Sitelet https://web.archive.org/web/20210816110914/https://github.com/caddyserver/caddy/issues/4058
Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Feature Request: caddy trust with support for --config switch #4058

Open
tgelite opened this issue Mar 11, 2021 · 2 comments
Open

Feature Request: caddy trust with support for --config switch #4058

tgelite opened this issue Mar 11, 2021 · 2 comments

Comments

@tgelite
Copy link

@tgelite tgelite commented Mar 11, 2021 •

I’m trying to script setup and configuration of caddy server based on a custom download that includes additional plugins (caddy-auth-portal, caddy-auth-jwt, caddy-trace, and various caddy-dns modules ).

During setup, the caddy unit file is configured to run caddy as a non priveledged user (by design).

To get certificates configured properly we are attempting to use the caddy trust command as root during install/config. I think this is performing the trust install based on the default caddy CA location created upon install, rather than the custom storage file_system root declaration I’m passing in my /etc/caddy/Caddyfile (provided below)

The result is on first startup from systemctl is throwing errors indicating it can not import the root ca because the service is not running as a priveledged user.

What would be nice is to be able to run caddy trust as root, indicating the custom location for all local CA certificate files.

Here is an example of the preamble to the Caddyfile configuration I use to expose the certificate deployment for shared use by our combined components on the processing node. In this scenario letsEncrypt/ZeroTLS is not being used...

{
storage file_system {
root /opt/caddy/storage
}
local_certs
http_port 80
https_port 443
}

The rest of our deployment detail is in forum issue https://caddy.community/t/new-feature-caddy-trust-with-support-for-config-switch/11606

@tgelite
Copy link
Author

@tgelite tgelite commented Mar 11, 2021 •

systemd file, note we use update-alternatives to map /usr/bin/caddy to the custom arm7 with plugins we pull and lay down in our /opt/caddy/release/ path...

# caddy.service
#
# For using Caddy with a config file.
#
# Make sure the ExecStart and ExecReload commands are correct
# for your installation.
#
# See https://caddyserver.com/docs/install for instructions.
#
# WARNING: This service does not use the --resume flag, so if you
# use the API to make changes, they will be overwritten by the
# Caddyfile next time the service is restarted. If you intend to
# use Caddy's API to configure it, add the --resume flag to the
# caddy run command or use the caddy-api.service file instead.

[Unit]
Description=Caddy
Documentation=https://caddyserver.com/docs/
After=network.target network-online.target
Requires=network-online.target

[Service]
User=caddy
Group=caddy
ExecStart=/usr/bin/caddy run --environ --config /etc/caddy/Caddyfile
ExecReload=/usr/bin/caddy reload --config /etc/caddy/Caddyfile
TimeoutStopSec=5s
LimitNOFILE=1048576
LimitNPROC=512
PrivateTmp=true
ProtectSystem=full
AmbientCapabilities=CAP_NET_BIND_SERVICE

[Install]
WantedBy=multi-user.target
@gdhameeja
Copy link
Contributor

@gdhameeja gdhameeja commented Mar 12, 2021

I'd like to work on this.

@caddyserver caddyserver deleted a comment Mar 31, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Linked pull requests

Successfully merging a pull request may close this issue.

None yet
4 participants