Page MenuHomeVyOS Platform

certbot: dependent services might stop on certificate renewal issues
Closed, ResolvedPublicBUG

Description

If ACME/certbot is used for PKI and haproxy it can become an issue if certbot is blocked by the firewall that the renewal service will fail and tear-down the production service - even if the certificate is yet not expired.

haproxy[345144]: [NOTICE]   (345144) : haproxy version is 2.6.12-1+deb12u3
haproxy[345144]: [NOTICE]   (345144) : path to executable is /usr/sbin/haproxy
haproxy[345144]: [WARNING]  (345144) : Exiting Master process...
systemd[1]: Stopping HAProxy Load Balancer...
haproxy[345144]: [ALERT]    (345144) : Current worker (345146) exited with code 143 (Terminated)
haproxy[345144]: [WARNING]  (345144) : All workers exited. Exiting... (0)
systemd[1]: haproxy.service: Deactivated successfully.
systemd[1]: Stopped HAProxy Load Balancer.
systemd[1]: haproxy.service: Consumed 1min 620ms CPU time.

The reason is certbot is erroring out and services are stopped

image.png (952×2 px, 985 KB)

Details

Version
rolling, 1.5.0, 1.4.4
Is it a breaking change?
Unspecified (possibly destroys the router)
Issue type
Bug (incorrect behavior)

Event Timeline

c-po changed the task status from Open to In progress.
c-po claimed this task.
c-po triaged this task as Normal priority.