Skip to content

How it works

Each server is processed independently, in parallel (default 4 at a time), in these phases:

# Phase Changes the server? On failure
1 connect: SSH login, host key verified no stop; server untouched
2 sudo: sudo works with the configured password no stop; server untouched
3 health: each target's health checks (service running, config valid) no stop; server untouched
4 files: each destination exists and is writable; shows owner, mode, and whether it is already the new cert no stop; server untouched
5 state: Kubernetes secrets already contain the new cert? no stop; server untouched
6 tls: what every VERIFY port serves now (information only) no —
sslsync check ends here
7 upload: files go to a private temp dir (umask 077), sha256 verified /tmp only stop; temp dir removed
8 replace: back up to <file>.bak-<stamp>, overwrite in place so owner and mode are kept, sha256 verified yes rollback
9 reload: each changed target's reload (e.g. nginx -t && systemctl reload nginx, k8s secret update + rollout) yes rollback
10 health: the same checks again no rollback
11 verify: every VERIFY port must serve the new cert (retries for about 30 s) no rollback

Rollback restores every backed-up file and removes files it created. It then runs each reloaded target's rollback, so services load the old certificate again. For Kubernetes, that means re-applying the secrets saved before the update and restarting. A failure during rollback is reported as ROLLBACK-FAILED with the backup names, so you can finish it by hand.

Idempotent: a server whose files, secrets and ports already have the new certificate is reported as up-to-date and left alone. Re-running after a partial failure only does what is still missing.

Statuses

Status Meaning
ready check: healthy and ready for the new certificate
up-to-date already has the new certificate everywhere; nothing done
updated deploy succeeded and was verified
planned plan (dry run)
check-failed a check failed; nothing was changed
rolled-back failed after changes; old certificate restored
ROLLBACK-FAILED failed and the rollback was incomplete; act now (see troubleshooting)