Automating Certificate Issuance with ACME Instead of Manual Renewal
Context
TLS certificates across managed machines were issued and renewed manually, which meant renewals were easy to miss and created recurring outage risk when certificates expired unnoticed.
Decision
Deploy a certificate handler that automates Let's Encrypt issuance and renewal via the ACME protocol across all managed machines.
Alternatives Considered
Keep manual renewal with calendar reminders
Pros
- No new infrastructure to run
Cons
- Still relies on someone remembering and acting in time
- Does not scale as the number of managed machines grows
Use a commercial CA with manual issuance workflow
Pros
- Established vendor support
Cons
- Cost per certificate
- Still a manual process, doesn't remove the core risk
Reasoning
Automating the full certificate lifecycle removed the human failure point entirely. Building a working understanding of the ACME protocol also meant the automation could be debugged and extended rather than treated as a black box.