If ACME/certbot is used for PKI and haproxy it can become an issue if certbot is blocked by the firewall that the renewal service will fail and tear-down the production service - even if the certificate is yet not expired.
haproxy[345144]: [NOTICE] (345144) : haproxy version is 2.6.12-1+deb12u3 haproxy[345144]: [NOTICE] (345144) : path to executable is /usr/sbin/haproxy haproxy[345144]: [WARNING] (345144) : Exiting Master process... systemd[1]: Stopping HAProxy Load Balancer... haproxy[345144]: [ALERT] (345144) : Current worker (345146) exited with code 143 (Terminated) haproxy[345144]: [WARNING] (345144) : All workers exited. Exiting... (0) systemd[1]: haproxy.service: Deactivated successfully. systemd[1]: Stopped HAProxy Load Balancer. systemd[1]: haproxy.service: Consumed 1min 620ms CPU time.
The reason is certbot is erroring out and services are stopped
