runbook: note that Caddy's certificates live on the boot disk

The caddy-data volume is a podman named volume, so it sits under
/var/lib/containers on the boot disk rather than the separately managed
data disk. An instance replacement re-registers the ACME account and
re-issues, and enough of those in a week hits Let's Encrypt's
duplicate-certificate limit.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
2026-10-10 15:21:56 +07:00
co-authored by Claude Opus 5.5
parent b4fad783e4
commit be965b58cf
+7
View File
@@ -58,6 +58,13 @@ curl -vI https://gitea.jasonmross.dev # valid Let's Encrypt cert
DNS-01 means renewal does not need inbound port 80 at all. That is testable:
temporarily remove the `gitea-allow-web` port 80 rule and force a renewal.
The ACME account and certificates live in the `caddy-data` podman volume, under
`/var/lib/containers` on the **boot** disk, not the data disk. Replacing the
instance therefore re-registers and re-issues on first start. That is fine
occasionally, but Let's Encrypt allows 5 duplicate certificates per week, so
several replacements in a few days can lock issuance out until the window
rolls over.
### fail2ban — drill it, do not trust the status output
```bash