🧙
Interactive wizard
Run wizard.sh and answer three questions. Certificate lands in volumes/output/.
Run wizard.sh and answer three questions. Certificate lands in volumes/output/.
fullchain.pem + privkey.pem + cert.pem + ca.pem — ready for Nginx, Synology DSM, OPNsense, and more.
One command converts to PFX for Windows / IIS / Synology apps that require it.
crond runs inside the container. acme.sh renews automatically when certs approach expiry.
Single domain, *.example.com wildcard, or multi-domain SAN — same wizard.
No port 80 or 443 needed. No inbound connection to the device.
Let's Encrypt by default. ZeroSSL and BuyPass selectable without code changes.
amd64 and arm64 on GHCR. Runs on Raspberry Pi as well as x86 hosts.
Uses the official neilpang/acme.sh image as base. No fork, no rewrite.