diff --git a/docker/healthcheck.sh b/docker/healthcheck.sh index 2ab11033..881bbd60 100755 --- a/docker/healthcheck.sh +++ b/docker/healthcheck.sh @@ -74,7 +74,13 @@ esac # Check -wget "$web_url" -O /dev/null -q || exit 1 +# Skip SSL certificate validation since there is no guarantee the container +# trusts the one used. It should be safe to drop the SSL validation since the +# current script intended to be used from inside the container and only checks +# the endpoint availability, ignoring the content of the response. +# +# See https://github.com/AdguardTeam/AdGuardHome/issues/5642. +wget --no-check-certificate "$web_url" -O /dev/null -q || exit 1 echo "$dns_hosts" | while read -r host do diff --git a/docker/web-bind.awk b/docker/web-bind.awk index d9d198dd..d2c3b323 100644 --- a/docker/web-bind.awk +++ b/docker/web-bind.awk @@ -1,23 +1,13 @@ -BEGIN { scheme = "http" } - +# Don't consider the HTTPS hostname since the enforced HTTPS redirection should +# work if the SSL check skipped. See file docker/healthcheck.sh. /^bind_host:/ { host = $2 } /^bind_port:/ { port = $2 } -/force_https: true$/ { scheme = "https" } - -/port_https:/ { https_port = $2 } - -/server_name:/ { https_host = $2 } - END { - if (scheme == "https") { - host = https_host - port = https_port - } if (match(host, ":")) { - print scheme "://[" host "]:" port + print "http://[" host "]:" port } else { - print scheme "://" host ":" port + print "http://" host ":" port } } \ No newline at end of file