issue_wildcard_cert
Issue a wildcard SSL/TLS certificate for a domain and all subdomains via Certbot DNS-01 Route 53 validation, defaulting to staging to avoid Let's Encrypt rate limits.
Instructions
Request a wildcard certificate (domain and *.domain) via certbot --dns-route53 (DNS-01 validation, required since HTTP-01 can't prove ownership of a wildcard). Requires the certbot-dns-route53 plugin installed on the box and AWS credentials in the environment (see README) - fails fast with guidance if credentials are missing. Defaults to staging; a local guard refuses production requests that would exceed Let's Encrypt's rate limits, reporting when to retry. For a single non-wildcard domain, use issue_cert instead.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| No | Contact email for the Let's Encrypt account; omitted registers unsafely-without-email | ||
| domain | Yes | Base domain, e.g. julcap.net - issues it plus *.julcap.net | |
| staging | No | True (default) uses Let's Encrypt's staging CA: untrusted certs, but no rate-limit risk |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| success | Yes | ||
| certbot_output | Yes | ||
| rate_limit_note | No | Set when the local rate-limit guard refused a production request (with when to retry), or when a Let's Encrypt production limit is close |