From 1ffb28d4f5086745aea9a5838fd5acf65f8e4954 Mon Sep 17 00:00:00 2001 From: talksik Date: Fri, 22 Dec 2023 09:21:20 -0800 Subject: [PATCH] explaining certificates and such --- README.md | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/README.md b/README.md index 37f3a56..65f7a87 100644 --- a/README.md +++ b/README.md @@ -43,3 +43,13 @@ Make sure you have static ip for each node. Using this guide: https://k21academy.com/docker-kubernetes/prometheus-grafana-monitoring/ +## SSL Certificates +The way it all works in baby terms is that you tell your DNS server like domains.google.com to use an a record for your domain to go to an IP address. + +Then, presuming you have a nginx server running and portforwarding works, certbot will hit your domain (say `flowy.live`), and make sure that it hit this current server (or something like that). + +And then, it generates a certificate with a certificate authority and installs in some folder within the linux computer. + +Then you point to that ssl certificate in nginx config for different endpoints. + +run a cronjob on the system that runs the nginx server as mentioned [here](https://www.nginx.com/blog/using-free-ssltls-certificates-from-lets-encrypt-with-nginx/) to auto-renew certificate(s) when they are about to expire.