TLS that fails safe. Observability that’s already on.
Each instance bundles its own certbot — nothing shared between customers — and ships with real health monitoring and distributed-tracing export already wired in, not left as homework.
WarmHawk issues its own TLS certificate via certbot at install time and degrades to HTTP-only rather than crashing if issuance fails; a renewal loop keeps it current automatically. On Tier 1/2, bundled Uptime Kuma watches every service’s health check by default, and native OTEL export is wired in but inert until you point it at a backend you run.
What happens when cert issuance fails
install.sh brings nginx up HTTP-only first, then runs certbot certonly --webroot against your domain. If that fails — almost always because DNS doesn’t point at this server yet — the installer does not tear anything down. Your instance stays reachable over HTTP, and it prints the recovery command instead of exiting with a stack-wide failure:
API details (Tier 0 / self-hosters) · Retry just the TLS step once DNS resolves▸
dig +short app.yourcompany.com # confirm it now points at this server
./scripts/install.sh --retry-tlsThis re-runs only the certbot request and the nginx reload — it doesn’t regenerate secrets, touch your database, or re-prompt for anything you already answered.
BYO-cert
Already manage your own certificate (an internal CA, an existing wildcard)? Skip certbot entirely at install time:
API details (Tier 0 / self-hosters) · Install with your own certificate▸
./scripts/install.sh --domain app.yourcompany.com \
--skip-certbot --cert-path /path/to/fullchain.pem --key-path /path/to/privkey.pemIn this mode you own renewal too — the bundled renewal loop only manages certificates it issued itself via certbot.
Automatic renewal, and verifying it
The certbot service runs a renewal loop — certbot renew every 12 hours — which only actually renews once a certificate is inside its window (Let’s Encrypt certs are valid 90 days). Worth verifying rather than assuming:
API details (Tier 0 / self-hosters) · Confirm the renewal loop is running, and the cert's real expiry▸
docker compose ps certbot
echo | openssl s_client -connect app.yourcompany.com:443 -servername app.yourcompany.com 2>/dev/null \
| openssl x509 -noout -datesObservability: on by default, not homework
Every WarmHawk instance on Tier 1/2 bundles two observability pieces at no extra cost, both running on the same internal-only network as everything else:
- Uptime Kuma, pre-pointed at every service’s Docker health check the moment the stack comes up — no manual monitor setup required. It has no published port of its own; reach it through your own reverse-proxy rule or an SSH tunnel if you want the dashboard.
- Native OTEL export — both
apiandworkerare wired withOTEL_SERVICE_NAMEand readOTEL_EXPORTER_OTLP_ENDPOINTfrom your environment. Unset, it’s inert — nothing is exported anywhere, and no third-party telemetry backend is bundled or required. Point it at a backend you already run or subscribe to (Grafana Tempo, Honeycomb, anything OTLP-compatible) to get real traces:
API details (Tier 0 / self-hosters) · .env — enable OTEL export▸
OTEL_EXPORTER_OTLP_ENDPOINT=https://your-otel-collector.example.com:4318Neither piece phones home to WarmHawk — both are entirely yours to view, configure, or point elsewhere.
License activation or a lapsed subscription showing an unrelated error alongside a TLS problem? That’s a separate system — see license activation troubleshooting.
Questions
TLS & observability: questions worth answering up front
Does a failed certificate issuance take down the instance?+
No. If certbot can’t issue a certificate — usually because DNS hasn’t propagated yet — nginx stays up serving plain HTTP instead of crashing the stack. You get a working, reachable instance immediately and TLS once you fix the underlying cause.
Is Uptime Kuma something I have to set up myself?+
No — it ships bundled and pre-pointed at every service’s health check by default on Tier 1/2, at no extra cost. It runs on the same internal-only network as everything else; reach it through your own reverse-proxy path or SSH tunnel if you want to view it.
Do I need a specific observability backend for OTEL to be useful?+
No — OTEL export is native and free, but inert until you point OTEL_EXPORTER_OTLP_ENDPOINT at a backend you run or subscribe to (Grafana Tempo, Honeycomb, whatever you already use). WarmHawk doesn’t operate an observability backend for you.
Can I use a certificate I already manage myself instead of certbot?+
Yes — pass --skip-certbot with --cert-path and --key-path and installation skips the certbot step entirely, configuring nginx with the certificate and key you provide. You own renewal in that mode; the bundled renewal loop only manages certificates it issued itself.