FerryDocs

Automatic HTTPS

Ferry gets one certificate for each public hostname from Let's Encrypt, with the HTTP-01 challenge.

Edit on GitHub
orderchallengehttps://Ferryproxy on port 80Let's Encryptor an ACME CACertificateshop.example.comBrowser

The proxy routes a new hostname. Ferry orders a certificate from Let's Encrypt.

1 / 4

Ferry gets each from , or from a different . It uses the .

Turn it on

Terminal
ferryd --base-domain apps.example.com \
  --proxy-addr 0.0.0.0:80 --https-addr 0.0.0.0:443 \
  --acme-email you@example.com

The two options --https-addr and --acme-email are necessary. --https-addr alone does not start an listener.

  • The HTTP listener must be reachable from the internet on port 80.
  • The DNS name must point at the server.

Use port 443

With HTTPS on, Ferry prints public URLs as https://host with no port. Listen on 0.0.0.0:443. Then these URLs work.

Which hosts get a certificate

Each host that the proxy routes, but not a and not an IP address:

  • the host of each web service and static site, under each domain of the server
  • each custom domain
  • the dashboard host, if you set one

Each host gets its own certificate. Ferry does not request wildcard certificates.

On this page