π DeploymentΒΆ
π³ DockerΒΆ
Docker imageΒΆ
To deploy the CA, use the following Docker image:
harbor.confirm.ch/ca/ca
Docker commandΒΆ
To deploy the CA service via a simple docker command, use the following CLI arguments:
docker run -d \
--name ca \
-e CA_DNS=ca.example.net \
-e CA_NAME="Example CA" \
-e CA_PROVISIONER=admin \
-p 8443:8443 \
-v ca:/ca \
harbor.confirm.ch/ca/ca
Hint
Itβs recommended to deploy the CA service via Docker Compose.
Docker ComposeΒΆ
Use the following docker-compose.yml file to start the CA:
---
services:
ca:
image: harbor.confirm.ch/ca/ca
environment:
CA_DNS: ca.example.net
CA_NAME: Example CA
CA_PROVISIONER: admin
ports:
- '8443:8443'
volumes:
- ca:/ca
restart: unless-stopped
volumes:
ca:
Then bring the stack up with:
docker compose up -d
First startΒΆ
On the first start, the CA is initialised and prints its details to the container logs:
docker logs ca
Important
Write down the CA fingerprint, itβs required to bootstrap the
stepCLI.Write down the provisioner password from
passwords/${CA_PROVISIONER}, then delete the file:
docker exec ca cat passwords/{provisioner}
docker exec ca rm passwords/{provisioner}
Test deploymentΒΆ
To test the deployment, check if you can get the root certificate via curl, or wget:
# Get CA certificate via curl.
curl --insecure https://{FQDN}/roots.pem
# Get CA certificate via wget.
wget --no-check-certificate -O - https://{FQDN}/roots.pem
After that, bootstrap the step CLI and try to get your first certificate via π£ step CLI.
π‘οΈ Reverse proxy deploymentΒΆ
Important
When deploying the CA behind a reverse proxy, please check out the π‘οΈ Reverse proxy chapter.
πΎ BackupΒΆ
The /ca volume contains everything the CA needs, i.e. the config, the database, the root & intermediate keys, and their passwords.
Danger
If you lose the volume, you lose the CA and the secrets. All issued certificates must then be replaced by ones from a new CA.