[:en]The wife now also starts a blog. Time to play: This blog here is still set up the old-fashioned way, php and mysql running on the web server. But setting up a wordpress for her gives me a welcome excuse to play with docker.
So there you go:
For the simplified creation of vhosts for docker containers I set use a trio of containers using a slightly-adapted version of this docker-compose.yml:
- nginx as reverse-proxy
- jwilder/docker-genfor automatic creation of v-hosts based on container environment variables: simply pass
-e VIRTUAL_HOST=your.domain.comand this container adapts the vhosts config for nginx accordingly. - jrcs/letsencrypt-nginx-proxy-companion to also automatically fetch a letsencrypt certificate and enable ssl for the new vhost..
For the wordpress instance I run an adapted docker-compose.yml for the usual container pair of wordpress and mysql. Apart from keeping the wordpress instance in a directory volume (for easy fiddling) i added the following modification:
environment:
VIRTUAL_HOST: <vhost-1>.de,<vhost-2>.de...
LETSENCRYPT_HOST: <vhost-1>.de,<vhost-2>.de...
LETSENCRYPT_EMAIL: <letsencrypt-mail>
This enables automatic creation and sslification of the vhost in the nginx reverse proxy.
The nginx-reverse-proxy solution really makes it very convenient to just spin up a new container and immediately use it with a valid SSL certificate. Definitely worth the time for initial setup – it does not take longer than setting up SSL manually but you only have it once to get SSL for all vhosts.[:de]Die Frau setzt jetzt auch ein Blog auf. Da gerät man schnell ins Spielen. Während dieses Blog hier noch altbacken mit php und mysql auf dem Server läuft habe ich für das neue ein Team aus Dockercontainern aufgesetzt:
Für die automatische Einrichtung ein Trio aus Containern basierend auf diesem compose file:
- nginx als reverse-proxy
- jwilder/docker-gen zum automatischen erstellen passender vhost-konfigurationen für den reverse proxy. Einfach die passende Umgebungsvariable
-e VIRTUAL_HOST=your.domain.comsetzen, und nginx richtet den passenden Vhost ein und leitet ihn auf den exponierten port weiter. - jrcs/letsencrypt-nginx-proxy-companion zum automatischen Abruf passender Letsencrypt SSL zertifikate für die erstellten Vhosts.
Darunter dann ein angepasstes docker-compose.yml für das übliche Paar aus WordPress-container und *sql-container. Hauptanpassung (neben dem verschieben des WordPress-folders auf ein directory volume für einfachere anpassungen):
environment:
VIRTUAL_HOST: <vhost-1>.de,<vhost-2>.de...
LETSENCRYPT_HOST: <vhost-1>.de,<vhost-2>.de...
LETSENCRYPT_EMAIL: <letsencrypt-mail>
Damit funktioniert dann auch das automatische Erstellen eines vhosts.
Die Nginx-reverse-proxy-lösung macht es supereinfach neuen Containern gleich einen funktionierenden Vhost mit SSL zuzuteilen. Dabei braucht man fürs Aufsetzen auch wenig länger als für die manuelle SSL-Konfiguration eines einzelnen Vhosts. Sobald man den zweiten Container mit SSL versorgen möchte oder einen neuen Vhost hinzufügt hat man diese Zeit wieder drin.[:]