Certificates that actually renew

Starting point

Renewal via Certbot ran through hooks that, after the rebuild, pointed at a container that no longer existed. That is exactly how the earlier outage came about.

Decision

I do not rely on names from memory or from old documentation. I ask the real system and test the renewal explicitly.

Implementation

  • I find the actual container name with docker ps --filter name=traefik.
  • The crontab and the renewal configurations of both domains now call docker stop and docker start on the real Traefik container.
  • certbot renew --dry-run --force-renewal passes for both domains.

Takeaway

A --dry-run test is the cheapest insurance against silent outages. I check assumptions on the running system before I write them into a configuration.