Skip to content

Certificates

Certificates are TLS certificates your customers manage at the account level, independent of any single load balancer. A customer uploads a certificate (or issues one from Let’s Encrypt) once, then attaches it to as many load balancer listeners as they like. Uploading, issuing, and deleting are self-service; the admin panel provides oversight.

Open a customer under Customers > Users. The Certificates tab lists every certificate the account owns, including Kubernetes-managed ones.

Column Meaning
Name The customer’s label.
ID A stable UUID, copyable with one click. Use it in automation (OpenTofu, MCP).
Domains The primary domain plus a SAN count.
Type Let’s Encrypt or Uploaded.
Status Issuance state, for example Active, Pending DNS, Issuing, Failed, Renewal Pending.
Expires Time until expiry.
Used by The load balancer listeners referencing the certificate.
Fingerprint A SHA-256 hash, used to detect duplicate uploads.

The tab is read-only. You cannot upload or delete certificates on a customer’s behalf; that stays a self-service action for the account owner.

Certificates tab on a customer’s detail page

  • Upload validation. The private key must match the certificate. A supplied CA chain must parse and actually sign the leaf. Expired certificates are rejected outright. The panel reads the domain, SAN list, and expiry date out of the certificate itself.
  • Quota. Each account has a certificate quota, 20 by default. Raise it, lower it, or set it to 0 for unlimited from the account’s Resource Limits on its Cloud Service tab; see Manage users.
  • Let’s Encrypt. Issued through a load balancer the customer picks, which answers the HTTP-01 challenge on its public IP. The domain must resolve to that IP. Certificates are valid 90 days and renew automatically from 30 days before expiry, through the same load balancer. If that load balancer is deleted, renewal is blocked until the customer re-issues through one that exists.
  • SNI. A listener holds an ordered list of certificates. The first is the default served to clients that send no server name; the rest are served by SNI, so one port can serve several unrelated domains.
  • In-use protection. A certificate referenced by a listener cannot be deleted. The error lists the load balancers and ports using it.
  • Kubernetes-managed. Certificates minted by the Kubernetes load balancer bridge appear in the store tagged as managed and are read-only for the customer.
  • Expiry alerts. An uploaded certificate approaching expiry sends an email to the account owner, and monitoring supports certificate alert rules. Let’s Encrypt certificates renew themselves and skip the reminder.

Customers manage the full workflow (upload, Let’s Encrypt requests, attaching to listeners, deletion) from the user panel. See Certificates (user guide).