damien

damien

Hi,

I have set up a VPS, installed certbot and managed to run Phoenix 1.5.7 using HTTPS.
The paths to the key and cert files from lets encrypt are read by phoenix from ENV variables in the prod.secret.exs file.
The files will be renewed automatically by certbot every 3 months using a cron job.

I can’t find answers to the following questions:

  • How to deal with the renewal of the keys on the Phoenix side? Do I have to restart the Phoenix server or will Phoenix read the updated files in due time?

  • Would the situation be the same with the new elixir runtime config files?

I would appreciate any insights on these issues which are new to me.
Thanks in advance for your help.

Showing Posts 1 to 8

crova

crova

While I don’t know the exact answers to your questions, maybe you can find some insights from this library.
And if you would accept bringing a dependency to your app, you could use the library to manage your certificates and eventually ditch certbot.

soup

soup

I keep my certs in /etc/letsencrypt/live/..., set in a docker env file.

I add this to my endpoint:

  plug Plug.Static,
    at: "/",
    from: "certbot/"

and have a matching rel/overlays/certbot folder (it’s empty, just exists to create the folder).

I have this in my phoenix service in my docker compose file:

    volumes:
      - ${LETS_ENCRYPT_ROOT}:/etc/letsencrypt:ro
      - ./certbot:/app/certbot

I use certbot’s webroot option and basically tell it to go use /my/compose/root/certbot, which gets mounted at /app/certbot, which cowboy will serve at /, and it all just works.

First run you have to shuffle some mess around but it’s easier to use certbot’s own webserver to generate the first set of certs, then change it to use webroot.

The SSL guide recommends you use the fullchain.pem file for atomic updates, you don’t have to restart phx.

sam701

sam701

I use traefik running in front of my app. It cares about the certificate renewal and also routing.

Exadra37

Exadra37

I am also using it for now, but be very careful with trusting in the headers because they don’t cleanup the headers as they should. For example, the x-forward-for is set by them, but it can also be set by the client sending the request, thus you end-up with two ips in your backend:

curl -I --header "X-Forwarded-For: 82.22.85.84" https://your-site-behind-traefik.tld

Your backend logs:

app_1        | 18:51:33.229 | info | HEAD / | request_id=FnZrTLGwHk701AMAAAax proxy_ip=82.22.85.84, xx.23x.8x.8x remote_ip=::ffff:172.18.0.2 user_agent=curl/7.68.0 module=Phoenix.Logger function=phoenix_endpoint_start/4 line=178

So which IP you gonna trust now proxy_ip=82.22.85.84, xx.23x.8x.8x?

It seems that the last is the real IP from the client, but Treafik should always drop any header it sets, as any good behaved proxy does :slight_smile:

sam701

sam701

That is true, overwritten headers could be an issue. But maybe it is not an issue for @damien I find it nice not to care about certificate renewal.

Regarding the overwritten headers… what if you configure traefik / your LB to use some other, “unforgeable” name for the header, e.g. X-Forwarded-34535435987-For? :slight_smile:

Exadra37

Exadra37

Could be a workaround if Traefik allows for that, but then you also need to account for that in software that assumes the standard header for the proxy to be the x-fowarded-for.

I was loving Traefik until I discovered this issue and that they kept “refusing” to fix it, despite open bugs.

So, I will have to ditch Traefik in a near future, because if they screw-up in the basics of security and won’t fix I don’t even want to imagine what else they got fundamentally wrong.

Exadra37

Exadra37

I strongly recommend you to use the library mentioned by @crova:

This library is from @sasajuric the author of the book Elixir in Action and also a very reputable member of our community :slight_smile:

sasajuric

sasajuric

Author of Elixir In Action

If those files are updated, I think you don’t need to restart anything and the new certs will be eventually picked up. FWIW site_encrypt forces this manually by invoking :ssl.clear_pem_cache.

— All posts loaded —

Where Next? Top

Trending in Questions Top

katta
I having some trouble figuring out if I have set myself too strict of standards for my production server. Currently I can handle 75% of r...
New
brecabral
Documentation While reading the Scoped Routes section, I noticed that the documentation currently refers to a problem without explainin...
New
achenet
Hello, I’m trying to build a basic Phoenix web-app, and I’d like to use Tailwind. However, when I launch mix phx.server, I get an error...
New
kpanic
Hi everyone, I am toying with the idea of building a “match maker” for giving personal help to people that wants to start coding. I sta...
New
asweet-confluent
I recently noticed that Elixir’s Logger defaults its primary log level to :debug when no :logger, :level application configuration is pre...
New
Cxx-mlr
I’m working on a small exercise involving update_in/3, and I came up with this solution: data = %{ name: "Periodic Table", category:...
New
ChrisAmelia
I’ve got trouble wrapping my head around the order in which functions are called in this snippet (from Phoenix’s authentication): toke...
New

Other Trending Topics Top

GenericJam
Edit: 2026 May 15 - This post is archived. Mob is alive!! Main docs: mob v0.7.11 — Documentation A bit of explanation for the slightly c...
New
JesseHerrick
Hey, I’m Jesse and I’m the main contributor behind Dexter, a full-featured, lightning-fast Elixir LSP optimized for large codebases. It s...
New
mudasobwa
I am happy to introduce the very α version of the new programming language compiled to BEAM. Welcome Cure. It has literally three kille...
New
garrison
Hobbes is a low-level distributed database for the Elixir programming language. Hobbes provides a simple, safe, and scalable storage lay...
New
mhanberg
Hi everyone! The first release candidate for the Expert language server project is now available! We’ve published a press release detai...
New
budgie
A little off-topic, but I feel like people here have a good head on their shoulders. I used to be quite good at making software. Was luc...
New

We're in Beta

About us Mission Statement

Options

Thread Display Mode




Thread Preview

Skip Thread Previews