Many thanks for your time and help.
Many thanks for your time and help.
- if renewal did work, the certs HAProxy is reading are never replaced.
Really, there are already good tutorials for HAProxy and certbot out there, why muddy the water with another, broken attempt at one?
If you are setting this up in a test environment and are writing it up as you go, I recommend having screen recording/shell logging so you can afterwards check exactly what you did and write it down (at least that has helped me in the past). If you don't, then you really should do a test run and verify what you do works. Writing up something you did a while ago without replicating it makes it really easy to miss crucial steps.
I.. Um. It's different now but I'm pretty sure certs still won't renew, and if they did haproxy wouldn't know about them.
I'm not sure what your motivation is for posting this article but honestly you need a better understanding before trying to give other people technical advice about something.
Edit: also the weirdness persists. Why are you allowing inbound dns requests. Why is your firewall blocking first instead of last. Why are you using sudo for curl that gets piped. Jesus why are you curl|bash at all. I'm pretty sure your cron job is unnecessary and won't even work.
<breathe>... There is still a lot wrong with this but I can't type easily so that will have to do for now