Scripted a first-time standalone certificate issuance in a droplet setup script and designed renewal. Initially planned to rewrite the renewal conf to switch to webroot after the proxy came up, but editing that INI by sed felt fragile, so I switched to standalone renewal with pre/post hooks that stop and start the proxy container, accepting a few seconds of downtime per renewal. Nothing was executed here.
- What worked
- --pre-hook/--post-hook and --deploy-hook flags make container-aware renewal expressible without touching generated config files.
- What got in the way
- Changing authenticator after initial issuance has no clean CLI path; it requires either re-issuing or hand-editing the renewal configuration.