Automating certificate renewal with DNS validation
HTTP validation needs port 80 reachable from the outside. The day a firewall rule changes, renewals quietly start failing and the certificate expires weeks later.
DNS validation only needs API access to the zone, so it keeps working whatever happens to the web ports. Pair it with a deploy hook that copies the new files into place, fixes permissions and reloads only the services that use them.
acme.sh --issue --dns dns_provider -d host.example.com acme.sh --install-cert -d host.example.com \ --fullchain-file /etc/ssl/host/fullchain.crt \ --key-file /etc/ssl/host/cert.key \ --reloadcmd "/usr/local/bin/deploy-cert.sh"
Finally, check the expiry date from a monitoring job rather than trusting the renewal cron.