{"id":20688993,"url":"https://github.com/kenzo0107/ngx_mruby-ssl-dynamic-delivery","last_synced_at":"2025-06-17T09:36:46.170Z","repository":{"id":48399326,"uuid":"347868220","full_name":"kenzo0107/ngx_mruby-ssl-dynamic-delivery","owner":"kenzo0107","description":"Tutorial for Certificate Management on Multi-tenant Web Servers","archived":false,"fork":false,"pushed_at":"2021-07-28T05:33:21.000Z","size":275,"stargazers_count":1,"open_issues_count":0,"forks_count":0,"subscribers_count":2,"default_branch":"main","last_synced_at":"2025-03-18T01:52:57.055Z","etag":null,"topics":["mruby"],"latest_commit_sha":null,"homepage":"","language":"Ruby","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/kenzo0107.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null}},"created_at":"2021-03-15T06:58:58.000Z","updated_at":"2022-09-10T15:51:57.000Z","dependencies_parsed_at":"2022-09-05T07:11:53.258Z","dependency_job_id":null,"html_url":"https://github.com/kenzo0107/ngx_mruby-ssl-dynamic-delivery","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/kenzo0107/ngx_mruby-ssl-dynamic-delivery","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/kenzo0107%2Fngx_mruby-ssl-dynamic-delivery","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/kenzo0107%2Fngx_mruby-ssl-dynamic-delivery/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/kenzo0107%2Fngx_mruby-ssl-dynamic-delivery/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/kenzo0107%2Fngx_mruby-ssl-dynamic-delivery/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/kenzo0107","download_url":"https://codeload.github.com/kenzo0107/ngx_mruby-ssl-dynamic-delivery/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/kenzo0107%2Fngx_mruby-ssl-dynamic-delivery/sbom","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":260329445,"owners_count":22992900,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["mruby"],"created_at":"2024-11-16T23:07:47.146Z","updated_at":"2025-06-17T09:36:46.104Z","avatar_url":"https://github.com/kenzo0107.png","language":"Ruby","funding_links":[],"categories":[],"sub_categories":[],"readme":"[![Test](https://github.com/kenzo0107/ngx_mruby-ssl-dynamic-delivery/actions/workflows/test.yml/badge.svg)](https://github.com/kenzo0107/ngx_mruby-ssl-dynamic-delivery/actions/workflows/test.yml) [![Lint](https://github.com/kenzo0107/ngx_mruby-ssl-dynamic-delivery/actions/workflows/lint.yml/badge.svg)](https://github.com/kenzo0107/ngx_mruby-ssl-dynamic-delivery/actions/workflows/lint.yml)\n\n## 本リポジトリの目的\n\nngx_mruby でローカル環境で動的証明書配信を試験する。\n\n以下論文の p4 にある設定例を参考に検証する。\n\n[高集積マルチテナントWebサーバの大規模証明書管理](https://rand.pepabo.com/papers/iot37-proceeding-matsumotory.pdf)\n\n## 構成図\n\n![](logo.png)\n\n1. ngx_mruby で SSL/TLS ハンドシェイク時にドメインを元に Redis から証明書(crt), 秘密鍵(key) を取得\n    - Redis に存在しない場合は DynamoDB から取得し、 Redis にキャッシュ登録\n2. 取得した crt, key を元に SSL/TLS ハンドシェイク\n3. ngx_mruby でアクセスしたドメイン名を返す\n\n簡易的に ngx_mruby を用いた証明書の動的読み込みを体験できる様な構成にしています。\n\n\n## 開発環境の構築\n\n### 1. 環境に必要なツールのインストール\n\n- [dip](https://github.com/bibendi/dip)\n\n### 2. プロビジョニング\n\n```console\ndip provision\n```\n### 3. /etc/hosts 設定\n\n```console\necho \"127.0.0.1 aaa.localhost bbb.localhost foo.example.com\" | sudo tee -a /etc/hosts\n```\n\n各開発環境で利用するドメインを 127.0.0.1 に向ける。\n\n### 4. serverの起動\n\n```console\ndocker-compose up -d\n```\n\n## テスト実行\n\n```console\ndip test\n```\n\n## curl でアクセス\n\n```console\n$ curl -k https://aaa.localhost\naaa.localhost\n\n$ curl -k https://bbb.localhost\nbbb.localhost\n\n$ curl -k https://foo.example.com\nfoo.example.com\n```\n\n各ドメインで証明書を動的に読み込みし、ドメイン名を返すことが確認できる。\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fkenzo0107%2Fngx_mruby-ssl-dynamic-delivery","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fkenzo0107%2Fngx_mruby-ssl-dynamic-delivery","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fkenzo0107%2Fngx_mruby-ssl-dynamic-delivery/lists"}