Configuration
The PHP container does not start as root by default.update-ca-certificates requires root privileges. In your docker-compose.yml, adjust the PHP container as shown below and mount the certificate bundle as a volume.
Remove any existing command on the PHP service. Startup is handled by the customized entrypoint.
The example path
/etc/pki/tls/certs/ca-bundle.crt is typical for RHEL/CentOS systems. On Debian/Ubuntu, the system CA bundle is often at /etc/ssl/certs/ca-certificates.crt. Adjust the host path to match your distribution.Apply
Save yourdocker-compose.yml and restart the containers:
docker compose up -d php.
How It Works
On PHP container startup, the customized entrypoint runs these steps automatically—you do not need to execute anything manually:- The CA bundle is mounted from the host to
/usr/local/share/ca-certificates/. - The container starts as root (
user: "0:0") so thatupdate-ca-certificatescan add the certificates to the system-wide trust store. /scripts/entrypoint.shswitches to the application user (PUID/PGID) and starts VARIOS AI via/scripts/run.sh.
Result
After the container starts:- The host’s CA bundle is available inside the container.
- The certificates are registered in the system-wide trust store.
- Applications in the container can establish TLS connections to servers signed by these CAs.
Typical Use Cases
- Using an internal corporate CA
- Accessing internal APIs with self-signed certificates
- Trust for private container registries or package repositories
- Outbound traffic through a firewall or proxy with TLS inspection
