diff --git a/docs/src/setup/docker/vanilla-docker-installation.md b/docs/src/setup/docker/vanilla-docker-installation.md index 09c4d5b2643..af706bff410 100644 --- a/docs/src/setup/docker/vanilla-docker-installation.md +++ b/docs/src/setup/docker/vanilla-docker-installation.md @@ -132,7 +132,7 @@ These variables are automatically set by the `create-envfile.py` script if the ` !!! warning When `LETSENCRYPT_MODE` is set to production a valid email and email SMPT server are required to make the system generate a valid certificate. -Whenever you change someting on .env file, you will need to rebuild the containers: +Whenever you change something on .env file, you will need to rebuild the containers: ```bash docker-compose up -d @@ -141,6 +141,75 @@ docker-compose up -d !!! Note This command drops any change you might have done manually inside the containers, except for the static volumes. +### Troubleshoot HTTPS configuration + +If the server is not reachable through HTTPS, inspect the Nginx configuration in the `nginx` container: + +```bash +docker-compose exec nginx sh +cd /etc/nginx +``` + +Check that the `nginx.https.enabled.conf` symlink exists and points to `nginx.https.available.conf`: + +```bash +ls -lah +rm -f nginx.https.enabled.conf +ln -s nginx.https.available.conf nginx.https.enabled.conf +``` + +Inspect the actual HTTPS configuration file: + +```bash +vim nginx.https.available.conf +``` + +!!! warning + Always edit `nginx.https.available.conf`, not `nginx.https.enabled.conf`. The `nginx.https.enabled.conf` file is a symlink, while `nginx.https.available.conf` is the real configuration file where SSL-related changes should be made. + +After saving any changes, reload Nginx: + +```bash +nginx -s reload +exit +``` + +### Configure custom SSL certificates + +In production deployment mode, GeoNode uses Let's Encrypt certificates by default. To provide your own certificates, copy your local certificate files into the Nginx certificate volume and update the HTTPS configuration. + +Assuming your certificate chain and private key are already available on the host as `chain.crt` and `my_geonode.key`, run: + +```bash +docker-compose exec nginx sh -c 'mkdir -p /geonode-certificates/my_geonode' + +docker compose cp chain.crt nginx:/geonode-certificates/my_geonode/chain.crt +docker compose cp my_geonode.key nginx:/geonode-certificates/my_geonode/my_geonode.key + +docker-compose exec nginx sh +cd /etc/nginx +vim nginx.https.available.conf +``` + +!!! note + The `docker compose cp` command requires Docker Compose V2. The legacy `docker-compose` command does not support `cp`. + +Update the certificate paths: + +```diff +-ssl_certificate /certificate_symlink/fullchain.pem; +-ssl_certificate_key /certificate_symlink/privkey.pem; ++ssl_certificate /geonode-certificates/my_geonode/chain.crt; ++ssl_certificate_key /geonode-certificates/my_geonode/my_geonode.key; +``` + +Reload Nginx when the changes are saved: + +```bash +nginx -s reload +exit +``` + ### Remove all data and bring your running GeoNode deployment to the initial stage This action allows you to stop all the containers and reset all the data with the deletion of all the volumes.