-
-
Notifications
You must be signed in to change notification settings - Fork 13
Open
Description
We use dokku-acl together with the dokku-letsencrypt plugin. For auto-renewal of certificates, the plugin creates a cronjob for the dokku-User:
@daily /var/lib/dokku/plugins/available/letsencrypt/cron-job
which in turn executes
dokku letsencrypt:auto-renew &>> /var/log/dokku/letsencrypt.log
which fails on our hosts:
User default does not have permissions to run letsencrypt:auto-renew
Access denied
What would be the best way to fix this issue? I thought about some ways, but I didn't find one which works well...
- We've set
export DOKKU_SUPER_USER=dokku. So if the cronjob would exportNAMEit should work, right? - We could add
letsencrypt:auto-renewtoDOKKU_ACL_USER_COMMANDS. But sinceletsencrypt:auto-renewcallsletsencryptandcerts:add, we would need to whitelist those functions for all apps as well, which is undesirable.
Metadata
Metadata
Assignees
Labels
No labels