nself ssl
nself ssl — ɳSelf documentation.
Manage SSL certificates for ɳSelf services.
Synopsis
nself ssl <subcommand>
Description
nself ssl manages the SSL certificates used by nginx to serve HTTPS traffic for all ɳSelf services. Certificates are generated automatically during nself build, but you can use this command to check their status or force regeneration without a full rebuild.
Certificate generation uses mkcert when available (produces browser-trusted certificates for local development) or falls back to OpenSSL self-signed certificates with Subject Alternative Names (SANs) covering all configured subdomains. Certificates are stored in the project’s ssl/ directory.
Use nself ssl status to verify expiry dates before a deployment or after changing your BASE_DOMAIN. For production domains, ssl add provisions a single-domain certbot certificate and ssl setup provisions certificates via DNS-01 challenge (supports wildcard certs).
Subcommands
| Subcommand | Description |
|---|---|
status |
Show SSL certificate status by connecting live to configured domains |
renew [domain] |
Reload nginx with existing certificates and optionally run certbot renewal |
add <domain> |
Provision a certbot SSL certificate for a single custom domain |
setup |
Provision SSL certificates via DNS-01 challenge (supports wildcard) |
Flags
ssl add <domain>
| Flag | Default | Description |
|---|---|---|
--upstream |
"" |
Backend service to proxy to (host:port), e.g. app:3000 |
ssl setup
| Flag | Default | Description |
|---|---|---|
--provider |
cloudflare |
DNS provider: cloudflare, route53, digitalocean, custom |
--email |
"" |
Email for Let’s Encrypt registration |
--wildcard |
false | Request wildcard certificate (*.domain) |
--staging |
false | Use Let’s Encrypt staging environment |
--install-cron |
false | Install a systemd timer for automatic certificate renewal (Linux only) |
Examples
# Check certificate status and expiry
nself ssl status
# Reload nginx with existing certs (and renew if certbot-managed)
nself ssl renew
# Provision a certificate for one custom domain
nself ssl add custom.example.com --upstream app:3000
# Provision a wildcard certificate via Cloudflare DNS-01
nself ssl setup --provider cloudflare --wildcard --email ops@example.com
Sample status output:
Certificate: ssl/cert.pem
Issued to: *.localhost, localhost
Expires: 2027-03-28 (730 days remaining)
CA trust: ✓ trusted (mkcert CA installed)
SANs: localhost, *.localhost, api.localhost, auth.localhost