Skip to content

Comment on Ask HN: Do you use Nginx in production? or have you switchedparent

Comments

Interesting, what do you for SSL instead?

I use acme.sh with DNS challenges on an external machine. Then I push up (rsync) the certs and reload Nginx.

Here’s a blog post https://blog.uxtly.com/isolated-tls-certificate-creation

Thanks eFortis? I guess this mainly for security and separation of concerns?

Yes, the certificate renewal and the server are more hardened this way.

Cool! Do you do other things to hardend the servers like Knockerd?

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.