Back to BlogServers

Certbot Auto-Renewal with Nginx on Linux

How Let's Encrypt renewal works on Nginx hosts, dry-run testing, and alerts before certificates expire.

Renewal mechanics

Let's Encrypt certificates expire every ninety days. Certbot installs a systemd timer or cron job that runs certbot renew twice daily, renewing only when expiry is near.

The Nginx plugin adjusts server blocks during renewal challenges. Webroot mode suits setups where Nginx config is templated and should not be auto-modified.

Vcom Web Tech verifies renewal after every Nginx refactor because broken location blocks silently break HTTP-01 challenges.

Dry runs and hooks

Run certbot renew --dry-run after initial issuance and after firewall changes. Success in dry-run does not guarantee DNS is correct for all alt names, but it catches most config errors.

Use --deploy-hook to reload Nginx only when a certificate actually renews, avoiding unnecessary reloads twice a day.

Log renewal output to syslog or a file monitored by your alerting stack.

Multi-domain and wildcard

SAN certificates reduce management overhead for www and apex pairs. Wildcard certificates require DNS-01 challenges with API credentials stored securely.

Rotate API tokens used for DNS challenges with least privilege on DNS providers.

Document which domains each certificate covers to prevent accidental partial expiry on legacy hostnames.

When renewal fails

Common failures include port 80 blocked, A records pointing elsewhere, and rate limits from excessive failed orders. Fix root cause before forcing new orders.

Maintain a calendar alert thirty days before manual certificates if you mix Let's Encrypt with corporate CA certs on internal services.

Keep a break-glass procedure to upload temporary certificates if automation breaks during holidays.

Additional operational notes

Operational excellence on Linux hosting requires documenting every change to Nginx, systemd, PM2, Docker, and DNS in a runbook your team shares. Vcom Web Tech clients benefit when staging environments mirror production firewall rules, TLS versions, and mail authentication so surprises appear before customers notice. Schedule quarterly reviews of backups, certificate expiry, DMARC reports, and monitoring alerts even when traffic feels stable.

When incidents occur, capture timelines and root causes in blameless postmortems. Patterns from past 502 errors, failed renewals, or bounce spikes inform checklists for the next deployment. Training new team members on SSH access, log locations, and escalation paths reduces dependency on single maintainers.

Security patches, dependency upgrades, and framework migrations should ride the same CI pipelines that deploy application code. Automate smoke tests that hit health endpoints and send test mail through staging SMTP relays. Small consistent investments beat heroic firefighting during launch weekends.

Capacity planning matters on VPS hosts where vertical scaling has limits. Watch disk inode usage, connection counts, and database connection pools as traffic grows. Proactive upgrades cost less than emergency migrations during peak sales or campaign sends.

Finally, communicate with stakeholders using plain language about risk, downtime windows, and deliverability metrics. Technical depth supports trust when email authentication or deployment strategy changes affect revenue-facing systems.

Additional operational notes

Operational excellence on Linux hosting requires documenting every change to Nginx, systemd, PM2, Docker, and DNS in a runbook your team shares. Vcom Web Tech clients benefit when staging environments mirror production firewall rules, TLS versions, and mail authentication so surprises appear before customers notice. Schedule quarterly reviews of backups, certificate expiry, DMARC reports, and monitoring alerts even when traffic feels stable.

When incidents occur, capture timelines and root causes in blameless postmortems. Patterns from past 502 errors, failed renewals, or bounce spikes inform checklists for the next deployment. Training new team members on SSH access, log locations, and escalation paths reduces dependency on single maintainers.

Security patches, dependency upgrades, and framework migrations should ride the same CI pipelines that deploy application code. Automate smoke tests that hit health endpoints and send test mail through staging SMTP relays. Small consistent investments beat heroic firefighting during launch weekends.

Capacity planning matters on VPS hosts where vertical scaling has limits. Watch disk inode usage, connection counts, and database connection pools as traffic grows. Proactive upgrades cost less than emergency migrations during peak sales or campaign sends.

Finally, communicate with stakeholders using plain language about risk, downtime windows, and deliverability metrics. Technical depth supports trust when email authentication or deployment strategy changes affect revenue-facing systems.