How to issue and auto-renew a TLS certificate with Let's Encrypt
Coming from another cloud?
▸AWS·ACM
This Quake AI feature maps to AWS’s ACM.
▸DigitalOcean·Load Balancer Lets Encrypt
This Quake AI feature maps to DigitalOcean’s Load Balancer Lets Encrypt.
▸Google Cloud·Managed Certs
This Quake AI feature maps to Google Cloud’s Managed Certs.
How to issue and auto-renew a TLS certificate with Let's Encrypt
Use Certbot on a Quake AI instance to obtain and renew a TLS certificate from Let's Encrypt. Terminate TLS on the application instance or on a self-managed reverse proxy.
Prerequisites
- CLIOpenStack CLI installed and authenticated (
clouds.yamloropenrcsourced)
Windows: CLI examples use bash. Set up a Linux CLI environment on Windows before proceeding.
- A running Linux instance with a floating IP, SSH access, and a user that can run
sudo - A certificate hostname that resolves to the instance's floating IP (point your domain at Quake AI)
- Inbound
TCPport80forHTTP-01, or API access at your DNS provider forDNS-01
Install Certbot#
sudo apt update
sudo apt install -y certbotFor Nginx or Apache plugins:
sudo apt install -y python3-certbot-nginxFor Apache, install python3-certbot-apache instead.
Choose a challenge#
Choose the challenge that matches your web server and certificate:
| Challenge | Requires | Use when |
|---|---|---|
| HTTP-01 (webroot) | Port 80 reachable on the hostname | Nginx/Apache already serves the site |
| HTTP-01 (standalone) | Port 80 free on the instance | No web server yet; certbot binds temporarily |
| DNS-01 | API access at your DNS host | Wildcard certificates (*.example.com) |
Issue the certificate#
Use HTTP-01 with webroot#
sudo certbot certonly --webroot \
-w /var/www/html \
-d www.example.com \
--agree-tos -m [email protected] --non-interactiveUse HTTP-01 standalone#
If another service uses port 80, stop it before you run Certbot:
sudo certbot certonly --standalone \
-d www.example.com \
--agree-tos -m [email protected] --non-interactiveUse DNS-01 for a wildcard certificate#
sudo certbot certonly --manual --preferred-challenges dns \
-d example.com -d '*.example.com' \
--agree-tos -m [email protected]Certbot prints a _acme-challenge TXT record. Add it at your DNS host, wait for propagation, then press Enter to continue.
Certbot stores the certificate at /etc/letsencrypt/live/www.example.com/fullchain.pem and the private key at /etc/letsencrypt/live/www.example.com/privkey.pem.
Configure Nginx or Apache#
Point the TLS listener at fullchain.pem and privkey.pem. Reload the web server after each renewal.
For Nginx with the plugin:
sudo certbot --nginx -d www.example.comConfigure automatic renewal#
The operating-system package normally installs a systemd timer or cron entry for certbot renew. Check for a systemd timer:
systemctl list-timers | grep certbotTest the renewal configuration:
sudo certbot renew --dry-runThe dry run must finish without renewal errors. If you use standalone mode, configure Certbot renewal hooks to stop and restart the web server, or switch to webroot mode so Certbot can use port 80.
Verify HTTPS and renewal#
List the certificates Certbot manages:
sudo certbot certificatesThe output should include the certificate name, covered domains, expiry date, and paths under /etc/letsencrypt/live/.
After you configure TLS termination, request the hostname:
curl -I https://www.example.comA successful request returns an HTTP status line from your web server or reverse proxy without a TLS verification error. Run sudo certbot renew --dry-run again after you change the web server or challenge configuration.
See also#
Usage Guidelines
The sample code, software libraries, command line tools, proofs of concept, templates, and other related technology on this page (including any of the foregoing that is provided by Quake AI personnel) is provided to you as Quake AI Content under the Quake AI Customer Agreement, or the relevant written agreement between you and Quake AI (whichever applies). Do not use this Quake AI Content in your production accounts, or on production or other critical data. You are responsible for testing, securing, and optimizing the Quake AI Content (such as sample code) as appropriate for production grade use based on your specific quality control practices and standards. Deploying Quake AI Content may incur Quake AI charges for creating or using Quake AI chargeable resources, such as running Compute instances or storing data in Object Storage. Your use is also subject to the Acceptable Use Policy.
For the full policy, see Usage Guidelines.
Last validated: 01.09.2026