What's New
ACME Challenge Exception for IP-Whitelisted Domains
When using --whitelist, the domain script now automatically adds a location block that allows Let's Encrypt HTTP-01 challenges through, even when other traffic is blocked.
# This now works! SSL certificates with IP whitelist
docker exec proxy-nginx /scripts/domain.sh upsert \
--domain=private.example.com \
--upstream=myapp-nginx \
--whitelist="100.64.0.0/10"
docker exec -it proxy-nginx certbot --nginx -d private.example.comRemoved
- TransIP DNS-01 plugin removed - The ACME exception makes DNS-01 unnecessary for most use cases. HTTP-01 works even with IP whitelisting.
Why This Change
After investigation, we found that DNS-01 challenge is not needed for IP-whitelisted domains if nginx is configured correctly. The /.well-known/acme-challenge/ path now bypasses the IP whitelist, allowing Let's Encrypt to verify domain ownership.
Benefits:
- Simpler setup (no DNS provider credentials needed)
- Works with any DNS provider
- Fully automatic renewal via standard HTTP-01
🤖 Generated with Claude Code