Skip to content

v1.3.0 - ACME exception for IP-whitelisted domains

Latest

Choose a tag to compare

@jfbauer jfbauer released this 06 Apr 07:22
837e120

What's New

ACME Challenge Exception for IP-Whitelisted Domains

When using --whitelist, the domain script now automatically adds a location block that allows Let's Encrypt HTTP-01 challenges through, even when other traffic is blocked.

# This now works! SSL certificates with IP whitelist
docker exec proxy-nginx /scripts/domain.sh upsert \
  --domain=private.example.com \
  --upstream=myapp-nginx \
  --whitelist="100.64.0.0/10"

docker exec -it proxy-nginx certbot --nginx -d private.example.com

Removed

  • TransIP DNS-01 plugin removed - The ACME exception makes DNS-01 unnecessary for most use cases. HTTP-01 works even with IP whitelisting.

Why This Change

After investigation, we found that DNS-01 challenge is not needed for IP-whitelisted domains if nginx is configured correctly. The /.well-known/acme-challenge/ path now bypasses the IP whitelist, allowing Let's Encrypt to verify domain ownership.

Benefits:

  • Simpler setup (no DNS provider credentials needed)
  • Works with any DNS provider
  • Fully automatic renewal via standard HTTP-01

🤖 Generated with Claude Code