertificateKeyFile /etc/letsencrypt/live/sherab.duckdns.org/privkey.pem
    SSLCertificateChainFile /etc/letsencrypt/live/sherab.duckdns.org/chain.pem

    ProxyPass / http://localhost:5230/
    ProxyPassReverse / http://localhost:5230/

    ErrorLog ${APACHE_LOG_DIR}/sherab_error.log
    CustomLog ${APACHE_LOG_DIR}/sherab_access.log combined
</VirtualHost>

```

now the site is not reachable ☹

---

<div class="post-metadata">

**Author:** ![9peppe](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/9peppe/32/31596_2.png) [@9peppe](https://community.letsencrypt.org/u/9peppe)\
**Post date:** [November 17, 2023, 10:23pm UTC](https://community.letsencrypt.org/t/certification-for-a-docker-container/208508/12 "2023-11-17T22:23:06Z")

</div>

> [@wisdomlight](#):
>
> `sherab.duckdns.org`

I see your website. It's only missing a redirect from http to https.

 ![Screenshot_20231117-232208_Firefox](https://global.discourse-cdn.com/letsencrypt/original/3X/8/d/8d67fae8621770ce751acd40eadc4dffe7627869.png)

---

<div class="post-metadata">

**Author:** ![wisdomlight](https://avatars.discourse-cdn.com/v4/letter/w/b4bc9f/32.png) [@wisdomlight](https://community.letsencrypt.org/u/wisdomlight)\
**Post date:** [November 17, 2023, 10:26pm UTC](https://community.letsencrypt.org/t/certification-for-a-docker-container/208508/13 "2023-11-17T22:26:33Z")

</div>

> [@9peppe](#):
>
> I see your website. It's only missing a redirect from http to https.

thank you - I followed your point and realized I could do the http request

> [@9peppe](#):
>
> It's only missing a redirect from http to https.

how do I do that?  
just to show:

```nohighlight
/sites-available $ sudo /snap/bin/certbot certonly --standalone -d sherab.duckdns.org
Saving debug log to /var/log/letsencrypt/letsencrypt.log
Requesting a certificate for sherab.duckdns.org

Successfully received certificate.
Certificate is saved at: /etc/letsencrypt/live/sherab.duckdns.org/fullchain.pem
Key is saved at: /etc/letsencrypt/live/sherab.duckdns.org/privkey.pem
This certificate expires on 2024-02-15.
These files will be updated when the certificate renews.
Certbot has set up a scheduled task to automatically renew this certificate in the background.

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
If you like Certbot, please consider supporting our work by:
 * Donating to ISRG / Let's Encrypt: https://letsencrypt.org/donate
 * Donating to EFF: https://eff.org/donate-le
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
sherab@raspberrypi:/etc/apache2/sites-available $ sudo service apache2 start

```

---

<div class="post-metadata">

**Author:** ![9peppe](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/9peppe/32/31596_2.png) [@9peppe](https://community.letsencrypt.org/u/9peppe)\
**Post date:** [November 17, 2023, 10:28pm UTC](https://community.letsencrypt.org/t/certification-for-a-docker-container/208508/14 "2023-11-17T22:28:36Z")

</div>

> [@wisdomlight](#):
>
> how do I do that?

I think you can run `certbot enhance --redirect` but you'd have to check on that.

---

<div class="post-metadata">

**Author:** ![wisdomlight](https://avatars.discourse-cdn.com/v4/letter/w/b4bc9f/32.png) [@wisdomlight](https://community.letsencrypt.org/u/wisdomlight)\
**Post date:** [November 17, 2023, 10:29pm UTC](https://community.letsencrypt.org/t/certification-for-a-docker-container/208508/15 "2023-11-17T22:29:33Z")

</div>

ok thank you - I think I might go to bed now as it begins to be late for me  
I really appreciate your time and advice.  
Thank you  
🙏 💐

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [December 17, 2023, 10:30pm UTC](https://community.letsencrypt.org/t/certification-for-a-docker-container/208508/16 "2023-12-17T22:30:29Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
