Troubleshooting¶
| Message | Fix |
|---|---|
.env is readable by other users |
chmod 600 .env |
unknown host key |
sslsync trust --only <server> |
HOST KEY CHANGED |
Confirm with the server owner that it was reinstalled, then ssh-keygen -R <host> and sslsync trust. Never skip this. |
authentication failed |
check _USER/_PASSWORD; try ssh user@host by hand |
sudo password incorrect |
set _SUDO_PASSWORD if it differs from the login password |
does not exist — check the path |
compare with sslsync find user@host; for a new location set _<TARGET>_CREATE=true |
still serves the old certificate |
the reload did not make the service pick up the file. Is VERIFY pointing at the right service? Is there a load balancer in front? Check the per-port table of sslsync find |
certificate … does not cover <host> |
the VERIFY host is outside the SAN, e.g. a.b.example.com vs *.example.com |
health: … failed before deploy |
the service was already broken; fix it first. Deploying would hide the cause |
ROLLBACK-FAILED¶
The message lists what could not be restored. On that server:
ls /path/to/*.bak-<stamp> # stamp is in the message and the log folder name
sudo cp -p /path/file.bak-<stamp> /path/file
sudo systemctl reload nginx # or the target's reload
# Kubernetes:
ls /root/ssl-secret-backup/<stamp>/
sudo kubectl apply -f <file> # after removing resourceVersion/uid lines
Then run sslsync status --only <server>.