letsencrypt renew

์ธ์ฆ์„œ ๋งŒ๋ฃŒ ํ™•์ธ

  • sudo certbot certificates

์ธ์ฆ์„œ ์žฌ๊ฐฑ์‹ 

  • sudo certbot renew --dry-run

์ธ์ฆ์„œ๋ฅผ ์žฌ๊ฐฑ์‹ ํ•ด๋„, docker nginx์™€ ํฌํŠธ ์ถฉ๋Œ์ด ๋ฐœ์ƒํ•˜๊ณ  ์„ค์ •ํ–ˆ๋˜ ๋ณผ๋ฅจ์— pem ํŒŒ์ผ๋“ค์ด ๋ณต์‚ฌ๊ฐ€ ์ด๋ค„์ง€์ง€ ์•Š์œผ๋ฉด์„œ ์—๋Ÿฌ๊ฐ€ ๋ฐœ์ƒํ•œ๋‹ค. ๊ทธ๋ž˜์„œ ์ด ๋ถ€๋ถ„์„ ์Šคํฌ๋ฆฝํŠธ๋กœ ์ž๋™ํ™”ํ•˜๋Š” ๊ฒƒ์ด ์ธ์ฆ์„œ ์—๋Ÿฌ๋ฅผ ์ค„์ผ ์ˆ˜ ์žˆ์„๊ฒƒ์ด๋‹ค.

  1. docker nginx์˜ ์ธ์ฆ์„œ ๋ณผ๋ฅจ์— sh ํŒŒ์ผ์„ ์ƒ์„ฑํ•œ๋‹ค.

#!/bin/bash

# --- ๊ฐฑ์‹  ์„ฑ๊ณต ํ›„ ์‹คํ–‰๋  ์ž‘์—…๋“ค ---

# 1. ๊ฐฑ์‹ ๋œ ์ธ์ฆ์„œ ํŒŒ์ผ๋“ค์„ /home/ubuntu/etc/ssl/ ๋””๋ ‰ํ„ฐ๋ฆฌ๋กœ ๋ณต์‚ฌ
cp /etc/letsencrypt/live/domain/*.pem docker nginx์— ์„ค์ •ํ•œ volume

# 2. ์ •์ง€๋˜์–ด ์žˆ๋˜ Docker Nginx ์ปจํ…Œ์ด๋„ˆ๋ฅผ ๋‹ค์‹œ ์‹คํ–‰ (์ƒˆ ์ธ์ฆ์„œ ์ ์šฉ)
cd docker compose up -d nginx

  1. ์ธ์ฆ์„œ ๊ฐฑ์‹  hook ์žฌ์„ค์ •

sudo certbot renew --force-renewal --pre-hook "sh -c 'cd docker compose stop nginx'" --deploy-hook deploy_cert.sh

Last updated