Automated certificates for Docker containers
For a service running in a container, the Docker package copies the renewed certificate and key into the container through the Docker Engine API and tells the process to reload.
package docker-target 2.0.0
copyCertificatecopyPrivateKeyrestartContainerwhen configuredsignalContainerwhen configured
At a glance
- Package
docker-target 2.0.0- Compatibility
Docker Engine >=20.10 <30.0- Runs from
- Any Windows or Linux agent with network access to it
- Mechanism
- REST API
- Authentication
- Local - no remote login
- Capabilities
- Import certificateImport private keyReload service
- Deployment steps
- copyCertificate → copyPrivateKey → restartContainer* → signalContainer*
- Rollback
- None
- Key usage
- No requirement
* conditional step
What it does
The agent on the Docker host talks to the Docker Engine over its local socket (or named pipe on Windows), copies the full chain and key into a directory inside the container, and then sends a signal to the main process - HUP by default - or restarts the container.
HUP reloads nginx and HAProxy; USR1 gracefully restarts Apache.
How it runs
- 01
copyCertificate / copyPrivateKey
Certificate and key are copied into the container directory.
- 02
signalContainer
The configured signal is sent to the main process (signal mode).
- 03
restartContainer
The container is restarted (restart mode).
What you configure
- Docker Engine socket (default /var/run/docker.sock)
- Container name or id
- Directory and file names inside the container
- After copying: signal (default HUP) or restart
Prerequisites
- An agent on the Docker host with access to the Docker socket
Limitations
- Files copied into a container do not survive re-creating it; mount a volume if the container is replaced regularly.
Doing it by hand
The documentation has a step-by-step guide for replacing this certificate manually - useful for a first install, or to see exactly what the package automates.
Related features
Solutions
More in Linux and containers
Documentation
Automate Docker containers
Enroll an agent, attach the package, and the next renewal installs itself.
Community plan, no card required. Open registration - your account is ready in a few minutes.