mirror of
https://github.com/netbirdio/netbird.git
synced 2026-10-10 07:29:06 +02:00
[signal] Answer Let's Encrypt challenges on the UBI image's port
The challenge listener defaults to :443, which a non-root UID cannot bind on OpenShift or Podman, so Let's Encrypt could not work in the UBI image. Now that the listener address is configurable, default it to empty so the TLS listener on port 10000 answers the challenges itself when public port 443 is forwarded to it.
This commit is contained in:
@@ -26,9 +26,11 @@ ENV HOME=/var/lib/netbird
|
||||
ENV NB_LETSENCRYPT_DATA_DIR="/var/lib/netbird"
|
||||
# Unprivileged ports: runtimes such as OpenShift and Podman keep the kernel
|
||||
# default that reserves ports below 1024 for root, so serve on the legacy
|
||||
# gRPC port instead of 80/443. Let's Encrypt also needs its challenge
|
||||
# listener on an unprivileged port. 9090 is the metrics endpoint.
|
||||
# gRPC port instead of 80/443. With Let's Encrypt, the empty listen address
|
||||
# answers challenges on that port when public 443 is forwarded to it.
|
||||
# 9090 is the metrics endpoint.
|
||||
ENV NB_PORT="10000"
|
||||
ENV NB_LETSENCRYPT_LISTEN_ADDRESS=""
|
||||
EXPOSE 10000 9090
|
||||
# The signal server only handles SIGINT for a graceful stop.
|
||||
STOPSIGNAL SIGINT
|
||||
|
||||
Reference in New Issue
Block a user