Is your feature request related to a problem? Please describe:
Portainer docker image is not able to use services secured by certificates issued by a private CA (like Step CA). Even the docker host machine has these CA in the /etc/ssl/certs/ca-certificates.crt the portainer image has his own certificates file and not using the ones on the docker host machine.
Describe the solution you'd like:
Overwrite image default certificates store with the one from host system /etc/ssl/certs/ca-certificates.crt. This can be done by overwriting the file via docker volume parameter when portainer container is started. The volume can be mounted as read-only, so changes are possible only from the docker host.
Additional context
I've activated OIDC auth in portainer using Gitea OAuth feature and both services are using SSL configuration via certificates issued by a private CA. In order for portainer to accept these certificates, the private issuer CA must be made available inside the docker image, without a custom build.
Creating a feature request
Is your feature request related to a problem? Please describe:
Portainer docker image is not able to use services secured by certificates issued by a private CA (like Step CA). Even the docker host machine has these CA in the
/etc/ssl/certs/ca-certificates.crt
the portainer image has his own certificates file and not using the ones on the docker host machine.Describe the solution you'd like:
Overwrite image default certificates store with the one from host system
/etc/ssl/certs/ca-certificates.crt
. This can be done by overwriting the file via docker volume parameter when portainer container is started. The volume can be mounted as read-only, so changes are possible only from the docker host.Additional context
I've activated OIDC auth in portainer using Gitea OAuth feature and both services are using SSL configuration via certificates issued by a private CA. In order for portainer to accept these certificates, the private issuer CA must be made available inside the docker image, without a custom build.
Going to open a PR for supporting this feature.