Renew SSL certificates on every server, safely¶
sslsync puts a new certificate on all your servers from one laptop. It checks every server first, replaces the files, reloads the services, and proves that each port serves the new certificate. If anything goes wrong, it puts the old certificate back automatically.
Why sslsync¶
-
One file to configure
Every server, port, path and password lives in one
.envfile. No YAML, no code.sslsync listtells you about typos. -
Nothing changes until it is safe
Login, sudo, service health, file paths and permissions are all checked before a single byte is written.
-
Proof, not hope
After a reload, sslsync connects to every port and compares the certificate byte for byte. "Reload succeeded" is not enough.
-
Automatic rollback
A failed reload, health check or verification restores the old files, Kubernetes secrets and permissions, then reloads again.
-
Works with what you have
Nginx, Apache, HAProxy, MinIO, PostgreSQL, Kubernetes secrets, or plain files. Mix several on one server.
-
Full audit trail
Every run writes a log per server plus a machine-readable
summary.json. Backups on the server share the run's ID.
How it looks¶
$ sslsync deploy --group staging
[web-staging] ✓ connect web-staging | Ubuntu 24.04 LTS
[web-staging] ✓ sudo ok
[web-staging] ✓ health 3 check(s) passed
[web-staging] ~ /etc/ssl/certs/site.crt will be replaced (root:root 644, fullchain)
[web-staging] ~ /etc/ssl/private/site.key will be replaced (root:root 600, key)
[web-staging] ✓ upload 2 file(s) staged, sha256 verified
[web-staging] ✓ replace 2 replaced, 0 created
[web-staging] ✓ reload NGINX
[web-staging] ✓ web.example.com:443 serves the NEW certificate (expires 2027-02-12)
[web-staging] ● updated
Where to go next¶
| I want to… | Read |
|---|---|
| understand certificates first | What is an SSL certificate? |
| install it | Installation |
| use it for the first time | Quick start |
| renew a certificate | Tutorial: renew a certificate |
| add a server | Tutorial: add a server |
| look up a setting | Configuration reference |
| fix an error | Troubleshooting |