issue_cert
Obtain a Let's Encrypt SSL certificate for an existing nginx site, enabling HTTPS and HTTP-to-HTTPS redirect. Uses staging by default; set staging:false for production certificates.
Instructions
Request a certificate via certbot --nginx (HTTP-01 validation). Requires an nginx server block for domain to already exist (create_site) - certbot's nginx plugin edits that existing sites-available config in place, adding an SSL server block and an HTTP->HTTPS redirect; it does not create a new site from scratch, and it reloads nginx itself on success (no separate reload_nginx call needed). Pre-checks that the domain resolves and fails fast with guidance if not, avoiding a wasted attempt against Let's Encrypt's rate limits. Defaults to Let's Encrypt staging, which issues browser-untrusted certs but is exempt from rate limits - pass staging:false only when you're ready for a real, publicly CT-logged certificate: production Let's Encrypt enforces real per-domain issuance rate limits (a handful of certs per week), and a mis-issued cert isn't silently undone - call revoke_cert if you need to invalidate one. A local guard also refuses production requests that would exceed Let's Encrypt's duplicate-certificate, failed-validation or per-domain limits, reporting when to retry. For a *.domain wildcard, use issue_wildcard_cert instead - HTTP-01 can't validate wildcards.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| No | Contact email registered with the Let's Encrypt account, used for renewal-failure and expiry notices. Omitted registers with --register-unsafely-without-email, so Let's Encrypt cannot warn you if a future automated renewal fails. | ||
| domain | Yes | Domain to request a certificate for. Must already resolve (see check_dns) and already have an nginx server block from create_site - certbot edits that existing config rather than creating one. | |
| staging | No | True (default) uses Let's Encrypt's staging CA - browser-untrusted certs, but exempt from production rate limits; use for testing the flow. False requests a real, browser-trusted cert and counts against production rate limits. |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| success | Yes | ||
| dns_check | No | Present only when the DNS pre-check failed, before certbot was even invoked | |
| certbot_output | Yes | Raw combined stdout/stderr from the certbot CLI invocation, on success or failure | |
| rate_limit_note | No | Set when the local rate-limit guard refused a production request (with when to retry), or when a Let's Encrypt production limit is close |