Open nephilim75 opened 9 months ago
I seem to be having a similar issue with a similar OS. The certs maybe seem to be updating automatically now but any time I try to renew them manually or test the site I get an error and NPM crashes.
OS: unraid
OS version: 6.12.3
CPU: AMD Ryzen 7 2700X Eight-Core @ 3700 MHz
│ Application: Nginx Proxy Manager │
│ Application Version: 2.10.4 │
│ Docker Image Version: 23.08.1 │
│ Docker Image Platform: linux/amd64
Container Log:
text error warn system array login
[cont-init ] 55-nginx-proxy-manager.sh: - /config/nginx/proxy_host/9.conf [cont-init ] 55-nginx-proxy-manager.sh: - /config/nginx/resolvers.conf [cont-init ] 55-nginx-proxy-manager.sh: - /config/nginx/default_host/site.conf [cont-init ] 55-nginx-proxy-manager.sh: terminated successfully. [cont-init ] 85-take-config-ownership.sh: executing... [cont-init ] 85-take-config-ownership.sh: terminated successfully. [cont-init ] 89-info.sh: executing... ╭――――――――――――――――――――――――――――――――――――――――――――――――――――――――――――――――――――――╮ │ │ │ Application: Nginx Proxy Manager │ │ Application Version: 2.10.4 │ │ Docker Image Version: 23.08.1 │ │ Docker Image Platform: linux/amd64 │ │ │ ╰――――――――――――――――――――――――――――――――――――――――――――――――――――――――――――――――――――――╯ [cont-init ] 89-info.sh: terminated successfully. [cont-init ] all container initialization scripts executed. [init ] giving control to process supervisor. [supervisor ] loading services... [supervisor ] loading service 'default'... [supervisor ] loading service 'app'... [supervisor ] loading service 'nginx'... [supervisor ] loading service 'logmonitor'... [supervisor ] service 'logmonitor' is disabled. [supervisor ] loading service 'logrotate'... [supervisor ] service 'logrotate' is disabled. [supervisor ] loading service 'cert_cleanup'... [supervisor ] all services loaded. [supervisor ] starting services... [supervisor ] starting service 'nginx'... [supervisor ] starting service 'app'... [app ] [12/5/2023] [9:20:14 PM] [Global ] › ℹ info Using Sqlite: /data/database.sqlite [cert_cleanup] ---------------------------------------------------------- [cert_cleanup] Let's Encrypt certificates cleanup - 2023/12/05 21:20:14 [cert_cleanup] ---------------------------------------------------------- [cert_cleanup] Keeping /etc/letsencrypt/archive/npm-6/privkey2.pem. [cert_cleanup] Keeping /etc/letsencrypt/archive/npm-6/fullchain2.pem. [cert_cleanup] Keeping /etc/letsencrypt/archive/npm-6/cert2.pem. [cert_cleanup] Keeping /etc/letsencrypt/archive/npm-6/chain2.pem. [cert_cleanup] Keeping /etc/letsencrypt/archive/npm-1/cert2.pem. [cert_cleanup] Keeping /etc/letsencrypt/archive/npm-1/privkey2.pem. [cert_cleanup] Keeping /etc/letsencrypt/archive/npm-1/chain2.pem. [cert_cleanup] Keeping /etc/letsencrypt/archive/npm-1/fullchain2.pem. [cert_cleanup] Keeping /etc/letsencrypt/archive/npm-5/privkey2.pem. [cert_cleanup] Keeping /etc/letsencrypt/archive/npm-5/fullchain2.pem. [cert_cleanup] Keeping /etc/letsencrypt/archive/npm-5/chain2.pem. [cert_cleanup] Keeping /etc/letsencrypt/archive/npm-5/cert2.pem. [cert_cleanup] Keeping /etc/letsencrypt/archive/npm-8/fullchain1.pem. [cert_cleanup] Keeping /etc/letsencrypt/archive/npm-8/privkey1.pem. [cert_cleanup] Keeping /etc/letsencrypt/archive/npm-8/chain1.pem. [cert_cleanup] Keeping /etc/letsencrypt/archive/npm-8/cert1.pem. [cert_cleanup] Keeping /etc/letsencrypt/archive/npm-2/chain2.pem. [cert_cleanup] Keeping /etc/letsencrypt/archive/npm-2/privkey2.pem. [cert_cleanup] Keeping /etc/letsencrypt/archive/npm-2/cert2.pem. [cert_cleanup] Keeping /etc/letsencrypt/archive/npm-2/fullchain2.pem. [cert_cleanup] Keeping /etc/letsencrypt/archive/npm-10/fullchain1.pem. [cert_cleanup] Keeping /etc/letsencrypt/archive/npm-10/cert1.pem. [cert_cleanup] Keeping /etc/letsencrypt/archive/npm-10/privkey1.pem. [cert_cleanup] Keeping /etc/letsencrypt/archive/npm-10/chain1.pem. [cert_cleanup] Keeping /etc/letsencrypt/archive/npm-7/fullchain2.pem. [cert_cleanup] Keeping /etc/letsencrypt/archive/npm-7/chain2.pem. [cert_cleanup] Keeping /etc/letsencrypt/archive/npm-7/cert2.pem. [cert_cleanup] Keeping /etc/letsencrypt/archive/npm-7/privkey2.pem. [cert_cleanup] Keeping /etc/letsencrypt/archive/npm-3/chain2.pem. [cert_cleanup] Keeping /etc/letsencrypt/archive/npm-3/fullchain2.pem. [cert_cleanup] Keeping /etc/letsencrypt/archive/npm-3/privkey2.pem. [cert_cleanup] Keeping /etc/letsencrypt/archive/npm-3/cert2.pem. [cert_cleanup] Keeping /etc/letsencrypt/archive/npm-9/privkey1.pem. [cert_cleanup] Keeping /etc/letsencrypt/archive/npm-9/chain1.pem. [cert_cleanup] Keeping /etc/letsencrypt/archive/npm-9/cert1.pem. [cert_cleanup] Keeping /etc/letsencrypt/archive/npm-9/fullchain1.pem. [cert_cleanup] 36 file(s) kept. [cert_cleanup] 0 file(s) deleted. [app ] [12/5/2023] [9:20:15 PM] [Migrate ] › ℹ info Current database version: none [app ] [12/5/2023] [9:20:15 PM] [Setup ] › ℹ info Logrotate Timer initialized [app ] [12/5/2023] [9:20:15 PM] [Setup ] › ℹ info Logrotate completed. [app ] [12/5/2023] [9:20:15 PM] [IP Ranges] › ℹ info Fetching IP Ranges from online services... [app ] [12/5/2023] [9:20:15 PM] [IP Ranges] › ℹ info Fetching https://ip-ranges.amazonaws.com/ip-ranges.json [supervisor ] all services started. [app ] [12/5/2023] [9:20:15 PM] [IP Ranges] › ℹ info Fetching https://www.cloudflare.com/ips-v4 [app ] [12/5/2023] [9:20:15 PM] [IP Ranges] › ℹ info Fetching https://www.cloudflare.com/ips-v6 [app ] [12/5/2023] [9:20:15 PM] [SSL ] › ℹ info Let's Encrypt Renewal Timer initialized [app ] [12/5/2023] [9:20:15 PM] [SSL ] › ℹ info Renewing SSL certs close to expiry... [app ] [12/5/2023] [9:20:15 PM] [IP Ranges] › ℹ info IP Ranges Renewal Timer initialized [app ] [12/5/2023] [9:20:15 PM] [Global ] › ℹ info Backend PID 434 listening on port 3000 ... [app ] [12/5/2023] [9:20:17 PM] [Nginx ] › ℹ info Reloading Nginx [app ] [12/5/2023] [9:20:17 PM] [SSL ] › ℹ info Renew Complete [app ] [12/5/2023] [10:20:15 PM] [SSL ] › ℹ info Renewing SSL certs close to expiry... [app ] [12/5/2023] [10:20:18 PM] [Nginx ] › ℹ info Reloading Nginx [app ] [12/5/2023] [10:20:18 PM] [SSL ] › ℹ info Renew Complete
@nephilim75, since you are using the jc21's image, you should create your issue there instead: https://github.com/NginxProxyManager/nginx-proxy-manager/issues
@z0rg0n, I don't see any error in what you shared. Can you provide more details about the errors ?
Sure thing @jlesage
The error first occurred in October sometime and it was fine before then. It seems like a few other people were having similar issues around then both here in github and on the unraid form.
I noticed that when I tried to navigate to my page through the URL I get a 502 error:
My set up is cloudflare>duck DNS>nginx PM>various docker containers. It seems like the issue is with nginx PM since I can reach the dockers on the loacl network fine and I haven't changed anything in cloudflare or anywhere else.
At first the logs were giving me a renew cert error of some kind but that seems to be resolved in the logs I shared.
When I open up NGINX PM I can click around fine but when I go to the SSL tab and try to test connections it gives me the error 'Communication with the API failed, is NPM running correctly?' Then the entire docker container stops.
Renewing certificates or creating new certificates give me the error 'Internal Error' but does not shut down the container.
A weird bit is I installed the official NGINX docker container and it gives the same errors.
I'm not great at all this sys admin stuff so I'm sorry if that's too much or too little info. But if you or someone can give me some direction if it's not actually a bug it would be much appreciated. I've exhausted all my knowledge and troubleshooting ability.
Then the entire docker container stops.
Can you share the container's log when this happens ?
When I navigate to the SSL Certificate page, click the 3 dots, then click 'Renew Now' the log outputs the following:
[app ] [12/10/2023] [9:57:46 PM] [SSL ] › ℹ info Renewing Let'sEncrypt certificates for Cert #7: nextcloud.jessecloud.club
[app ] [12/10/2023] [9:57:46 PM] [SSL ] › ℹ info Command: certbot renew --force-renewal --config "/etc/letsencrypt.ini" --work-dir "/tmp/letsencrypt-lib" --logs-dir "/tmp/letsencrypt-log" --cert-name "npm-7" --preferred-challenges "dns,http" --no-random-sleep-on-renew --disable-hook-validation
[app ] [12/10/2023] [9:58:19 PM] [Express ] › ⚠ warning Command failed: certbot renew --force-renewal --config "/etc/letsencrypt.ini" --work-dir "/tmp/letsencrypt-lib" --logs-dir "/tmp/letsencrypt-log" --cert-name "npm-7" --preferred-challenges "dns,http" --no-random-sleep-on-renew --disable-hook-validation
[app ] Saving debug log to /tmp/letsencrypt-log/letsencrypt.log
[app ] Failed to renew certificate npm-7 with error: Some challenges have failed.
[app ] All renewals failed. The following certificates could not be renewed:
[app ] /etc/letsencrypt/live/npm-7/fullchain.pem (failure)
[app ] 1 renew failure(s), 0 parse failure(s)
[app ] Ask for help or search for solutions at https://community.letsencrypt.org. See the logfile /tmp/letsencrypt-log/letsencrypt.log or re-run Certbot with -v for more details.
When I test server reach ability on that same page, just before it crashes the log looks like this:
Once it crashes the log closes so I couldn't copy the text.
Ok so there are 2 different problems.
Clicking Test Server Reachability
causes a crash, but this is an isolated issue that doesn't affect normal functionality of NPM.
For the renew issue, did you check at /tmp/letsencrypt-log/letsencrypt.log
(inside the container) to see the details about the problem ?
Thank you for the help! It looks like it's not an issue with Nginx.
Thank you for the help! It looks like it's not an issue with Nginx.
You are talking about the renew failure ?
Yes. I posted in the let's encrypt form and they stated it's an issue with some issue Cloudflare not being configured:
Or maybe it's saying that my server isn't configured correctly 😮💨 in which case I'm back to troubleshooting Niginx I guess.
Either way though I think you can close this bug report, thank you.
Current Behavior
Certs won't be renewed automatically.
Expected Behavior
Certs will be renewed automatically
Steps To Reproduce
Just running NPM as a docker container on unraid server running latest version. I am not so familiar run docker containers, so I might haven't enough information to troubleshoot. Pls guide me to provide all relevant information.
Docker container itself seem sto work fine. Verion should be up to date. I can reach the web UI but I want to have automatic renew of certs in place.
Any idea what I could try to get this fixed?
Environment
Container creation
default settings. No changes done
Container log
Container inspect
Anything else?
No response