How to Set Up SSL for Snipe-IT: Docker, Apache, and Nginx Configuration

To set up SSL for Snipe-IT, configure your web server to terminate HTTPS connections on port 443 using an X.509 certificate, then force HTTPS scheme in app/Providers/AppServiceProvider.php and set APP_URL=https://your-domain in the .env file to ensure Laravel generates secure URLs.

Snipe-IT is a Laravel 12 application that requires two layers of SSL configuration: web-server termination for encrypted traffic and framework awareness to generate correct HTTPS URLs. The grokability/snipe-it repository provides Apache virtual-host templates and Docker startup scripts that automate SSL detection and configuration.

Understanding SSL Architecture for Snipe-IT

Setting up SSL consists of two distinct parts. Web-server termination configures Apache, Nginx, or the Docker container to present an X.509 certificate and listen on port 443. Laravel awareness tells the framework that requests are secure so generated URLs, redirects, and the asset pipeline use https:// instead of http://.

The official Docker image ships with an Apache virtual-host template at docker/001-default-ssl.conf and a startup script at docker/startup.sh that automatically enables SSL when certificates are present.

Generate SSL Certificates

Create the certificate directory and generate self-signed certificates for testing, or place CA-signed certificates in the same location:

mkdir -p /var/lib/snipeit/ssl
openssl req -newkey rsa:2048 -nodes -keyout /var/lib/snipeit/ssl/snipeit-ssl.key \
  -x509 -days 365 -out /var/lib/snipeit/ssl/snipeit-ssl.crt \
  -subj "/C=US/ST=State/L=City/O=Organization/CN=snipe.example.com"

Enable SSL in the Container

The docker/startup.sh script checks for the presence of snipeit-ssl.crt and snipeit-ssl.key in /var/lib/snipeit/ssl/ before running a2enmod ssl and a2ensite default-ssl.conf. According to the source code in docker/startup.sh, this automation only triggers if both files exist at container startup.

After placing the certificates, rebuild and restart the containers:

docker compose up -d --build

Method 2: Manual Apache SSL Installation

For traditional Apache installations without Docker, use the SSL configuration template from docker/001-default-ssl.conf as your reference.

Install Certificates

Place your certificate files in the expected directory:

sudo mkdir -p /var/lib/snipeit/ssl
sudo cp your-domain.crt /var/lib/snipeit/ssl/snipeit-ssl.crt
sudo cp your-domain.key /var/lib/snipeit/ssl/snipeit-ssl.key
sudo chown -R www-data:www-data /var/lib/snipeit/ssl

Configure the SSL Virtual Host

Create /etc/apache2/sites-available/snipeit-ssl.conf using the structure from docker/001-default-ssl.conf:

<IfModule mod_ssl.c>
    <VirtualHost *:443>
        ServerName snipe.example.com
        SSLEngine on
        SSLCertificateFile /var/lib/snipeit/ssl/snipeit-ssl.crt
        SSLCertificateKeyFile /var/lib/snipeit/ssl/snipeit-ssl.key
        DocumentRoot /var/www/html/public
        
        <Directory /var/www/html/public>
            AllowOverride All
            Require all granted
        </Directory>
    </VirtualHost>
</IfModule>

Enable the site and required modules:

sudo a2enmod ssl
sudo a2ensite snipeit-ssl.conf
sudo systemctl reload apache2

Redirect HTTP to HTTPS

Add the following rewrite rules to your non-SSL virtual host to force secure connections:

RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]

Method 3: Nginx SSL Configuration

While the repository does not ship an Nginx configuration, apply the same certificate paths and Laravel HTTPS enforcement principles:

server {
    listen 80;
    server_name snipe.example.com;
    return 301 https://$host$request_uri;
}

server {
    listen 443 ssl;
    server_name snipe.example.com;

    ssl_certificate /var/lib/snipeit/ssl/snipeit-ssl.crt;
    ssl_certificate_key /var/lib/snipeit/ssl/snipeit-ssl.key;

    root /var/www/html/public;
    index index.php;

    location / {
        try_files $uri $uri/ /index.php?$query_string;
    }

    location ~ \.php$ {
        fastcgi_pass php-fpm:9000;
        fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
        include fastcgi_params;
    }
}

Configuring Laravel for HTTPS

Regardless of your web server, you must inform Laravel that the application is running behind HTTPS. Edit app/Providers/AppServiceProvider.php to force the HTTPS scheme:

use Illuminate\Support\Facades\URL;

public function boot()
{
    if (config('app.env') === 'production') {
        URL::forceScheme('https');
    }
}

Update the .env file to reflect the secure base URL:

APP_URL=https://snipe.example.com

Clear the configuration cache to apply changes:

php artisan config:clear

The config/app.php file uses this environment variable as the canonical base URL for redirects, password resets, and email notifications.

Troubleshooting Common SSL Issues

  • Docker container does not listen on port 443: Verify that snipeit-ssl.crt and snipeit-ssl.key exist in /var/lib/snipeit/ssl/ before the container starts. The docker/startup.sh script only enables the SSL site if both files are present.
  • Laravel generates HTTP URLs: Ensure APP_URL starts with https:// and that URL::forceScheme('https') is present in app/Providers/AppServiceProvider.php. Run php artisan config:clear after any .env changes.
  • Apache fails to start: Check that certificate files exist at the paths specified in your virtual host and that the www-data user has read permissions.
  • Browser shows certificate warnings: Self-signed certificates trigger security warnings. For production, use certificates from a recognized Certificate Authority or install your self-signed CA into client trust stores.

Summary

  • Place SSL certificates in /var/lib/snipeit/ssl/snipeit-ssl.crt and /var/lib/snipeit/ssl/snipeit-ssl.key for both Docker and manual Apache installations.
  • The docker/startup.sh script auto-enables SSL when certificate files are present at container startup.
  • Reference docker/001-default-ssl.conf for the official Apache SSL virtual-host configuration.
  • Force HTTPS scheme in app/Providers/AppServiceProvider.php using URL::forceScheme('https') to ensure Laravel generates secure URLs.
  • Update APP_URL in .env to use https:// and clear the config cache with php artisan config:clear.

Frequently Asked Questions

Laravel generates URLs based on the APP_URL environment variable and the request scheme. If APP_URL still starts with http:// or if URL::forceScheme('https') is missing from app/Providers/AppServiceProvider.php, the framework will continue producing insecure URLs. Update both settings and clear the configuration cache.

Can I use Let's Encrypt certificates with Snipe-IT Docker?

Yes. Mount your Let's Encrypt certificates to /var/lib/snipeit/ssl/snipeit-ssl.crt and /var/lib/snipeit/ssl/snipeit-ssl.key in the container volume. The docker/startup.sh script will detect these files and automatically enable the SSL virtual host defined in docker/001-default-ssl.conf.

What file permissions are required for SSL certificates?

The web server process must read the certificate files. For Apache in Docker or traditional installs, ensure the www-data user can read /var/lib/snipeit/ssl/snipeit-ssl.crt and /var/lib/snipeit/ssl/snipeit-ssl.key. Set permissions with chmod 644 for the certificate and chmod 600 for the private key.

Where is the SSL configuration stored in the Snipe-IT repository?

The Apache SSL template is located at docker/001-default-ssl.conf, and the startup logic that conditionally enables SSL is in docker/startup.sh. The framework HTTPS enforcement belongs in app/Providers/AppServiceProvider.php, while the base URL configuration is controlled by APP_URL in .env and config/app.php.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →