!MthpOIxqJhTgrMNxDS:nixos.org

NixOS ACME / LetsEncrypt

117 Members
Another day, another cert renewal49 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
13 Jun 2023
@m1cr0man:m1cr0man.comm1cr0manwhat would we need in lego to make this better? daemonising is out of the question, but there's a lot of logic in the renew script right now that could probably go into lego. In my own head, I had some sort of logic for offline renewal check on my list of things to try and contribute that would greatly reduce the complexity on our side today.20:29:09
@emilazy:matrix.orgemilyI suspect the majority of people don't have any of the special lego options set. but the biggest breakage would be DNS challenge setups, esp. in terms of provider availability.20:29:15
@m1cr0man:m1cr0man.comm1cr0man
In reply to @emilazy:matrix.org
I suspect the majority of people don't have any of the special lego options set. but the biggest breakage would be DNS challenge setups, esp. in terms of provider availability.
yeah lego is pretty much unmatched for DNS support
20:29:33
@emilazy:matrix.orgemilyCaddy/certmagic/etc. do actually have a backwards compatibility layer for lego's providers20:29:34
@m1cr0man:m1cr0man.comm1cr0manoh?20:29:43
@emilazy:matrix.orgemilyand probably the most first party DNS providers outside of lego too (https://github.com/libdns)20:29:51
@m1cr0man:m1cr0man.comm1cr0manoh. wow20:30:34
@emilazy:matrix.orgemilyhttps://github.com/caddy-dns/lego-deprecated is the shim20:31:07
@arianvp:matrix.orgArianI think cert-manager comes close. But it requires Kubernetes 20:34:12
@arianvp:matrix.orgArianIt does all the queueing and concurrency stuff 20:34:49
@m1cr0man:m1cr0man.comm1cr0manugh jeez20:37:19
@emilazy:matrix.orgemilyI think Caddy would be an easier sell than Kubernetes at least :P20:40:27

Show newer messages


Back to Room ListRoom Version: 6