This commit is contained in:
2025-12-11 16:41:12 +01:00
parent 807492e364
commit 81e48b555a
9 changed files with 92 additions and 23 deletions

View File

@@ -1,4 +1,4 @@
version = 4.1.1 version = 5.1.0
archive_dir = /etc/letsencrypt/archive/npm-11 archive_dir = /etc/letsencrypt/archive/npm-11
cert = /etc/letsencrypt/live/npm-11/cert.pem cert = /etc/letsencrypt/live/npm-11/cert.pem
privkey = /etc/letsencrypt/live/npm-11/privkey.pem privkey = /etc/letsencrypt/live/npm-11/privkey.pem
@@ -11,10 +11,10 @@ account = 020f85d8def96a90143fbf56a6214037
key_type = ecdsa key_type = ecdsa
elliptic_curve = secp384r1 elliptic_curve = secp384r1
preferred_chain = ISRG Root X1 preferred_chain = ISRG Root X1
pref_challs = dns-01, http-01 pref_challs = http-01,
config_dir = /etc/letsencrypt config_dir = /etc/letsencrypt
work_dir = /tmp/letsencrypt-lib work_dir = /tmp/letsencrypt-lib
logs_dir = /tmp/letsencrypt-log logs_dir = /data/logs
authenticator = webroot authenticator = webroot
webroot_path = /data/letsencrypt-acme-challenge, webroot_path = /data/letsencrypt-acme-challenge,
server = https://acme-v02.api.letsencrypt.org/directory server = https://acme-v02.api.letsencrypt.org/directory

View File

@@ -1,4 +1,4 @@
version = 4.1.1 version = 5.1.0
archive_dir = /etc/letsencrypt/archive/npm-12 archive_dir = /etc/letsencrypt/archive/npm-12
cert = /etc/letsencrypt/live/npm-12/cert.pem cert = /etc/letsencrypt/live/npm-12/cert.pem
privkey = /etc/letsencrypt/live/npm-12/privkey.pem privkey = /etc/letsencrypt/live/npm-12/privkey.pem
@@ -11,10 +11,10 @@ account = 020f85d8def96a90143fbf56a6214037
key_type = ecdsa key_type = ecdsa
elliptic_curve = secp384r1 elliptic_curve = secp384r1
preferred_chain = ISRG Root X1 preferred_chain = ISRG Root X1
pref_challs = dns-01, http-01 pref_challs = http-01,
config_dir = /etc/letsencrypt config_dir = /etc/letsencrypt
work_dir = /tmp/letsencrypt-lib work_dir = /tmp/letsencrypt-lib
logs_dir = /tmp/letsencrypt-log logs_dir = /data/logs
authenticator = webroot authenticator = webroot
webroot_path = /data/letsencrypt-acme-challenge, webroot_path = /data/letsencrypt-acme-challenge,
server = https://acme-v02.api.letsencrypt.org/directory server = https://acme-v02.api.letsencrypt.org/directory

View File

@@ -1,4 +1,4 @@
version = 4.1.1 version = 5.1.0
archive_dir = /etc/letsencrypt/archive/npm-13 archive_dir = /etc/letsencrypt/archive/npm-13
cert = /etc/letsencrypt/live/npm-13/cert.pem cert = /etc/letsencrypt/live/npm-13/cert.pem
privkey = /etc/letsencrypt/live/npm-13/privkey.pem privkey = /etc/letsencrypt/live/npm-13/privkey.pem
@@ -11,10 +11,10 @@ account = 020f85d8def96a90143fbf56a6214037
key_type = ecdsa key_type = ecdsa
elliptic_curve = secp384r1 elliptic_curve = secp384r1
preferred_chain = ISRG Root X1 preferred_chain = ISRG Root X1
pref_challs = dns-01, http-01 pref_challs = http-01,
config_dir = /etc/letsencrypt config_dir = /etc/letsencrypt
work_dir = /tmp/letsencrypt-lib work_dir = /tmp/letsencrypt-lib
logs_dir = /tmp/letsencrypt-log logs_dir = /data/logs
authenticator = webroot authenticator = webroot
webroot_path = /data/letsencrypt-acme-challenge, webroot_path = /data/letsencrypt-acme-challenge,
server = https://acme-v02.api.letsencrypt.org/directory server = https://acme-v02.api.letsencrypt.org/directory

View File

@@ -1,4 +1,4 @@
version = 4.1.1 version = 5.1.0
archive_dir = /etc/letsencrypt/archive/npm-14 archive_dir = /etc/letsencrypt/archive/npm-14
cert = /etc/letsencrypt/live/npm-14/cert.pem cert = /etc/letsencrypt/live/npm-14/cert.pem
privkey = /etc/letsencrypt/live/npm-14/privkey.pem privkey = /etc/letsencrypt/live/npm-14/privkey.pem
@@ -11,10 +11,10 @@ account = 020f85d8def96a90143fbf56a6214037
key_type = ecdsa key_type = ecdsa
elliptic_curve = secp384r1 elliptic_curve = secp384r1
preferred_chain = ISRG Root X1 preferred_chain = ISRG Root X1
pref_challs = dns-01, http-01 pref_challs = http-01,
config_dir = /etc/letsencrypt config_dir = /etc/letsencrypt
work_dir = /tmp/letsencrypt-lib work_dir = /tmp/letsencrypt-lib
logs_dir = /tmp/letsencrypt-log logs_dir = /data/logs
authenticator = webroot authenticator = webroot
webroot_path = /data/letsencrypt-acme-challenge, webroot_path = /data/letsencrypt-acme-challenge,
server = https://acme-v02.api.letsencrypt.org/directory server = https://acme-v02.api.letsencrypt.org/directory

View File

@@ -1,4 +1,4 @@
version = 4.1.1 version = 5.1.0
archive_dir = /etc/letsencrypt/archive/npm-15 archive_dir = /etc/letsencrypt/archive/npm-15
cert = /etc/letsencrypt/live/npm-15/cert.pem cert = /etc/letsencrypt/live/npm-15/cert.pem
privkey = /etc/letsencrypt/live/npm-15/privkey.pem privkey = /etc/letsencrypt/live/npm-15/privkey.pem
@@ -11,10 +11,10 @@ account = 020f85d8def96a90143fbf56a6214037
key_type = ecdsa key_type = ecdsa
elliptic_curve = secp384r1 elliptic_curve = secp384r1
preferred_chain = ISRG Root X1 preferred_chain = ISRG Root X1
pref_challs = dns-01, http-01 pref_challs = http-01,
config_dir = /etc/letsencrypt config_dir = /etc/letsencrypt
work_dir = /tmp/letsencrypt-lib work_dir = /tmp/letsencrypt-lib
logs_dir = /tmp/letsencrypt-log logs_dir = /data/logs
authenticator = webroot authenticator = webroot
webroot_path = /data/letsencrypt-acme-challenge, webroot_path = /data/letsencrypt-acme-challenge,
server = https://acme-v02.api.letsencrypt.org/directory server = https://acme-v02.api.letsencrypt.org/directory

View File

@@ -1,4 +1,4 @@
version = 4.1.1 version = 5.1.0
archive_dir = /etc/letsencrypt/archive/npm-16 archive_dir = /etc/letsencrypt/archive/npm-16
cert = /etc/letsencrypt/live/npm-16/cert.pem cert = /etc/letsencrypt/live/npm-16/cert.pem
privkey = /etc/letsencrypt/live/npm-16/privkey.pem privkey = /etc/letsencrypt/live/npm-16/privkey.pem
@@ -11,10 +11,10 @@ account = 020f85d8def96a90143fbf56a6214037
key_type = ecdsa key_type = ecdsa
elliptic_curve = secp384r1 elliptic_curve = secp384r1
preferred_chain = ISRG Root X1 preferred_chain = ISRG Root X1
pref_challs = dns-01, http-01 pref_challs = http-01,
config_dir = /etc/letsencrypt config_dir = /etc/letsencrypt
work_dir = /tmp/letsencrypt-lib work_dir = /tmp/letsencrypt-lib
logs_dir = /tmp/letsencrypt-log logs_dir = /data/logs
authenticator = webroot authenticator = webroot
webroot_path = /data/letsencrypt-acme-challenge, webroot_path = /data/letsencrypt-acme-challenge,
server = https://acme-v02.api.letsencrypt.org/directory server = https://acme-v02.api.letsencrypt.org/directory

View File

@@ -1,4 +1,4 @@
version = 4.1.1 version = 5.1.0
archive_dir = /etc/letsencrypt/archive/npm-17 archive_dir = /etc/letsencrypt/archive/npm-17
cert = /etc/letsencrypt/live/npm-17/cert.pem cert = /etc/letsencrypt/live/npm-17/cert.pem
privkey = /etc/letsencrypt/live/npm-17/privkey.pem privkey = /etc/letsencrypt/live/npm-17/privkey.pem
@@ -11,10 +11,10 @@ account = 020f85d8def96a90143fbf56a6214037
key_type = ecdsa key_type = ecdsa
elliptic_curve = secp384r1 elliptic_curve = secp384r1
preferred_chain = ISRG Root X1 preferred_chain = ISRG Root X1
pref_challs = dns-01, http-01 pref_challs = http-01,
config_dir = /etc/letsencrypt config_dir = /etc/letsencrypt
work_dir = /tmp/letsencrypt-lib work_dir = /tmp/letsencrypt-lib
logs_dir = /tmp/letsencrypt-log logs_dir = /data/logs
authenticator = webroot authenticator = webroot
webroot_path = /data/letsencrypt-acme-challenge, webroot_path = /data/letsencrypt-acme-challenge,
server = https://acme-v02.api.letsencrypt.org/directory server = https://acme-v02.api.letsencrypt.org/directory

View File

@@ -7,6 +7,9 @@ services:
- 9443:9443 - 9443:9443
container_name: portainer container_name: portainer
restart: always restart: always
#environment:
#- VIRTUAL_HOST=portainer.home.ramberg.net
#- VIRTUAL_PORT=9443
volumes: volumes:
- /var/run/docker.sock:/var/run/docker.sock - /var/run/docker.sock:/var/run/docker.sock
- /home/rcadmin/docker/portainer/data:/data - /home/rcadmin/docker/portainer/data:/data

66
stunnel/README.md Normal file
View File

@@ -0,0 +1,66 @@
# stunnel
## download
`docker pull chainguard/stunnel:latest`
or
`docker pull cgr.dev/ORGANIZATION/stunnel:latest`
## run
`docker run cgr.dev/chainguard/stunnel`
or
`docker run cgr.dev/chainguard/stunnel:latest`
## Options
```
Global options:
chroot = directory to chroot stunnel process
EGD = path to Entropy Gathering Daemon socket
engine = auto|engine_id
engineCtrl = cmd[:arg]
engineDefault = TASK_LIST
foreground = yes|quiet|no foreground mode (don't fork, log to stderr)
log = append|overwrite log file
output = file to append log messages
pid = pid file
RNDbytes = bytes to read from random seed files
RNDfile = path to file with random seed data
RNDoverwrite = yes|no overwrite seed datafiles with new random data
syslog = yes|no send logging messages to syslog
Service-level options:
accept = [host:]port accept connections on specified host:port
CAengine = engine-specific CA certificate identifier for 'verify' option
CApath = CA certificate directory for 'verify' option
CAfile = CA certificate file for 'verify' option
cert = certificate chain
checkEmail = peer certificate email address
checkHost = peer certificate host name pattern
checkIP = peer certificate IP address
ciphers = permitted ciphers for TLS 1.2 or older
ciphersuites = permitted ciphersuites for TLS 1.3
client = yes|no client mode (remote service uses TLS)
config = command[:parameter] to execute
connect = [host:]port to connect
CRLpath = CRL directory
CRLfile = CRL file
curves = ECDH curve names
debug = [facility].level (e.g. daemon.info)
delay = yes|no delay DNS lookup for 'connect' option
engineId = ID of engine to read the key from
engineNum = number of engine to read the key from
exec = file execute local inetd-type program
execArgs = arguments for 'exec' (including $0)
failover = rr|prio failover strategy
ident = username for IDENT (RFC 1413) checking
include = directory with configuration file snippets
key = certificate private key
local = IP address to be used as source for remote connections
logId = connection identifier type
OCSP = OCSP responder URL
```