From 223f14d92d2e627c540ae2e1b55a76a1c48fb46d Mon Sep 17 00:00:00 2001 From: Peetz0r Date: Sat, 30 Jan 2021 20:03:02 +0100 Subject: [PATCH] Run certbot in matrix docker-network Required in ipv6-only setups. The default docker network is ipv4-only, so validation would fail. Our own network has ipv6 (if enabled) so that works fine. --- .../tasks/ssl/setup_ssl_lets_encrypt_obtain_for_domain.yml | 1 + 1 file changed, 1 insertion(+) diff --git a/roles/matrix-nginx-proxy/tasks/ssl/setup_ssl_lets_encrypt_obtain_for_domain.yml b/roles/matrix-nginx-proxy/tasks/ssl/setup_ssl_lets_encrypt_obtain_for_domain.yml index 4639f122c..cd6cf9be0 100644 --- a/roles/matrix-nginx-proxy/tasks/ssl/setup_ssl_lets_encrypt_obtain_for_domain.yml +++ b/roles/matrix-nginx-proxy/tasks/ssl/setup_ssl_lets_encrypt_obtain_for_domain.yml @@ -35,6 +35,7 @@ --user={{ matrix_user_uid }}:{{ matrix_user_gid }} --cap-drop=ALL -p {{ matrix_ssl_lets_encrypt_container_standalone_http_host_bind_port }}:8080 + --network={{ matrix_docker_network }} --mount type=bind,src={{ matrix_ssl_config_dir_path }},dst=/etc/letsencrypt --mount type=bind,src={{ matrix_ssl_log_dir_path }},dst=/var/log/letsencrypt {{ matrix_ssl_lets_encrypt_certbot_docker_image }}