
Letting Caddy Own the Certificates
Certbot on a timer, a deploy hook, and a Discord webhook whose only job was to tell me when the other two broke quietly. Caddy does that work itself, so I moved the front door and deleted the rest.

Certbot on a timer, a deploy hook, and a Discord webhook whose only job was to tell me when the other two broke quietly. Caddy does that work itself, so I moved the front door and deleted the rest.

Nine self-hosted services, nine login forms, nine passwords in my manager under slightly different names. So I put an identity provider in front of all of them on a thin client, and published it to every interface on the box without noticing.

The renewal notice is what did it. Three hundred dollars a year for Ghost(Pro) to host forty posts, with a members list four rows long and one of them me. What I actually use it for is a static site. So I moved it, and not one URL changed.

Two firewall changes in one maintenance window. By morning one box pings the gateway, cannot reach the Plex VM, and looks perfectly healthy in UniFi. Routing is fine. It is working from a cache written before I moved the network underneath it.

Flipping msDS-SupportedEncryptionTypes is one line. I have never once been nervous about the line. I am nervous about the call two days later: a nightly job stopped, and nobody can say why. The attribute is trivial. The blast radius is not.

A utility script died on a fresh Windows 11 box. wmic bios get serialnumber, gone, and the DISM command that puts it back stops working this month. The one-liners map onto Get-CimInstance cleanly. The for /f blocks wrapped around them do not.

A report-only CA policy, and one question: if I enable it, who stops being able to work? What If gave me thirteen rows and no answer. So I wrote a PowerShell module that folds them into one.

A service’s cert I don’t use much had expired. Turns out certbot had been failing twice a day for months and nothing said a word. Port 80 is blocked on my home line, so HTTP-01 was never an option. Wrote up the fix, and hand rolled some alerting.

Pester 6.1 shipped, so I checked my Copilot standards against an install instead of the release notes. Four claims no longer held. Two aren’t in the announcement at all, and one example from the release notes doesn’t actually run.

Windows OpenSSH ships everything except ssh-copy-id. VS Code Remote-SSH kept asking for my password, and the documented fix is macOS/Linux only. So I built one: platform detection, idempotent installs, real verification.