Skip to content

How to issue and auto-renew a TLS certificate with Let's Encrypt

How-to · Updated Sep 2026

Coming from another cloud?

▸AWS·ACM

This Quake AI feature maps to AWS’s ACM.

▸DigitalOcean·Load Balancer Lets Encrypt

This Quake AI feature maps to DigitalOcean’s Load Balancer Lets Encrypt.

▸Google Cloud·Managed Certs

This Quake AI feature maps to Google Cloud’s Managed Certs.

Before this

How to issue and auto-renew a TLS certificate with Let's Encrypt

Use Certbot on a Quake AI instance to obtain and renew a TLS certificate from Let's Encrypt. Terminate TLS on the application instance or on a self-managed reverse proxy.

Prerequisites

Windows: CLI examples use bash. Set up a Linux CLI environment on Windows before proceeding.

  • A running Linux instance with a floating IP, SSH access, and a user that can run sudo
  • A certificate hostname that resolves to the instance's floating IP (point your domain at Quake AI)
  • Inbound TCP port 80 for HTTP-01, or API access at your DNS provider for DNS-01

Install Certbot#

bash
sudo apt update
sudo apt install -y certbot

For Nginx or Apache plugins:

bash
sudo apt install -y python3-certbot-nginx

For Apache, install python3-certbot-apache instead.

Choose a challenge#

Choose the challenge that matches your web server and certificate:

ChallengeRequiresUse when
HTTP-01 (webroot)Port 80 reachable on the hostnameNginx/Apache already serves the site
HTTP-01 (standalone)Port 80 free on the instanceNo web server yet; certbot binds temporarily
DNS-01API access at your DNS hostWildcard certificates (*.example.com)

Issue the certificate#

Use HTTP-01 with webroot#

bash
sudo certbot certonly --webroot \
  -w /var/www/html \
  -d www.example.com \
  --agree-tos -m [email protected] --non-interactive

Use HTTP-01 standalone#

If another service uses port 80, stop it before you run Certbot:

bash
sudo certbot certonly --standalone \
  -d www.example.com \
  --agree-tos -m [email protected] --non-interactive

Use DNS-01 for a wildcard certificate#

bash
sudo certbot certonly --manual --preferred-challenges dns \
  -d example.com -d '*.example.com' \
  --agree-tos -m [email protected]

Certbot prints a _acme-challenge TXT record. Add it at your DNS host, wait for propagation, then press Enter to continue.

Certbot stores the certificate at /etc/letsencrypt/live/www.example.com/fullchain.pem and the private key at /etc/letsencrypt/live/www.example.com/privkey.pem.

Configure Nginx or Apache#

Point the TLS listener at fullchain.pem and privkey.pem. Reload the web server after each renewal.

For Nginx with the plugin:

bash
sudo certbot --nginx -d www.example.com

Configure automatic renewal#

The operating-system package normally installs a systemd timer or cron entry for certbot renew. Check for a systemd timer:

bash
systemctl list-timers | grep certbot

Test the renewal configuration:

bash
sudo certbot renew --dry-run

The dry run must finish without renewal errors. If you use standalone mode, configure Certbot renewal hooks to stop and restart the web server, or switch to webroot mode so Certbot can use port 80.

Verify HTTPS and renewal#

List the certificates Certbot manages:

bash
sudo certbot certificates

The output should include the certificate name, covered domains, expiry date, and paths under /etc/letsencrypt/live/.

After you configure TLS termination, request the hostname:

bash
curl -I https://www.example.com

A successful request returns an HTTP status line from your web server or reverse proxy without a TLS verification error. Run sudo certbot renew --dry-run again after you change the web server or challenge configuration.

See also#

Usage Guidelines

The sample code, software libraries, command line tools, proofs of concept, templates, and other related technology on this page (including any of the foregoing that is provided by Quake AI personnel) is provided to you as Quake AI Content under the Quake AI Customer Agreement, or the relevant written agreement between you and Quake AI (whichever applies). Do not use this Quake AI Content in your production accounts, or on production or other critical data. You are responsible for testing, securing, and optimizing the Quake AI Content (such as sample code) as appropriate for production grade use based on your specific quality control practices and standards. Deploying Quake AI Content may incur Quake AI charges for creating or using Quake AI chargeable resources, such as running Compute instances or storing data in Object Storage. Your use is also subject to the Acceptable Use Policy.

For the full policy, see Usage Guidelines.

Last validated: 01.09.2026

Was this page helpful?