walter
Using Let's Encrypt with Distillery 2 and phoenix 1.4 without nginx
Howdy!
I’m updating a small deployment set up for a friend and have hit a snag. I’m not sure how to integrate Let’s Encrypt via certbot with a distillery based deployment.
I already have a distillery 1.5 based deployment set up on Ubuntu 16.04 based server handling http with nginx. I’m in the process of updating this to use distillery 2 and phoenix 1.4. I figured why not take advantage of cowboy 2’s http2 support and simplify the set up by getting rid of `nginx’ ala steps found in https://blog.progressplum.app/ssl-migration-from-nginx-to-cowboy-2-in-phoenix-1-4/.
I’ve been basing the set up off of https://medium.com/@a4word/phoenix-app-secured-with-let-s-encrypt-469ac0995775. However, this assumes a non-distillery based phoenix server (i.e. no releases) and uses Plug.Static to serve .well-known assets.
My question is how would this work with distillery?
I’m seeing some Elixir packages for handling acme stuff via the app itself, but nothing is jumping out at me as working with phoenix 1.4 well or in combination with distillery.
Most Liked
sasajuric
I’ve written site_encrypt for this purpose. It’s been used for the past 6 months or so on my blog site. The blog itself is an Elixir powered system which uses Phoenix 1.3, and runs as an OTP release built with distillery 1.x. The project source can be found here. The Elixir project is in the site folder, so you can consult that as a template. There’s also a small demo project included in the library repo.
I haven’t tried using site_encrypt with Phoenix 1.4, but in theory it should work. If there are some problems, please open up an issue on GitHub.
alexgaribay
I’m the author of the first article you linked to.
The examples I give are for Distillery, albeit Distillery 2.0. I give an example Mix.Config file that you can use for production. You’ll have to change the values themselves to values like "$MY_ENV_VAR" and allow values to be replaced at run-time with REPLACE_OS_VARS=true.
I’ll update the post to include how you’d do SSL renewal.
OvermindDL1
I find it easier just to use DNS authentication, doesn’t matter what web server you use then, just point them to the live certs is all. ^.^
Don’t need to stop the webserver at all, just make sure the webserver is pulling the live certs and you are good.
Popular in Questions
Other popular topics
Latest Phoenix Threads
Categories:
Sub Categories:
Forums
Popular Tags
- #ecto
- #liveview
- #troubleshooting
- #learning-elixir
- #deployment
- #library
- #erlang
- #testing
- #genserver
- #mix
- #absinthe
- #remote-other
- #otp
- #plug
- #how-to-question
- #macros
- #postgres
- #channels
- #elixirconf
- #exunit
- #discussion
- #code-sync
- #javascript
- #podcasts
- #onsite
- #dialyzer
- #docker
- #authentication
- #umbrella
- #full-time-contract
- #podcasts-by-brainlid
- #ecto-query
- #elixir-ls
- #phoenix_html
- #iex
- #blog-post
- #graphql
- #genstage
- #ai
- #websockets
- #supervisor
- #elixirconf-us
- #advent-of-code
- #distillery
- #processes
- #forms
- #api
- #metaprogramming
- #hex
- #security









