> I just got so sick of the constant pain of certificates.
I've honestly never had any sort of "constant pain" by using nginx and acme.sh. Certbot is an actual abomination.
I have a script just as a shortcut for these two commands:
acme.sh --issue --dns dns_cf -d "$1" -d "*.$1"
acme.sh --installcert -d "$1" -d "*.$1" --certpath /foo/$1/cert --keypath /foo/$1/key --fullchainpath /foo/$1/fullchain --reloadcmd "/usr/local/bin/docker-compose -f /foo/docker-compose.yml exec -T nginx nginx -s reload"
You just have to run those commands once per domain and it'll keep that wildcard certificate valid forever, acme.sh sets up a cronjob to renew the cert when needed and will automatically reload my nginx container after.