Recently it’s come to my attention that Caddy has an AI sponsor so I have been looking at moving away from Caddy.

I’m currently looking for another reverse proxy to use in place of Caddy. For TLS I am looking into using CertBot and it appears there’s a module (https://github.com/desec-io/certbot-dns-desec) I can use that works for https://desec.io/ to handle my certs.

I have two questions, the first is about CertBot. Since Caddy is handling my certs automatically, how often would I want to renew my certs? Desec.io has this command to obtain a cert:

certbot certonly \
     --authenticator dns-desec \
     --dns-desec-credentials /etc/letsencrypt/secrets/$DOMAIN.ini \
     -d "$DOMAIN" \
     -d "*.$DOMAIN"

Would I be required to run the same command periodically to renew my cert?

My second question is a bit more open ended. I am looking to hear any suggestions or experiences about different reverse proxies that are preferably free of AI. There is a list here with some suggested alternatives: https://codeberg.org/ethical-foss/open-slopware#web-servers

  • confusedpuppy@lemmy.dbzer0.comOP
    link
    fedilink
    English
    arrow-up
    1
    ·
    6 hours ago

    This is great, thank you for taking the time for this write up :) The provided scripts are a huge help to me

    So far my only question I have is about the directories you use. I was wondering if you could provide the directories you use or even just an example so I could better understand the file tree. I’m very particular with my files and have a whole system dedicated to maintaining neat and organized files

    I agree about not using /etc for server related stuff. I keep all my server/container related stuff in /srv so it’s easier for me to manage

    • lemmyvore@feddit.nl
      link
      fedilink
      English
      arrow-up
      1
      ·
      edit-2
      4 hours ago

      The dirs are subdirs of /srv/letsencrypt. I like to take advantage of explicit dir assignment if the software allows it, so I don’t have any surprises if the defaults change.

      ROOT=/srv/letsencrypt
      SECDIR="${ROOT}/secrets"
      CFGDIR="${ROOT}/config"
      LOGDIR="${ROOT}/logs"
      TMPDIR="${ROOT}/tmp"
      
      for DIR in "$SECDIR" "$CFGDIR" "$LOGDIR" "$TMPDIR"; do
              mkdir -p "$DIR"
      done
      
      cd "$ROOT"
      
      ... then venv activate and run venv certbot ...