Selfhosted
A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.
Rules:
-
Be civil.
-
No spam.
-
Posts are to be related to self-hosting.
-
Don't duplicate the full text of your blog or readme if you're providing a link.
-
Submission headline should match the article title.
-
No trolling.
-
Promotion posts require active participation, with an account that is at least 30 days old. F/LOSS without a paywall has exceptions, with requirements. See the rules link for details. Tags [CBH] or [AIP] are required, see the links in Rule 8 for details.
-
AI-related discussions and AI-involved promotional posts have additional requirements for tagging, as noted in Rule 7 and the AI & Promotional Post Expanded Rules post, and find example disclosures here.
Resources:
- selfh.st Newsletter and index of selfhosted software and apps
- awesome-selfhosted software
- awesome-sysadmin resources
- Self-Hosted Podcast from Jupiter Broadcasting
Any issues on the community? Report it using the report flag.
Questions? DM the mods!
view the rest of the comments
I'm also using Certbot with DeSEC. I simply run it daily with
anacron. If it doesn't need to renew the certs yet it will say so and stop. That's basically it.I think it's a very good idea for your LE renewal to be independent of whatever reverse proxy or web server you're using.
Please keep in mind that Certbot is a Python app so you can manage it with
venv. Here's how I install it in a dedicated dir (let's say/srv/letsencryptbecause using/etcis not appropriate and it bugs me ๐):And to update it:
As for renewing certs (the script is longer, I'm making sure to create dirs and so on but this is the gist of it):
For DeSEC you need
secrets/${DOMAIN}.inito contain:Please note that DeSEC lets you restrict what the token can do, but setting the rights on the token has to be done through their API so you need a separate token for the API ๐ .
To use the certs from Caddy, point it at the files under the
config/live/${DOMAIN}/dir (which are symlinks that are maintained by Certbot), NOT the ones underarchive/.Or, if you want to also add mTLS to the mix:
Let me know if you have questions.
This is great, thank you for taking the time for this write up :) The provided scripts are a huge help to me
So far my only question I have is about the directories you use. I was wondering if you could provide the directories you use or even just an example so I could better understand the file tree. I'm very particular with my files and have a whole system dedicated to maintaining neat and organized files
I agree about not using /etc for server related stuff. I keep all my server/container related stuff in /srv so it's easier for me to manage
The dirs are subdirs of
/srv/letsencrypt. I like to take advantage of explicit dir assignment if the software allows it, so I don't have any surprises if the defaults change.Awesome, thanks so much, this is a big head start for me
I have a good idea how I want to organize things now