traefik-certs-dumper/readme.md
Sven Dowideit e8b376abe5 give a full example of a one shot example of using the container
Signed-off-by: Sven Dowideit <sven.dowideit@csiro.au>
2021-03-30 10:51:06 +10:00

5.1 KiB

traefik-certs-dumper

GitHub release Build Status Docker Information Go Report Card

If you appreciate this project:

Sponsor

Features

  • Supported sources:
    • file ("acme.json")
    • KV stores (Consul, Etcd, Zookeeper, Boltdb)
  • Watch changes:
    • from file ("acme.json")
    • from KV stores (Consul, Etcd, Zookeeper)
  • Output formats:
    • use domain as sub-directory (allow custom names and extensions)
    • flat (domain as filename)
  • Hook (only with watch mode and if the data source changes)

Installation

Download / CI Integration

curl -sfL https://raw.githubusercontent.com/ldez/traefik-certs-dumper/master/godownloader.sh | bash -s -- -b $(go env GOPATH)/bin v2.7.4

From Binaries

You can use pre-compiled binaries:

  • To get the binary just download the latest release for your OS/Arch from the releases page
  • Unzip the archive.
  • Add traefik-certs-dumper in your PATH.

From Docker

docker run ldez/traefik-certs-dumper:<tag_name>

Examples:

# assuming you're using traefik in a container, storing its configuration in consul
ubuntu@ereefs-prod-qld-00:~$ docker run --user $(id -u):$(id -g) --network consul_consul -v $(pwd)/dump/:/dump ldez/traefik-certs-dumper kv consul --endpoints consul.cluster:8500
dump
├──certs
│  ├──*.some.domain.com.crt
│  └──some.domain.com.crt
└──private
   ├──*.some.domain.com.key
   ├──some.domain.com.key
   └──letsencrypt.key
ubuntu@ereefs-prod-qld-00:~$ ls -lah
total 16K
drwxr-xr-x 4 ubuntu ubuntu 4.0K Mar 26 04:23 .
drwxr-xr-x 3 root   root   4.0K Mar 21 23:28 ..
drwxr-xr-x 2 ubuntu ubuntu 4.0K Mar 26 04:23 certs
drwxr-xr-x 2 ubuntu ubuntu 4.0K Mar 26 04:23 private
ubuntu@ereefs-prod-qld-00:~$ ls -lah certs/ private/
certs/:
total 16K
drwxr-xr-x 2 ubuntu ubuntu 4.0K Mar 26 04:23  .
drwxr-xr-x 4 ubuntu ubuntu 4.0K Mar 26 04:23  ..
-rw-r--r-- 1 ubuntu ubuntu 3.8K Mar 26 04:23 '*.some.domain.com.crt'
-rw-r--r-- 1 ubuntu ubuntu 3.8K Mar 26 04:23  some.domain.com.crt

private/:
total 20K
drwxr-xr-x 2 ubuntu ubuntu 4.0K Mar 26 04:23  .
drwxr-xr-x 4 ubuntu ubuntu 4.0K Mar 26 04:23  ..
-rw------- 1 ubuntu ubuntu 3.2K Mar 26 04:23 '*.some.domain.com.key'
-rw------- 1 ubuntu ubuntu 3.2K Mar 26 04:23  some.domain.com.key
-rw------- 1 ubuntu ubuntu 3.2K Mar 26 04:23  letsencrypt.key

Usage

Examples

Note: to dump data from Traefik v2, the CLI flag --version v2 must be added.

Simple Dump

$ traefik-certs-dumper file
dump
├──certs
│  └──my.domain.com.key
└──private
   ├──my.domain.com.crt
   └──letsencrypt.key

Change source and destination

$ traefik-certs-dumper file --source ./acme.json --dest ./dump/test
test
├──certs
│  └──my.domain.com.key
└──private
   ├──my.domain.com.crt
   └──letsencrypt.key

Use domain as sub-directory

$ traefik-certs-dumper file --domain-subdir=true
dump
├──my.domain.com
│  ├──certificate.crt
│  └──privatekey.key
└──private
   └──letsencrypt.key

Change file extension

$ traefik-certs-dumper file --domain-subdir --crt-ext=.pem --key-ext=.pem
dump
├──my.domain.com
│  ├──certificate.pem
│  └──privatekey.pem
└──private
   └──letsencrypt.key

Change file name

$ traefik-certs-dumper file --domain-subdir --crt-name=fullchain --key-name=privkey
dump
├──my.domain.com
│  ├──fullchain.crt
│  └──privkey.key
└──private
   └──letsencrypt.key

KV store

Consul

$ traefik-certs-dumper kv consul --endpoints localhost:8500

Etcd

$ traefik-certs-dumper kv etcd --endpoints localhost:2379

Boltdb

$ traefik-certs-dumper kv boltdb --endpoints /the/path/to/mydb.db

Zookeeper

$ traefik-certs-dumper kv zookeeper --endpoints localhost:2181