Raise expiry threshold above certbot's renewal window
Certbot renews at 30 days remaining, so a healthy certificate never falls below it and the old 14 day threshold could only fire after renewal had been broken for 16 straight days, leaving 14 days to react. 25 days fires about five days after the first failed renewal.
This commit is contained in:
12
README.md
12
README.md
@@ -14,7 +14,13 @@ maintenance checks can be added here over time.
|
||||
|
||||
`scripts/check-cert-expiry.sh` checks every Let's Encrypt certificate under
|
||||
`/etc/letsencrypt/live` and sends an ntfy alert when any certificate expires in
|
||||
less than 14 days.
|
||||
less than 25 days.
|
||||
|
||||
The threshold sits just below certbot's own renewal window. Certbot renews at 30
|
||||
days remaining, so a healthy certificate never drops below that. A 25 day
|
||||
threshold fires roughly five days after renewal first fails and still leaves 25
|
||||
days to fix it. A threshold below the renewal window means renewal has to stay
|
||||
broken for weeks before the alert trips, which is too late to be useful.
|
||||
|
||||
### Install
|
||||
|
||||
@@ -32,7 +38,7 @@ sudo install -m 0755 scripts/check-cert-expiry.sh /opt/scripts/check-cert-expiry
|
||||
|
||||
```bash
|
||||
CERT_DIR=/etc/letsencrypt/live
|
||||
EXPIRY_DAYS=14
|
||||
EXPIRY_DAYS=25
|
||||
NTFY_URL=http://127.0.0.1:2586/certbot
|
||||
ALERT_ON_NO_CERTS=true
|
||||
```
|
||||
@@ -40,7 +46,7 @@ ALERT_ON_NO_CERTS=true
|
||||
### Overrides
|
||||
|
||||
```bash
|
||||
EXPIRY_DAYS=21 /opt/scripts/check-cert-expiry.sh
|
||||
EXPIRY_DAYS=40 /opt/scripts/check-cert-expiry.sh
|
||||
```
|
||||
|
||||
If the ntfy topic is protected with an access token:
|
||||
|
||||
Reference in New Issue
Block a user