---
title: Unmanaged Studio Server - Using Let's Encrypt to Handle TLS for You
description: This example uses the popular certbot software and Let's Encrypt service to obtain a new TLS certificate for your server, which is automatically rotated.
---

[Skip to content](https://support.jacktrip.com/unmanaged-studio-server-using-lets-encrypt-to-handle-tls-for-you#main-content)

English

Show submenu for translations

[Customer portal](https://support.jacktrip.com/tickets?hsLang=en)

![jt-logo-dark.png\]](https://support.jacktrip.com/hs-fs/hubfs/jt-logo-dark.png?height=40&name=jt-logo-dark.png)

Open main navigation

Close main navigation

- English
  
  Show submenu for translations
- [Customer portal](https://support.jacktrip.com/tickets)
- Go to JackTrip Labs

 Go to JackTrip Labs

 Hello. How can we help you?

- There are no suggestions because the search field is empty.

1. [Knowledge Base](https://support.jacktrip.com/?hsLang=en)
2. [Managing a JackTrip Server](https://support.jacktrip.com/managing-a-jacktrip-server?hsLang=en)

# Unmanaged Studio Server - Using Let's Encrypt to Handle TLS for You

## This example uses the popular certbot software and Let's Encrypt service to obtain a new TLS certificate for your server, which is automatically rotated.

This example uses the popular [certbot](https://hub.docker.com/r/certbot/certbot/) software and [Let's Encrypt](https://letsencrypt.org/) service to obtain a new TLS certificate for your server, which is automatically rotated. It's based on guidance from [this Medium article](https://pentacent.medium.com/nginx-and-lets-encrypt-with-docker-in-less-than-5-minutes-b4b8a60d3a71) which we recommend reading first for additional context. In fact, you may want to set up a basic web server by following those instructions, before attempting to do it for your studio.

*Note that this example also requires having TCP port 80 accessible from the Internet.*

1. Create a new directory called "studio"
2. Create a new "default.conf" file with the following contents:
   
   ```
   ## Basic Settingstcp_nopush on;tcp_nodelay on;types_hash_max_size 2048;proxy_read_timeout 300;proxy_connect_timeout 300;proxy_send_timeout 300;gzip off;## SSL Settingsssl_protocols TLSv1 TLSv1.1 TLSv1.2 TLSv1.3; # Dropping SSLv3, ref: POODLEssl_prefer_server_ciphers on;## Connection upgrade for websocketsmap $http_upgrade $connection_upgrade {  default upgrade;  ''      close;}## This is used by certbot for domain validationserver {  listen 80;  server_name REPLACE_WITH_FQDN;  location /.well-known/acme-challenge/ {    root /var/www/certbot;  }  location / {    root   /usr/share/nginx/html;    index  index.html index.htm;  }}## Forward 443/tcp to studio container port 8000server {  listen 443 ssl;  server_name REPLACE_WITH_FQDN;  # Certificates generated by Let's Encrypt  ssl_certificate /etc/letsencrypt/live/REPLACE_WITH_FQDN/fullchain.pem;  ssl_certificate_key /etc/letsencrypt/live/REPLACE_WITH_FQDN/privkey.pem;  # Let's Encrypt best practice configs for nginx  include /etc/letsencrypt/options-ssl-nginx.conf;  ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem;  location / {    proxy_pass http://REPLACE_WITH_FQDN:8000;    proxy_buffers 100 128k;    proxy_http_version 1.1;    proxy_set_header Upgrade $http_upgrade;    proxy_set_header Connection $connection_upgrade;  }}
   ```
   
    Replace "REPLACE\_WITH\_FQDN" with your server's fully-qualified domain name.
3. Create a new "compose.yaml" file with the following contents:
   
   ```
   services:  nginx:    image: nginx    container_name: nginx    ports:      - "80:80"      - "443:443"    volumes:      - ./data/certbot/conf:/etc/letsencrypt:z      - ./data/certbot/www:/var/www/certbot:z      - ./default.conf:/etc/nginx/conf.d/default.conf:z    command: "/bin/sh -c 'while :; do sleep 6h & wait $${!}; nginx -s reload; done & nginx -g \"daemon off;\"'"  certbot:    image: certbot/certbot    volumes:      - ./data/certbot/conf:/etc/letsencrypt:z      - ./data/certbot/www:/var/www/certbot:z    entrypoint: "/bin/sh -c 'trap exit TERM; while :; do certbot renew; sleep 12h & wait $${!}; done;'"  studio:    image: jacktrip/studio    container_name: studio    privileged: true    shm_size: '384M'    cap_add:      - sys_nice    ulimits:      rtprio: 95    network_mode: host    environment:      - JACKTRIP_STUDIO_ID=REPLACE_WITH_STUDIO_ID      - JACKTRIP_STUDIO_TOKEN=REPLACE_WITH_STUDIO_TOKEN
   ```
   
    Replace "REPLACE\_WITH\_STUDIO\_ID" with your JACKTRIP\_STUDIO\_ID environment variable.  
   Replace "REPLACE\_WITH\_STUDIO\_TOKEN" with your JACKTRIP\_STUDIO\_TOKEN environment variable.
4. Create a bootstrap certificate for "the chicken or the egg problem" (from Medium article): 
     1. Download the script to your working directory as `init-letsencrypt.sh:`
        
        ```
        curl -L https://raw.githubusercontent.com/wmnnd/nginx-certbot/master/init-letsencrypt.sh > init-letsencrypt.sh
        ```
     2. Edit the script to add in your domain(s) and your email address.
     3. Then run `chmod +x init-letsencrypt.sh` and `./init-letsencrypt.sh`.
5. You should now be able to start up your studio server by running:
   
   ```
   docker-compose up -d
   ```
6. Test to make sure the containers are running and TLS works
   
   ```
   $ docker psCONTAINER ID   IMAGE             COMMAND                  CREATED              STATUS              PORTS                                                                      NAMES391547e7d2a9   jacktrip/studio   "/sbin/init"             About a minute ago   Up About a minute                                                                              studio74fd54feb41a   certbot/certbot   "/bin/sh -c 'trap ex…"   About a minute ago   Up About a minute   80/tcp, 443/tcp                                                            example2-certbot-14afbcc334962   nginx             "/docker-entrypoint.…"   About a minute ago   Up About a minute   0.0.0.0:80->80/tcp, :::80->80/tcp, 0.0.0.0:443->443/tcp, :::443->443/tcp   nginx$ curl https://REPLACE_WITH_FQDN/ping{"status":"OK"}
   ```
7. You are now ready to join your unmanaged studio!
   
    To stop the server after you are finished, run:
   
   ```
   docker-compose down
   ```

- [Setup Guides - Start here!](https://support.jacktrip.com/setup-guides-start-here?hsLang=en#main-content)

    - [Connecting to JackTrip for the First Time](https://support.jacktrip.com/setup-guides-start-here?hsLang=en#connecting-to-jacktrip-for-the-first-time)
    - [Advanced Setup Topics - Connecting, Recording, and Optimizing](https://support.jacktrip.com/setup-guides-start-here?hsLang=en#advanced-setup-topics-connecting-recording-and-optimizing)
    - [Using the Optional JackTrip Bridge](https://support.jacktrip.com/setup-guides-start-here?hsLang=en#using-the-optional-jacktrip-bridge)
- [Info, FAQs, and Troubleshooting](https://support.jacktrip.com/info-faqs-and-troubleshooting?hsLang=en#main-content)

    - [Info and FAQs](https://support.jacktrip.com/info-faqs-and-troubleshooting?hsLang=en#info-and-faqs)
    - [Bridge Troubleshooting](https://support.jacktrip.com/info-faqs-and-troubleshooting?hsLang=en#bridge-troubleshooting)
    - [Troubleshooting](https://support.jacktrip.com/info-faqs-and-troubleshooting?hsLang=en#troubleshooting)
    - [Managing Studio Servers](https://support.jacktrip.com/info-faqs-and-troubleshooting?hsLang=en#managing-studio-servers)
- [Open Source JackTrip](https://support.jacktrip.com/open-source-jacktrip?hsLang=en#main-content)

    - [Getting Started with JackTrip on your Computer](https://support.jacktrip.com/open-source-jacktrip?hsLang=en#getting-started-with-jacktrip-on-your-computer)
    - [Building Your Own JackTrip Bridge Device](https://support.jacktrip.com/open-source-jacktrip?hsLang=en#building-your-own-jacktrip-bridge-device)
    - [Alternative Raspberry Pi Configurations](https://support.jacktrip.com/open-source-jacktrip?hsLang=en#alternative-raspberry-pi-configurations)
    - [External Resources](https://support.jacktrip.com/open-source-jacktrip?hsLang=en#external-resources)
    - [Other Applications Related to JackTrip](https://support.jacktrip.com/open-source-jacktrip?hsLang=en#other-applications-related-to-jacktrip)
    - [Building Virtual Studio](https://support.jacktrip.com/open-source-jacktrip?hsLang=en#building-virtual-studio)
    - [SuperCollider](https://support.jacktrip.com/open-source-jacktrip?hsLang=en#supercollider)
- [Get Started with JackTrip](https://support.jacktrip.com/get-started-with-jacktrip?hsLang=en)
- [Managing a JackTrip Server](https://support.jacktrip.com/managing-a-jacktrip-server?hsLang=en)

# JackTrip Labs Inc.

JackTrip Labs Help Center

Copyright © 2026, JackTrip Labs Inc.