- Refactored HAProxy configuration files, templates, and paths to use `/etc/easyhaproxy` instead of `/etc/haproxy`. - Updated Dockerfile to generate DH params and placeholder certificates in the new configuration directory. - Added health check support with timeout to `DockerComposeFixture` in E2E test utilities. - Adjusted tests, templates, and plugins to use the new `Consts`-based configuration paths. - Introduced pytest fixtures for environment isolation and temporary directory management.
84 lines
2.3 KiB
Markdown
84 lines
2.3 KiB
Markdown
---
|
|
sidebar_position: 9
|
|
---
|
|
|
|
# Setup custom certificates
|
|
|
|
You can use your own certificates with EasyHAProxy. You just need to let EasyHAProxy know that certificate.
|
|
|
|
There are two ways to do that.
|
|
|
|
- [Setup certificate as a label definition in docker container](#setup-certificate-as-a-label-definition-in-docker-container)
|
|
- [Map the certificate as a docker volume](#map-the-certificate-as-a-docker-volume)
|
|
|
|
## Setup certificate as a label definition in docker container
|
|
|
|
1. Create a single PEM from the certificate and key.
|
|
|
|
```bash title="Combine certificate and key"
|
|
cat example.com.crt example.com.key > single.pem
|
|
|
|
cat single.pem
|
|
|
|
-----BEGIN CERTIFICATE-----
|
|
MIIEvAIBADANBgkqhkiG9w0BAQEFAASCBKYwggSiAgEAAoIBAQC5ZheHqmBnEJP+
|
|
U9r1gxYWKLzdqrMrcxtQN6M1hIH9n0peuJeIrybdcV7sMbStMXI=
|
|
-----END CERTIFICATE-----
|
|
|
|
-----BEGIN PRIVATE KEY-----
|
|
MIIEojCCA4qgAwIBAgIUegW2BimwuL4RzRZ2WYkHA6U5nkAwDQYJKoZIhvcNAQEL
|
|
3j4wz8/I5fdsk090j4s5KA==
|
|
-----END PRIVATE KEY-----
|
|
```
|
|
|
|
2. Convert the `single.pem` to BASE64 in a single line:
|
|
|
|
```bash title="Convert to BASE64"
|
|
cat single.pem | base64 -w0
|
|
```
|
|
|
|
3. Define a label in yout container
|
|
|
|
Add the Base64 string you generated before to the label `easyhaproxy.[definition].sslcert`
|
|
|
|
## Map the certificate as a docker volume
|
|
|
|
EasyHAProxy stores the certificates inside the container folder `/etc/easyhaproxy/certs/haproxy`.
|
|
|
|
1. Run EasyHAProxy with the volume for the certificates:
|
|
|
|
```bash title="Create and mount certificate volume"
|
|
docker volume create certs_haproxy
|
|
|
|
docker run \
|
|
/* other parameters */
|
|
-v certs_haproxy:/etc/easyhaproxy/certs/haproxy \
|
|
-d byjg/easy-haproxy
|
|
```
|
|
|
|
2. Create a single PEM from the certificate and the key.
|
|
|
|
```bash title="Combine certificate and key"
|
|
cat example.com.crt example.com.key > single.pem
|
|
|
|
cat single.pem
|
|
|
|
-----BEGIN CERTIFICATE-----
|
|
MIIEvAIBADANBgkqhkiG9w0BAQEFAASCBKYwggSiAgEAAoIBAQC5ZheHqmBnEJP+
|
|
U9r1gxYWKLzdqrMrcxtQN6M1hIH9n0peuJeIrybdcV7sMbStMXI=
|
|
-----END CERTIFICATE-----
|
|
|
|
-----BEGIN PRIVATE KEY-----
|
|
MIIEojCCA4qgAwIBAgIUegW2BimwuL4RzRZ2WYkHA6U5nkAwDQYJKoZIhvcNAQEL
|
|
3j4wz8/I5fdsk090j4s5KA==
|
|
-----END PRIVATE KEY-----
|
|
```
|
|
|
|
3. Copy this certificate to EasyHAProxy volume:
|
|
|
|
```bash title="Copy certificate to container"
|
|
docker cp single.pem easyhaproxy:/etc/easyhaproxy/certs/haproxy
|
|
```
|
|
|
|
----
|
|
[Open source ByJG](http://opensource.byjg.com)
|