diff --git a/etc/docker/README.md b/etc/docker/README.md new file mode 100644 index 00000000..3363c305 --- /dev/null +++ b/etc/docker/README.md @@ -0,0 +1,14 @@ +### Generate Self-Signed Certificate Using OpenSSL + +``` +openssl req -x509 -nodes -days 365 -newkey rsa:2048 -keyout eshop-dk.key -out eshop-dk.crt -subj `"/CN=$certSubj`" -addext `"subjectAltName=DNS:localhost,DNS:host.docker.internal,DNS:app-authserver`" +openssl pkcs12 -export -in eshop-dk.crt -inkey eshop-dk.key -out eshop-dk.pfx -passout pass:8b6039b6-c67a-448b-977b-0ce6d3fcfd49 +``` + +### How to run? + +* Add entries to the hosts file (in Windows: `C:\Windows\System32\drivers\etc\hosts`): + +````powershell +127.0.0.1 app-authserver +```` \ No newline at end of file diff --git a/etc/docker/certs/eshop-dk.crt b/etc/docker/certs/eshop-dk.crt new file mode 100644 index 00000000..c4fd60fa --- /dev/null +++ b/etc/docker/certs/eshop-dk.crt @@ -0,0 +1,19 @@ +-----BEGIN CERTIFICATE----- +MIIDHzCCAgegAwIBAgIUX5WvovRMAkZTaoZGsFNyyjLU7F8wDQYJKoZIhvcNAQEL +BQAwADAeFw0yMjA0MDkxNjU3NDlaFw0yMzA0MDkxNjU3NDlaMAAwggEiMA0GCSqG +SIb3DQEBAQUAA4IBDwAwggEKAoIBAQD0KAzKq9bop31wIPo06eq4AYhdB0zZA+Eh +4mEOvCZ7MtAWUjkP1LudFF4IBlpIaAG0g6o5IhFRHQOIRfVXYA2NSGK8QpVSfmtk +it+Wc9bVvVJ9kqPhVakQIqhkOH4gPJ5MK/fhB6qSiN0TsbXZSHri6Q47Jd46X2DX +LK8c5/KRyrsFY/IVoSHC5kxyxLSzWK7T7JzqEXNtaVCOVf6difuCzPwiqqCk7WtC +LZcCj7n9m5UjpyOLo4iF8wIUk+IpaGKBxYBJ0MuMa8eG3Oz73JZBTaXAAJszNTgG +TVNYuUmi8z4s+U0p+sPW37hpv83atpPaV2rkyaYmM8DNgLyrPj3zAgMBAAGjgZAw +gY0wHQYDVR0OBBYEFGfpXUNdCmwNsLrHLLvxeQ0qQ3b7MB8GA1UdIwQYMBaAFGfp +XUNdCmwNsLrHLLvxeQ0qQ3b7MA8GA1UdEwEB/wQFMAMBAf8wOgYDVR0RBDMwMYIJ +bG9jYWxob3N0ghRob3N0LmRvY2tlci5pbnRlcm5hbIIOYXBwLWF1dGhzZXJ2ZXIw +DQYJKoZIhvcNAQELBQADggEBANY9ID0BUoIAqB/yfQwaXohG8lx4qwGl3BDBzr/L +N0B47WkemFqYNYsAzwdami8hz7D9JIHXeTH+kcpiNE6jrNW31mEzzcgFkzpZxUkb +39mBB5sDNyFlFdObW8G5s0joL0dm2CJK+ujN12EJucOoeOKZmkD49bxc027rj9vz +rEDk3b6L6wkWPf7bBjtHPLfew0R0j1shdZBQFCNa7HRU+JFSXBqHXQKGdxi0uGbb +ENCmZaYHYA4ZO+deqHYr+HWO1tZPS7Wicm+NMEBKqiPB0hQWqUXnBbe6sWGW5TmP +ihgNWE46+y6LMjmxlGUdJNOHAWJVDijWZMsvwnY+doW89MA= +-----END CERTIFICATE----- diff --git a/etc/docker/certs/eshop-dk.key b/etc/docker/certs/eshop-dk.key new file mode 100644 index 00000000..b43ecb99 --- /dev/null +++ b/etc/docker/certs/eshop-dk.key @@ -0,0 +1,28 @@ +-----BEGIN PRIVATE KEY----- +MIIEvQIBADANBgkqhkiG9w0BAQEFAASCBKcwggSjAgEAAoIBAQD0KAzKq9bop31w +IPo06eq4AYhdB0zZA+Eh4mEOvCZ7MtAWUjkP1LudFF4IBlpIaAG0g6o5IhFRHQOI +RfVXYA2NSGK8QpVSfmtkit+Wc9bVvVJ9kqPhVakQIqhkOH4gPJ5MK/fhB6qSiN0T +sbXZSHri6Q47Jd46X2DXLK8c5/KRyrsFY/IVoSHC5kxyxLSzWK7T7JzqEXNtaVCO +Vf6difuCzPwiqqCk7WtCLZcCj7n9m5UjpyOLo4iF8wIUk+IpaGKBxYBJ0MuMa8eG +3Oz73JZBTaXAAJszNTgGTVNYuUmi8z4s+U0p+sPW37hpv83atpPaV2rkyaYmM8DN +gLyrPj3zAgMBAAECggEAZG5tBJk257CtyofmJAnsgRAwVYQBOmt8GgISxorikV7P +db8QtdBd9DlCjK6ASLRvrx9Rz/qRgPocT9vnFa/vIySZaLNC1RInfs4ZNrwjrPwZ +iInfW3tu9bIr7j3Gs9/7hX24kxoiMfCWb9lz4hMMaXZQYkgrZ3uATEKXLZ7DivA5 +2yku9gQdWZlwXSQqWgx2kwZjyRAkUC88HtPfxCkF0NHJur7CgM3UxeFockwfJ+/i +EUFoklMSolIlqivJ1765J17hW7vebBnP7b5SZJFAGjxxhLJ7wQ+FlZiwNEoCLDZx +B7S6ARzzNAdMOsls1DwQWrX5Nupl3XgQRBakMEJxIQKBgQD7WkZV2XDkyEnBYTk2 +e2DYNlFNsJeHhwml0jTBASMGosrwRqFf4DpozFap6UFPHTyhYcGJfEfojG8zrWN+ +MuYT0EzMHtPBPnDSCtKeeZ2wq+ON3gps3lsdIJLgCo9IGbak+90AigzVe5JPykuh +qu6XGs1f/DSGLXAk1IqgsQbrmQKBgQD4q7ardKl0U2m4OiozAZqUR5l1oe+MSdxZ +j3DGkMpOe7F+b63jHtWjEE3MEtzKXsZxOucy5S3OTZs0hdRB+IRP443uNARoaatN +14ZYbvPjmCTn6m6qR+fs7MWesaUStAVgGVWQgWY+4CZz3Zm+UXcmS+QHoiSbGfaz +neI4tFsNawKBgQCyxCLwHgVIAhdK3S4GzLs1K3Spz6YF8wnukNGKT5esuY2iVGmj +ueNw85vTnp0feojLsq4mbWjrQS45z+DKOcMfZm+oYWhzsUgmayIfKhn4NFhUZw59 +HawpzCgKBhifzAH111f4cTbtgsSt0Q/3fI3SlHJrCQIGSDzRRQUPgriMSQKBgGuJ +Llyk/abNb5l4pcka93MKJ4XkOohrZHvieP2Vnbck7JPlzce7DN4QbeRDf/GP3LcY +puSukQl3LBghi7Hfu7AkkrshCYrxr1/hRTq2+IdCwyr7iVHf+J7PoYJIBj+5U93D +9umf28xy+I4Albzk0+beyMS4TKY6KyJvs2WcMQfzAoGARac5umqHTqNubeVoB2EX +BMFj55RDkWH9GU631deMDgfPvymZJ5HI1Dz+jdX7PbOfPbc+5AUN4lZqZw5/2yxN +ps0BUMz1Hr4goeoC0akFsnA5GXoFkhWh6xR45ZRfmPEDYxvk8tqeZvtZns+3AjfR ++C6C4YZdYsgLfWRFtxW3OlA= +-----END PRIVATE KEY----- diff --git a/etc/docker/certs/eshop-ssl.conf b/etc/docker/certs/eshop-ssl.conf new file mode 100644 index 00000000..e82d4494 --- /dev/null +++ b/etc/docker/certs/eshop-ssl.conf @@ -0,0 +1,40 @@ +[req] +default_bits = 2048 +default_keyfile = eshop-dk.key +distinguished_name = req_distinguished_name +req_extensions = req_ext +x509_extensions = v3_ca + +[req_distinguished_name] +commonName = Common Name (e.g. server FQDN or YOUR name) +commonName_default = eshoponabp +commonName_max = 64 + +[req_ext] +subjectAltName = @alt_names + +[v3_ca] +subjectAltName = @alt_names +basicConstraints = critical, CA:false +keyUsage = keyCertSign, cRLSign, digitalSignature,keyEncipherment + +[alt_names] +DNS.1 = localhost +DNS.2 = 127.0.0.1 +DNS.3 = host.docker.internal +DNS.4 = app-authserver +DNS.5 = app-web +DNS.6 = app-publicweb +DNS.7 = gateway-web +DNS.8 = gateway-web-public +DNS.9 = administration-service +DNS.10 = identity-service +DNS.11 = catalog-service +DNS.12 = basket-service +DNS.13 = ordering-service +DNS.14 = payment-service + +# Generate certificate from config +# Use the command: +# 'openssl req -x509 -nodes -days 365 -newkey rsa:2048 -keyout eshop-dk.key -out eshop-dk-cert.pem -config eshop-ssl.conf' + diff --git a/etc/docker/docker-compose.yml b/etc/docker/docker-compose.yml index a0134896..01593fbf 100644 --- a/etc/docker/docker-compose.yml +++ b/etc/docker/docker-compose.yml @@ -10,7 +10,7 @@ services: environment: - ASPNETCORE_ENVIRONMENT=Docker - ASPNETCORE_URLS=https://+:443;http://+:80; - - Kestrel__Certificates__Default__Path=/root/certificate/localhost.pfx + - Kestrel__Certificates__Default__Path=/root/certificate/eshop-dk.pfx - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 # - Redis__Configuration=redis # - RabbitMQ__Connections__Default__HostName=rabbitmq @@ -28,7 +28,7 @@ services: networks: - eshoponabp-network volumes: - - ../dev-cert:/root/certificate + - ./certs:/root/certificate identity-service: image: eshoponabp/service-identity:latest container_name: identity-service-container @@ -38,7 +38,7 @@ services: environment: - ASPNETCORE_ENVIRONMENT=Docker - ASPNETCORE_URLS=https://+:443;http://+:80 - - Kestrel__Certificates__Default__Path=/root/certificate/localhost.pfx + - Kestrel__Certificates__Default__Path=/root/certificate/eshop-dk.pfx - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 - Redis__Configuration=redis - RabbitMQ__Connections__Default__HostName=rabbitmq @@ -57,7 +57,7 @@ services: networks: - eshoponabp-network volumes: - - ../dev-cert:/root/certificate + - ./certs:/root/certificate catalog-service: image: eshoponabp/service-catalog:latest container_name: catalog-service-container @@ -67,7 +67,7 @@ services: environment: - ASPNETCORE_ENVIRONMENT=Docker - ASPNETCORE_URLS=https://+:443;http://+:80;http://+:81; - - Kestrel__Certificates__Default__Path=/root/certificate/localhost.pfx + - Kestrel__Certificates__Default__Path=/root/certificate/eshop-dk.pfx - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 - Kestrel__EndPoints__Http__Url=http://docker.host.internal:80 - Kestrel__EndPoints__Https__Url=https://docker.host.internal:443 @@ -91,7 +91,7 @@ services: networks: - eshoponabp-network volumes: - - ../dev-cert:/root/certificate + - ./certs:/root/certificate basket-service: image: eshoponabp/service-basket:latest container_name: basket-service-container @@ -101,7 +101,7 @@ services: environment: - ASPNETCORE_ENVIRONMENT=Docker - ASPNETCORE_URLS=https://+:443;http://+:80; - - Kestrel__Certificates__Default__Path=/root/certificate/localhost.pfx + - Kestrel__Certificates__Default__Path=/root/certificate/eshop-dk.pfx - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 # - Redis__Configuration=redis # - RabbitMQ__Connections__Default__HostName=rabbitmq @@ -121,7 +121,7 @@ services: networks: - eshoponabp-network volumes: - - ../dev-cert:/root/certificate + - ./certs:/root/certificate ordering-service: image: eshoponabp/service-ordering:latest container_name: ordering-service-container @@ -131,7 +131,7 @@ services: environment: - ASPNETCORE_ENVIRONMENT=Docker - ASPNETCORE_URLS=https://+:443;http://+:80; - - Kestrel__Certificates__Default__Path=/root/certificate/localhost.pfx + - Kestrel__Certificates__Default__Path=/root/certificate/eshop-dk.pfx - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 - Redis__Configuration=redis - RabbitMQ__Connections__Default__HostName=rabbitmq @@ -150,7 +150,7 @@ services: networks: - eshoponabp-network volumes: - - ../dev-cert:/root/certificate + - ./certs:/root/certificate payment-service: image: eshoponabp/service-payment:latest container_name: payment-service-container @@ -160,7 +160,7 @@ services: environment: - ASPNETCORE_ENVIRONMENT=Docker - ASPNETCORE_URLS=https://+:443;http://+:80; - - Kestrel__Certificates__Default__Path=/root/certificate/localhost.pfx + - Kestrel__Certificates__Default__Path=/root/certificate/eshop-dk.pfx - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 - Redis__Configuration=redis - RabbitMQ__Connections__Default__HostName=rabbitmq @@ -182,7 +182,7 @@ services: networks: - eshoponabp-network volumes: - - ../dev-cert:/root/certificate + - ./certs:/root/certificate app-web: image: eshoponabp/app-web:latest container_name: app-web-container @@ -203,7 +203,7 @@ services: networks: - eshoponabp-network volumes: - - ../dev-cert:/root/certificate + - ./certs:/root/certificate app-authserver: image: eshoponabp/app-authserver:latest container_name: app-authserver-container @@ -214,7 +214,7 @@ services: - ASPNETCORE_ENVIRONMENT=Docker - ASPNETCORE_URLS=https://+:443;http://+:80; - ASPNETCORE_HTTPS_PORT=44330 - - Kestrel__Certificates__Default__Path=/root/certificate/localhost.pfx + - Kestrel__Certificates__Default__Path=/root/certificate/eshop-dk.pfx - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 # - Redis__Configuration=redis # - RabbitMQ__Connections__Default__HostName=rabbitmq @@ -238,7 +238,7 @@ services: networks: - eshoponabp-network volumes: - - ../dev-cert:/root/certificate + - ./certs:/root/certificate app-publicweb: image: eshoponabp/app-publicweb:latest container_name: app-publicweb-container @@ -248,7 +248,7 @@ services: environment: - ASPNETCORE_ENVIRONMENT=Docker - ASPNETCORE_URLS=https://+:443;http://+:80; - - Kestrel__Certificates__Default__Path=/root/certificate/localhost.pfx + - Kestrel__Certificates__Default__Path=/root/certificate/eshop-dk.pfx - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 # - Redis__Configuration=redis # - RabbitMQ__Connections__Default__HostName=rabbitmq @@ -268,7 +268,7 @@ services: networks: - eshoponabp-network volumes: - - ../dev-cert:/root/certificate + - ./certs:/root/certificate gateway-web: image: eshoponabp/gateway-web:latest container_name: gateway-web-container @@ -278,7 +278,7 @@ services: environment: - ASPNETCORE_ENVIRONMENT=Docker # Yarp can't resolve dns, needs to be overridden - ASPNETCORE_URLS=https://+:443;http://+:80; - - Kestrel__Certificates__Default__Path=/root/certificate/localhost.pfx + - Kestrel__Certificates__Default__Path=/root/certificate/eshop-dk.pfx - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 - Redis__Configuration=redis - ReverseProxy__Clusters__accountCluster__Destinations__destination1__Address=http://app-authserver @@ -300,7 +300,7 @@ services: networks: - eshoponabp-network volumes: - - ../dev-cert:/root/certificate + - ./certs:/root/certificate gateway-web-public: image: eshoponabp/gateway-web-public:latest container_name: gateway-web-public-container @@ -310,7 +310,7 @@ services: environment: - ASPNETCORE_ENVIRONMENT=Docker # Yarp can't resolve dns, needs to be overridden - ASPNETCORE_URLS=https://+:443;http://+:80; - - Kestrel__Certificates__Default__Path=/root/certificate/localhost.pfx + - Kestrel__Certificates__Default__Path=/root/certificate/eshop-dk.pfx - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 - Redis__Configuration=redis - ReverseProxy__Clusters__accountCluster__Destinations__destination1__Address=http://app-authserver @@ -331,7 +331,7 @@ services: networks: - eshoponabp-network volumes: - - ../dev-cert:/root/certificate + - ./certs:/root/certificate networks: eshoponabp-network: