If, after configuring the domain in our Ghost image, you want to set up your blog as a secure site with an SSL certificate, you should follow the steps outlined below.
We will install Certbot to set up a free certificate from Let’s Encrypt. To perform these steps, you will need to connect via SSH to the Ghost server you created and configure it as explained below.
Select the update method
To update Ghost using our pre-installed image, follow the procedure corresponding to the Ubuntu version you used when deploying the server. If you chose the image based on Ubuntu 24.04, follow its update instructions. If you chose Ubuntu 26.04, use the procedure corresponding to that version.
Configure SSL in Ghost
Select the procedure to follow below:
Before changing the domain, verify that its DNS record points to the server's IP address.
Next, edit the /opt/ghost/.env file and replace the value of DOMAIN with your domain:
DOMAIN=example.com
Save the changes and, from the /opt/ghost directory, recreate the containers to apply the new configuration:
docker compose up -d --force-recreate
Once the containers are running and the DNS resolves to the server, you will be able to access Ghost from your domain. Caddy will automatically manage the SSL certificate according to the image configuration.
NOTICE
To run Ghost-CLI commands, you must do so with the ghostinst user, which is the user used to install Ghost. Therefore, commands must be executed as explained in this tutorial.
Manual installation of the SSL certificate
First of all, we configure our domain under HTTPS, and to do so we move to the installation directory:
# cd /var/www/ghost/
Then we change the domain name:
# su ghostinst -c 'ghost config url https://midominio.es'
And restart Ghost:
# su ghostinst -c 'ghost restart'
Next, we install the following packages to generate the SSL certificate with CertBot:
# apt install certbot python3-certbot-nginx
Then we will need to edit the Nginx configuration file located at /etc/nginx/sites-enabled/default:
# nano /etc/nginx/sites-enabled/default
We need to change this:
server_name Ghost;
To this (adding www is optional, not required):
server_name midominio.es www.midominio.es;
Save and restart the Nginx service:
# systemctl restart nginx
And finally, we generate the certificate with the following command:
# certbot --authenticator webroot -w /var/www/html/ --redirect --installer nginx -d midominio.es
If you added www, you must run:
# certbot --authenticator webroot -w /var/www/html/ --redirect --installer nginx -d midominio.es -d www.midominio.es
Remember, if you have any questions about this or any other issue regarding your servers at Clouding, feel free to contact soporte@clouding.io We are here to help you with whatever you need, just ask us!