WarmHawk
Docs / Self-hosting / TLS & observability

TLS that fails safe. Observability that’s already on.

Each instance bundles its own certbot — nothing shared between customers — and ships with real health monitoring and distributed-tracing export already wired in, not left as homework.

WarmHawk issues its own TLS certificate via certbot at install time and degrades to HTTP-only rather than crashing if issuance fails; a renewal loop keeps it current automatically. On Tier 1/2, bundled Uptime Kuma watches every service’s health check by default, and native OTEL export is wired in but inert until you point it at a backend you run.

What happens when cert issuance fails

install.sh brings nginx up HTTP-only first, then runs certbot certonly --webroot against your domain. If that fails — almost always because DNS doesn’t point at this server yet — the installer does not tear anything down. Your instance stays reachable over HTTP, and it prints the recovery command instead of exiting with a stack-wide failure:

API details (Tier 0 / self-hosters) · Retry just the TLS step once DNS resolves▸
dig +short app.yourcompany.com   # confirm it now points at this server
./scripts/install.sh --retry-tls

This re-runs only the certbot request and the nginx reload — it doesn’t regenerate secrets, touch your database, or re-prompt for anything you already answered.

BYO-cert

Already manage your own certificate (an internal CA, an existing wildcard)? Skip certbot entirely at install time:

API details (Tier 0 / self-hosters) · Install with your own certificate▸
./scripts/install.sh --domain app.yourcompany.com \
  --skip-certbot --cert-path /path/to/fullchain.pem --key-path /path/to/privkey.pem

In this mode you own renewal too — the bundled renewal loop only manages certificates it issued itself via certbot.

Automatic renewal, and verifying it

The certbot service runs a renewal loop — certbot renew every 12 hours — which only actually renews once a certificate is inside its window (Let’s Encrypt certs are valid 90 days). Worth verifying rather than assuming:

API details (Tier 0 / self-hosters) · Confirm the renewal loop is running, and the cert's real expiry▸
docker compose ps certbot
echo | openssl s_client -connect app.yourcompany.com:443 -servername app.yourcompany.com 2>/dev/null \
  | openssl x509 -noout -dates

Observability: on by default, not homework

Every WarmHawk instance on Tier 1/2 bundles two observability pieces at no extra cost, both running on the same internal-only network as everything else:

  • Uptime Kuma, pre-pointed at every service’s Docker health check the moment the stack comes up — no manual monitor setup required. It has no published port of its own; reach it through your own reverse-proxy rule or an SSH tunnel if you want the dashboard.
  • Native OTEL export — both api and worker are wired with OTEL_SERVICE_NAME and read OTEL_EXPORTER_OTLP_ENDPOINT from your environment. Unset, it’s inert — nothing is exported anywhere, and no third-party telemetry backend is bundled or required. Point it at a backend you already run or subscribe to (Grafana Tempo, Honeycomb, anything OTLP-compatible) to get real traces:
API details (Tier 0 / self-hosters) · .env — enable OTEL export▸
OTEL_EXPORTER_OTLP_ENDPOINT=https://your-otel-collector.example.com:4318

Neither piece phones home to WarmHawk — both are entirely yours to view, configure, or point elsewhere.

License activation or a lapsed subscription showing an unrelated error alongside a TLS problem? That’s a separate system — see license activation troubleshooting.

Questions

TLS & observability: questions worth answering up front

Does a failed certificate issuance take down the instance?+

No. If certbot can’t issue a certificate — usually because DNS hasn’t propagated yet — nginx stays up serving plain HTTP instead of crashing the stack. You get a working, reachable instance immediately and TLS once you fix the underlying cause.

Is Uptime Kuma something I have to set up myself?+

No — it ships bundled and pre-pointed at every service’s health check by default on Tier 1/2, at no extra cost. It runs on the same internal-only network as everything else; reach it through your own reverse-proxy path or SSH tunnel if you want to view it.

Do I need a specific observability backend for OTEL to be useful?+

No — OTEL export is native and free, but inert until you point OTEL_EXPORTER_OTLP_ENDPOINT at a backend you run or subscribe to (Grafana Tempo, Honeycomb, whatever you already use). WarmHawk doesn’t operate an observability backend for you.

Can I use a certificate I already manage myself instead of certbot?+

Yes — pass --skip-certbot with --cert-path and --key-path and installation skips the certbot step entirely, configuring nginx with the certificate and key you provide. You own renewal in that mode; the bundled renewal loop only manages certificates it issued itself.