Feat: Add ACME certificate automation (Let's Encrypt + full DNS-01 support via acme.sh) #52
Open
opened 2026-05-27 08:43:42 +01:00 by Gandalf
·
0 comments
No Branch/Tag Specified
main
release/1.7.38
develop
release/1.7.37
release/1.7.36
release/1.7.35
release/1.7.34
release/1.7.33
release/1.7.32
release/1.7.31
release/1.7.30
release/1.7.29
release/1.7.28
release/1.7.27
release/1.7.26
release/1.7.25
release/1.7.24
release/1.7.23
release/1.7.22
release/1.7.21
release/1.7.20
release/1.7.19
release/1.7.18
release/1.7.17
release/1.7.16
release/1.7.15
release/1.7.14
release/1.7.13
release/1.7.12
release/1.7.11
release/1.7.10
release/1.7.9
release/1.7.8
release/1.7.7
release/1.7.6
release/1.7.5
release/1.7.4
release/1.7.3
release/1.6.0
release/1.5.5
release/1.5.3
release/1.5.2
release/1.5.0a
release/1.4.0
release/1.3.1a
release/1.3.1
release/1.3.0
release/v1.2.2
release/v1.2.1
release/v1.2.0
release/1.1.2
release/1.1.1
release/1.1.0
release/1.0.0
release/0.2.0
release/v0.1.5
release/0.1.4
release/0.1.3
release/0.1
v1.7.38
v1.7.37
v1.7.36
v1.7.35
v1.7.34
v1.7.33
v1.7.32
v1.7.31
v1.7.30
v1.7.29
v1.7.28
v1.7.27
v1.7.26
v1.7.25
v1.7.24
v1.7.23
v1.7.22
v1.7.21
v1.7.20
v1.7.19
v1.7.18
v1.7.17
v1.7.16
v1.7.15
v1.7.14
v1.7.13
v1.7.12
v1.7.11
v1.7.10
v1.7.9
v1.7.8
v1.7.7
v1.7.6
v1.7.5
v1.7.4
v1.7.3
v1.6.0
v1.5.5
v1.5.3
v1.5.2
v1.5.1
v1.5.0a
v1.4.0
v1.3.1a
v1.3.1
v1.2.2
v1.2.1
v1.2.0
v1.1.2
v1.1.1
v1.1.0
v1.0.0
v0.2.0
v0.1.5
v0.1.4
v0.1.3
v0.1.2
v0.1.1
v0.1.0
Labels
Clear labels
Area/Docker
Area/Download Clients
Area/Frontend
Area/History
Area/Logging
Area/Matching
Area/Proxy
Area/SSE
Area/Webhooks
Compat/Breaking
Compat/Non-Breaking
Kind/Bug
Kind/Documentation
Kind/Enhancement
Kind/Feature
Kind/Security
Kind/Testing
Docker image and container packaging
Download client integrations
Client-side UI and build tooling
History and completed downloads views
Log streaming, file handling, and debug infrastructure
Matching and correlation logic
Upstream service proxy routes
Server-Sent Events and real-time streaming
Webhook processing and reliability
Breaking change that won't be backward compatible
Non-breaking compatibility change
Something is not working
Documentation changes
Improve existing functionality
New functionality
This is security issue
Issue or pull request related to testing
Priority
Critical
1
The priority is critical
Priority
High
2
The priority is high
Priority
Low
4
The priority is low
Priority
Medium
3
The priority is medium
Reviewed
Confirmed
1
Issue has been confirmed
Reviewed
Duplicate
2
This issue or pull request already exists
Reviewed
Invalid
3
Invalid issue
Reviewed
Won't Fix
3
This issue won't be fixed
Status
Abandoned
3
Somebody has started to work on this but abandoned work
Status
Blocked
1
Something is blocking this issue or pull request
Status
Need More Info
2
Feedback is required to reproduce issue or to continue work
Milestone
No items
No Milestone
Projects
Clear projects
No projects
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: Gandalf/sofarr#52
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Problem
Sofarr currently uses a bundled self-signed snakeoil certificate for its native HTTPS support (added in commit
da0898f). While this provides out-of-the-box HTTPS without an external reverse proxy, self-signed certificates are:Users who want proper trusted certificates are forced into workarounds (manual Let's Encrypt, custom cert mounting, or adding nginx/Caddy/Traefik), which undermines Sofarr’s “simple Docker deployment, no external web server required” design goal.
Proposed Solution
Add built-in ACME certificate automation with automatic issuance and renewal.
Key Requirements:
.env+ Docker workflow)Suggested Environment Variables
Implementation Recommendation (to keep it lightweight)
acme.sh --issue --dns $PROVIDER ...when neededfullchain.pem+privkey.pemin the expectedcerts/locationhttpsServer.setSecureContext()or file watcher)/app/certs).env.sampleWhy acme.sh?
It exactly matches the request (“essentially all the methods available in acme.sh”) and is the lightest, most battle-tested option with the broadest DNS provider coverage.
Benefits