this post was submitted on 05 Jan 2026
333 points (99.4% liked)

PC Gaming

14642 readers
719 users here now

For PC gaming news and discussion. PCGamingWiki

Rules:

  1. Be Respectful.
  2. No Spam or Porn.
  3. No Advertising.
  4. No Memes.
  5. No Tech Support.
  6. No questions about buying/building computers.
  7. No game suggestions, friend requests, surveys, or begging.
  8. No Let's Plays, streams, highlight reels/montages, random videos or shorts.
  9. No off-topic posts/comments, within reason.
  10. Use the original source, no clickbait titles, no duplicates. (Submissions should be from the original source if possible, unless from paywalled or non-english sources. If the title is clickbait or lacks context you may lightly edit the title.)

founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] Limerance@piefed.social 19 points 4 months ago (6 children)

The problem sometimes is the automation failing for some reason.

[–] dgdft@lemmy.world 5 points 4 months ago* (last edited 4 months ago) (4 children)

Have you had Certbot or LE fail on prod for you before?

I’m sure stuff happens, but I usually view them as one of the most robust moving parts on a server.

E: I don’t mean to express disbelief at all; just curious to learn about possible footguns.

[–] four@lemmy.zip 14 points 4 months ago (2 children)

Certbot / LE has to be running on some machine and that machine can be accidentally turned off, payments not fulfilled, was supposed to be moved but the new instance doesn't work, gateway configuration changed, etc.

Automation requires maintenance and that introduces human error

[–] dgdft@lemmy.world 4 points 4 months ago

Certbot/LE should typically be running on the box that's terminating TLS for you, right? If the box handling your traffic is down, shouldn't that be a self-evident problem?

I've been running Caddy and certbot for nearly a decade and never found a way for them to break without it being 100% my fault. They're more or less self-healing too. I'm with AmbiguousProps; cert renewals have been pretty damn reliable to automate compared to any other piece of tech, IME.

load more comments (1 replies)
load more comments (2 replies)
load more comments (3 replies)