From be965b58cff971a8b6e03fbde0f7f056015af15d Mon Sep 17 00:00:00 2001 From: Jason Ross Date: Sat, 10 Oct 2026 15:21:56 +0700 Subject: [PATCH] runbook: note that Caddy's certificates live on the boot disk The caddy-data volume is a podman named volume, so it sits under /var/lib/containers on the boot disk rather than the separately managed data disk. An instance replacement re-registers the ACME account and re-issues, and enough of those in a week hits Let's Encrypt's duplicate-certificate limit. Co-Authored-By: Claude Opus 5.5 --- docs/runbook.md | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/docs/runbook.md b/docs/runbook.md index f248723..976d664 100644 --- a/docs/runbook.md +++ b/docs/runbook.md @@ -58,6 +58,13 @@ curl -vI https://gitea.jasonmross.dev # valid Let's Encrypt cert DNS-01 means renewal does not need inbound port 80 at all. That is testable: temporarily remove the `gitea-allow-web` port 80 rule and force a renewal. +The ACME account and certificates live in the `caddy-data` podman volume, under +`/var/lib/containers` on the **boot** disk, not the data disk. Replacing the +instance therefore re-registers and re-issues on first start. That is fine +occasionally, but Let's Encrypt allows 5 duplicate certificates per week, so +several replacements in a few days can lock issuance out until the window +rolls over. + ### fail2ban — drill it, do not trust the status output ```bash