Skip to main content

nself ssl

nself ssl — ɳSelf documentation.

Manage SSL certificates for ɳSelf services.

Synopsis

nself ssl <subcommand>

Description

nself ssl manages the SSL certificates used by nginx to serve HTTPS traffic for all ɳSelf services. Certificates are generated automatically during nself build, but you can use this command to check their status or force regeneration without a full rebuild.

Certificate generation uses mkcert when available (produces browser-trusted certificates for local development) or falls back to OpenSSL self-signed certificates with Subject Alternative Names (SANs) covering all configured subdomains. Certificates are stored in the project’s ssl/ directory.

Use nself ssl status to verify expiry dates before a deployment or after changing your BASE_DOMAIN. For production domains, ssl add provisions a single-domain certbot certificate and ssl setup provisions certificates via DNS-01 challenge (supports wildcard certs).

Subcommands

Subcommand Description
status Show SSL certificate status by connecting live to configured domains
renew [domain] Reload nginx with existing certificates and optionally run certbot renewal
add <domain> Provision a certbot SSL certificate for a single custom domain
setup Provision SSL certificates via DNS-01 challenge (supports wildcard)

Flags

ssl add <domain>

Flag Default Description
--upstream "" Backend service to proxy to (host:port), e.g. app:3000

ssl setup

Flag Default Description
--provider cloudflare DNS provider: cloudflare, route53, digitalocean, custom
--email "" Email for Let’s Encrypt registration
--wildcard false Request wildcard certificate (*.domain)
--staging false Use Let’s Encrypt staging environment
--install-cron false Install a systemd timer for automatic certificate renewal (Linux only)

Examples

# Check certificate status and expiry
nself ssl status

# Reload nginx with existing certs (and renew if certbot-managed)
nself ssl renew

# Provision a certificate for one custom domain
nself ssl add custom.example.com --upstream app:3000

# Provision a wildcard certificate via Cloudflare DNS-01
nself ssl setup --provider cloudflare --wildcard --email ops@example.com

Sample status output:

Certificate: ssl/cert.pem
  Issued to:  *.localhost, localhost
  Expires:    2027-03-28 (730 days remaining)
  CA trust:   ✓ trusted (mkcert CA installed)
  SANs:       localhost, *.localhost, api.localhost, auth.localhost