From d3b6701541b337ea1389dc5b8f4b69dc510a6e73 Mon Sep 17 00:00:00 2001 From: jnfrati Date: Fri, 9 Oct 2026 14:15:17 +0200 Subject: [PATCH] [signal] Answer Let's Encrypt challenges on the UBI image's port The challenge listener defaults to :443, which a non-root UID cannot bind on OpenShift or Podman, so Let's Encrypt could not work in the UBI image. Now that the listener address is configurable, default it to empty so the TLS listener on port 10000 answers the challenges itself when public port 443 is forwarded to it. --- signal/Dockerfile.ubi | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/signal/Dockerfile.ubi b/signal/Dockerfile.ubi index a33800b1f..f0a6552da 100644 --- a/signal/Dockerfile.ubi +++ b/signal/Dockerfile.ubi @@ -26,9 +26,11 @@ ENV HOME=/var/lib/netbird ENV NB_LETSENCRYPT_DATA_DIR="/var/lib/netbird" # Unprivileged ports: runtimes such as OpenShift and Podman keep the kernel # default that reserves ports below 1024 for root, so serve on the legacy -# gRPC port instead of 80/443. Let's Encrypt also needs its challenge -# listener on an unprivileged port. 9090 is the metrics endpoint. +# gRPC port instead of 80/443. With Let's Encrypt, the empty listen address +# answers challenges on that port when public 443 is forwarded to it. +# 9090 is the metrics endpoint. ENV NB_PORT="10000" +ENV NB_LETSENCRYPT_LISTEN_ADDRESS="" EXPOSE 10000 9090 # The signal server only handles SIGINT for a graceful stop. STOPSIGNAL SIGINT