Docker中Certbot配置及启动失败(网络未找到)问题求助
Let's break down your problems step by step and fix them one by one:
Core Issue Diagnosis
The network ... not found error happens because:
- Your Certbot service isn't connected to the same Docker network as Nginx, so it can't communicate to complete the ACME challenge.
- You're relying on Docker Compose's default auto-created network, which can break if you've cleaned up containers/networks previously.
Plus, there are a couple of other misconfigurations that will block your setup even after fixing the network issue.
Step 1: Fix Docker Compose Network Configuration
Add an explicit custom network to ensure all services (including Certbot) are on the same network. This avoids random network ID mismatches:
version: '3' # Define a custom shared network networks: web_network: driver: bridge services: nginx: restart: always build: context: ./ dockerfile: ./nginx/Dockerfile depends_on: - server ports: - 80:80 # COMMENT OUT 443 PORT FOR NOW - Nginx will fail to start without existing certificates # - 443:443 volumes: - ./server/media:/nginx/media - ./conf.d:/nginx/conf.d - ./dhparam:/nginx/dhparam - ./certbot/conf:/nginx/ssl - ./certbot/data:/usr/share/nginx/html/letsencrypt # Attach to custom network networks: - web_network server: build: context: ./ dockerfile: ./server/Dockerfile command: gunicorn config.wsgi -c ./config/gunicorn.py volumes: - ./server/media:/server/media ports: - "8000:8000" depends_on: - db environment: DEBUG: 'False' DATABASE_URL: 'postgres://postgres:@db:5432/postgres' BROKER_URL: 'amqp://user:password@rabbitmq:5672/my_vhost' networks: - web_network db: image: postgres:11.2 environment: POSTGRES_DB: postgres POSTGRES_USER: postgres networks: - web_network certbot: image: certbot/certbot:latest command: certonly --webroot --webroot-path=/usr/share/nginx/html/letsencrypt --email artasdeco.ru@gmail.com --agree-tos --no-eff-email -d englishgame.ru volumes: - ./certbot/conf:/etc/letsencrypt - ./certbot/logs:/var/log/letsencrypt - ./certbot/data:/usr/share/nginx/html/letsencrypt # Attach to the same network as Nginx networks: - web_network # Ensure Nginx is running before Certbot starts depends_on: - nginx
Step 2: Fix Nginx SSL Certificate Key
Your nginx.conf has a critical mistake: you're using fullchain.pem for both the certificate and private key. Correct this:
server { listen 443 ssl http2; server_name englishgame.ru; ssl on; server_tokens off; ssl_certificate /etc/nginx/ssl/live/englishgame.ru/fullchain.pem; # Replace fullchain.pem with privkey.pem here ssl_certificate_key /etc/nginx/ssl/live/englishgame.ru/privkey.pem; ssl_dhparam /etc/nginx/dhparam/dhparam-2048.pem; ssl_buffer_size 8k; ssl_protocols TLSv1.2 TLSv1.1 TLSv1; ssl_prefer_server_ciphers on; ssl_ciphers ECDH+AESGCM:ECDH+AES256:ECDH+AES128:DH+3DES:!ADH:!AECDH:!MD5; location / { return 301 https://englishgame.ru$request_uri; } }
Step 3: Clean Up Old Network Residues (If Needed)
If you've had previous failed attempts, clear old networks to avoid conflicts:
# Stop all running containers docker-compose down # Prune unused networks docker network prune
Step 4: Deploy & Get Certificates
Follow these steps in order:
- Start Nginx and backend services first:
docker-compose up -d nginx server db - Run Certbot to generate certificates:
docker-compose run --rm certbot - Once certificates are generated, uncomment the
443:443port indocker-compose.yml, then restart Nginx:docker-compose up -d nginx
Bonus: Set Up Auto-Renewal
Add a service to handle automatic certificate renewal:
certbot-renew: image: certbot/certbot:latest command: renew volumes: - ./certbot/conf:/etc/letsencrypt - ./certbot/logs:/var/log/letsencrypt - ./certbot/data:/usr/share/nginx/html/letsencrypt networks: - web_network depends_on: - nginx
Then add a cron job to run it weekly (adjust the path to your docker-compose.yml):
0 12 * * * /usr/local/bin/docker-compose -f /path/to/your/docker-compose.yml run --rm certbot-renew && docker-compose reload nginx
内容的提问来源于stack exchange,提问作者Saichenko

