如何使用Let's Encrypt保护经Nginx代理的S3静态站点?
Hey there! Let's break down how to get SSL certificates from Let's Encrypt for all your Nginx-proxied S3 static sites. This setup will get you encrypted HTTPS connections, automatic certificate renewal, and keep your sites secure.
Step 1: Install Certbot & the Nginx Plugin
First, you'll need Certbot (the official Let's Encrypt tool) and its Nginx plugin, which handles most of the configuration heavy lifting for you.
For Ubuntu/Debian-based systems:
sudo apt update sudo apt install certbot python3-certbot-nginx
For CentOS/RHEL-based systems:
sudo dnf install certbot python3-certbot-nginx
Step 2: Prepare Your Nginx Configuration
Before grabbing certificates, make sure each of your domain's Nginx server blocks (for port 80/HTTP) is set up to allow Let's Encrypt's validation requests. Let's Encrypt uses the HTTP-01 challenge to verify you own the domain, which requires access to the /.well-known/acme-challenge/ path.
Here's a sample HTTP server block for one of your domains:
server { listen 80; server_name your-domain.com www.your-domain.com; # Allow ACME challenge files to be accessed location /.well-known/acme-challenge/ { root /var/www/html; allow all; } # Proxy all other traffic to your S3 bucket's public URL location / { proxy_pass https://your-s3-bucket-name.s3.amazonaws.com/; proxy_set_header Host your-s3-bucket-name.s3.amazonaws.com; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; } }
- Make sure
/var/www/htmlexists (create it withsudo mkdir -p /var/www/htmlif not) and has proper permissions (sudo chown www-data:www-data /var/www/html). - Repeat this server block for every domain you want to secure, updating the
server_nameandproxy_passvalues accordingly.
After updating your config, test it for errors and reload Nginx:
sudo nginx -t sudo systemctl reload nginx
Step 3: Obtain SSL Certificates
Now use Certbot's Nginx plugin to fetch and install certificates for your domains.
For individual domains:
sudo certbot --nginx -d your-domain.com -d www.your-domain.com
Add additional -d flags for every subdomain or alias you need (e.g., -d blog.your-domain.com).
For wildcard certificates (covers all subdomains of a root domain):
If you manage multiple subdomains under a single root domain, a wildcard certificate will simplify things. You'll need to use the DNS-01 challenge here (since HTTP-01 can't validate wildcards). If you use AWS Route 53 for DNS, use this command:
sudo certbot certonly --dns-route53 -d *.your-domain.com -d your-domain.com
Certbot will automatically create the required DNS records to validate your domain ownership.
When prompted:
- Enter your email address for renewal reminders.
- Agree to the terms of service.
- Choose whether to share your email with the Electronic Frontier Foundation (optional).
- Select whether to redirect all HTTP traffic to HTTPS (recommended—choose option 2).
Step 4: Verify the Setup
After Certbot finishes, restart Nginx to apply the changes:
sudo systemctl restart nginx
Visit your domain in a browser—you should see a green padlock indicating a valid SSL certificate. You can also use tools like openssl s_client -connect your-domain.com:443 to check certificate details.
Step 5: Set Up Automatic Certificate Renewal
Let's Encrypt certificates expire after 90 days, but Certbot automatically sets up a systemd timer or cron job to renew them. Test the renewal process with a dry run to make sure everything works:
sudo certbot renew --dry-run
If the dry run succeeds, you're all set—Certbot will handle renewals in the background automatically.
Key Notes
- Ensure your S3 bucket's public URL uses HTTPS (
https://your-bucket.s3.amazonaws.com) to avoid unencrypted traffic between Nginx and S3. - If you have firewall rules, make sure ports 80 (for HTTP validation) and 443 (for HTTPS traffic) are open to the internet.
- For non-Route 53 DNS providers, Certbot has plugins for most major services—check the Certbot docs for your provider's specific plugin.
内容的提问来源于stack exchange,提问作者user5431121

