Automatic HTTPS removes most certificate work, but a deployment can still carry a latent renewal failure for weeks: DNS credentials may have changed, a challenge port may be blocked, the storage location may no longer be writable, or a cluster member may not share certificate state as expected. Waiting for the normal renewal window makes the first realistic test time-sensitive.
What is a safe rehearsal that does not disturb the production certificate or hit CA rate limits? I am considering a separate test hostname, the staging ACME endpoint, the same DNS or HTTP challenge path and credentials, an isolated Caddy storage directory, and checks that confirm issuance, persistence, reload, and access from every serving node. Monitoring would alert on remaining lifetime and the last successful automation event rather than only on expiry.
Does that exercise enough of the production path, or is there a supported way to force a renewal dry run against the existing configuration? Which parts of the rehearsal commonly give false confidence?
Source: r/caddyserver · by /u/RocketSeven