Certificates that actually renew
Starting point
Renewal via Certbot ran through hooks that, after the rebuild, pointed at a container that no longer existed. That is exactly how the earlier outage came about.
Decision
I do not rely on names from memory or from old documentation. I ask the real system and test the renewal explicitly.
Implementation
- I find the actual container name with
docker ps --filter name=traefik. - The crontab and the renewal configurations of both domains now call
docker stopanddocker starton the real Traefik container. certbot renew --dry-run --force-renewalpasses for both domains.
Takeaway
A --dry-run test is the cheapest insurance against silent outages. I check assumptions on the running system before I write them into a configuration.