aethercert
Linux and containers

Automated certificates for Docker containers

For a service running in a container, the Docker package copies the renewed certificate and key into the container through the Docker Engine API and tells the process to reload.

The deployment steps defined in this package's manifest.

At a glance

Package
docker-target 2.0.0
Compatibility
Docker Engine >=20.10 <30.0
Runs from
Any Windows or Linux agent with network access to it
Mechanism
REST API
Authentication
Local - no remote login
Capabilities
Import certificateImport private keyReload service
Deployment steps
copyCertificate → copyPrivateKey → restartContainer* → signalContainer*
Rollback
None
Key usage
No requirement

* conditional step

What it does

The agent on the Docker host talks to the Docker Engine over its local socket (or named pipe on Windows), copies the full chain and key into a directory inside the container, and then sends a signal to the main process - HUP by default - or restarts the container.

HUP reloads nginx and HAProxy; USR1 gracefully restarts Apache.

How it runs

  1. 01

    copyCertificate / copyPrivateKey

    Certificate and key are copied into the container directory.

  2. 02

    signalContainer

    The configured signal is sent to the main process (signal mode).

  3. 03

    restartContainer

    The container is restarted (restart mode).

What you configure

  • Docker Engine socket (default /var/run/docker.sock)
  • Container name or id
  • Directory and file names inside the container
  • After copying: signal (default HUP) or restart

Prerequisites

  • An agent on the Docker host with access to the Docker socket

Limitations

  • Files copied into a container do not survive re-creating it; mount a volume if the container is replaced regularly.

Doing it by hand

The documentation has a step-by-step guide for replacing this certificate manually - useful for a first install, or to see exactly what the package automates.

Manual replacement guide

Automate Docker containers

Enroll an agent, attach the package, and the next renewal installs itself.

Community plan, no card required. Open registration - your account is ready in a few minutes.