Skip to content

fix: serve ACME HTTP-01 challenge for certbot webroot renewal - #32

Merged
ronibhakta1 merged 1 commit into
readium:mainfrom
ronibhakta1:fix/acme-challenge-renewal
Oct 8, 2026
Merged

ronibhakta1 merged 1 commit into
readium:mainfrom
ronibhakta1:fix/acme-challenge-renewal

Conversation

@ronibhakta1

@ronibhakta1 ronibhakta1 commented Oct 8, 2026 •

Copy link
Copy Markdown
Member

Problem

The prod cert expired (Let's Encrypt, 2026-10-08). Renewal couldn't work: the port 80 block redirected everything to HTTPS, including /.well-known/acme-challenge/, where location ~ /\. then returned 403. Standalone mode can't be used either, since nginx holds port 80.

Change

  • nginx: serve /.well-known/acme-challenge/ from /var/www/certbot on port 80; redirect the rest.
  • compose: mount /var/www/certbot read-only into nginx.

Server steps after merge

sudo mkdir -p /var/www/certbot
docker compose --profile nginx up -d --force-recreate nginx
sudo certbot reconfigure --cert-name speech-server.readium.org \
  --webroot -w /var/www/certbot \
  --deploy-hook "docker compose -f $(pwd)/docker-compose.yml --profile nginx exec -T nginx nginx -s reload"
sudo certbot renew --dry-run

certbot.timer then renews automatically and the hook reloads nginx.

@ronibhakta1
ronibhakta1 merged commit 83bce59 into readium:main Oct 8, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant