Feature Request: caddy trust with support for --config switch #4058
Labels
Milestone
Comments
|
systemd file, note we use update-alternatives to map /usr/bin/caddy to the custom arm7 with plugins we pull and lay down in our /opt/caddy/release/ path... |
|
I'd like to work on this. |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
I’m trying to script setup and configuration of caddy server based on a custom download that includes additional plugins (caddy-auth-portal, caddy-auth-jwt, caddy-trace, and various caddy-dns modules ).
During setup, the caddy unit file is configured to run caddy as a non priveledged user (by design).
To get certificates configured properly we are attempting to use the caddy trust command as root during install/config. I think this is performing the trust install based on the default caddy CA location created upon install, rather than the custom storage file_system root declaration I’m passing in my /etc/caddy/Caddyfile (provided below)
The result is on first startup from systemctl is throwing errors indicating it can not import the root ca because the service is not running as a priveledged user.
What would be nice is to be able to run caddy trust as root, indicating the custom location for all local CA certificate files.
Here is an example of the preamble to the Caddyfile configuration I use to expose the certificate deployment for shared use by our combined components on the processing node. In this scenario letsEncrypt/ZeroTLS is not being used...
{
storage file_system {
root /opt/caddy/storage
}
local_certs
http_port 80
https_port 443
}
The rest of our deployment detail is in forum issue https://caddy.community/t/new-feature-caddy-trust-with-support-for-config-switch/11606
The text was updated successfully, but these errors were encountered: