Skip to content

HTTPS for a development server

Use the same source-development command on localhost and a public server. The development launcher owns Compose layering and certificate setup.

Local development

Leave LETSENCRYPT_DOMAIN=localhost in .env and run:

scripts/dev-stack up
scripts/dev-stack url

The stack uses self-signed certificates and random loopback ports. Browser tests accept the test certificate. No public DNS or certificate registration is needed.

Public development server

Set LETSENCRYPT_DOMAIN to the server's domain and LETSENCRYPT_EMAIL to the certificate contact address in .env. Both the primary domain and bridge.<domain> must resolve to this server. Ports 80 and 443 must be reachable for the existing HTTP-01 certificate flow.

scripts/dev-stack doctor
scripts/dev-stack up
scripts/dev-stack url
scripts/dev-stack logs -f proxy

The launcher selects public ingress, renders the domain configuration, obtains or renews certificates and reloads the worktree's proxy. Re-run up after configuration changes. Do not call an alternate development Compose recipe or certificate script against fixed global container names.

Port/bind overrides are documented in .env.example for servers with an existing router. Certificates under volume/letsencrypt belong to this checkout; preserve them when maintaining the server.

Published-image production deployment is a separate interface. Follow the setup guide and the installer's certificate configuration rather than using the source-development launcher.