如何为Laradock中的Nginx Docker容器配置HTTPS?
Hey there, let's tackle this HTTPS setup in Laradock's Nginx container— I've been in your shoes with finicky Certbot setups before, so let's break down a couple of reliable approaches that don't have to rely on the built-in Certbot container.
If you have a purchased SSL certificate or want to use a self-signed one for local testing, this is straightforward:
Prepare your certificate files
Create acertsfolder inside Laradock'snginxdirectory (if it doesn't exist), then drop your.crt(public certificate) and.key(private key) files into it.Update your Nginx site config
Open your site's config file (usually innginx/sites/your-project.conf) and modify it to enable HTTPS:server { listen 443 ssl; listen [::]:443 ssl; server_name your-domain.com; # Replace with your actual domain # Point to your certificate files ssl_certificate /etc/nginx/certs/your-domain.crt; ssl_certificate_key /etc/nginx/certs/your-domain.key; # Optional SSL hardening (recommended) ssl_protocols TLSv1.2 TLSv1.3; ssl_ciphers HIGH:!aNULL:!MD5; ssl_prefer_server_ciphers on; # Keep your existing site root and PHP config root /var/www/your-project/public; index index.php index.html; location / { try_files $uri $uri/ /index.php?$query_string; } location ~ \.php$ { fastcgi_pass php-upstream; fastcgi_index index.php; fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name; include fastcgi_params; } } # Optional: Redirect all HTTP traffic to HTTPS server { listen 80; listen [::]:80; server_name your-domain.com; return 301 https://$host$request_uri; }Restart Nginx
Run this command to apply changes:docker-compose restart nginx
Laradock's built-in Certbot can be flaky— using a standalone Certbot container gives you more control:
Add Certbot to your Docker setup
Create adocker-compose.override.ymlfile in your Laradock root (to avoid modifying the originaldocker-compose.yml) with this config:services: certbot: image: certbot/certbot volumes: - ./nginx/certs:/etc/letsencrypt # Stores certificates - ./nginx/html:/var/www/html # For ACME challenge files command: certonly --webroot -w /var/www/html --email your-email@example.com --agree-tos --no-eff-email -d your-domain.comTemporarily configure Nginx for ACME validation
Update your site's config to serve the Certbot challenge files over HTTP:server { listen 80; listen [::]:80; server_name your-domain.com; root /var/www/html; index index.html; location /.well-known/acme-challenge/ { allow all; } }Restart Nginx with
docker-compose restart nginxbefore proceeding.Fetch your Let's Encrypt certificate
Run this command to trigger the certificate request:docker-compose run --rm certbotUpdate Nginx to use the new certificate
Modify your site's config to point to the Let's Encrypt files:ssl_certificate /etc/nginx/certs/live/your-domain.com/fullchain.pem; ssl_certificate_key /etc/nginx/certs/live/your-domain.com/privkey.pem;Don't forget to add the HTTPS server block and HTTP-to-HTTPS redirect from Approach 1.
Set up auto-renewal
Certbot certificates expire every 90 days. Add this command to your Certbot service for auto-renewal (you can run it manually or set up a cron job):command: renew --webroot -w /var/www/html --quietTo renew manually:
docker-compose run --rm certbot renew
If you use Cloudflare for your domain, their Origin CA certificates are free and auto-renew:
Generate the certificate in Cloudflare
- Log into Cloudflare, go to your domain's SSL/TLS > Origin Server page
- Click "Create Certificate", keep default settings, then download the
.crtand.keyfiles
Configure Nginx
Drop the certificate files into Laradock'snginx/certsfolder, then update your Nginx config exactly like Approach 1 (pointing to the Cloudflare certificate files).Set Cloudflare's encryption mode
In Cloudflare's SSL/TLS > Overview page, set the encryption mode to Full or Full (strict).Restart Nginx
Rundocker-compose restart nginxto apply changes.
- Make sure your domain's DNS points to your server's public IP (for public certificates)
- For local testing, use
mkcertto generate trusted local certificates (it avoids browser security warnings better than self-signed certs) - Ensure port 80 and 443 are open on your server's firewall (required for Let's Encrypt validation and HTTPS traffic)
内容的提问来源于stack exchange,提问作者Leonardo Lobato

