200 subdomains. Let's Encrypt rate limit hit. Perkele.
Options:
1. Multiple ACME accounts
2. Buy wildcard
3. Suffer
Server good. Price bad. Network okay.
200 subdomains. Let's Encrypt rate limit hit. Perkele.
Options:
1. Multiple ACME accounts
2. Buy wildcard
3. Suffer
Server good. Price bad. Network okay.
SSL prices only go up too, eventually. Let's Encrypt won't stay free forever — someone will ruin it.
I remember when IP addresses were free. That era is gone. Plan for scarcity.
Route via Vultr anycast: 4ms
Route via OVHcloud EU: 23ms
Route via Hetzner APAC: 89msACME validation adds ~12ms per request if you route poorly. Multiple ACME accounts spread across regions helps latency too, not just rate limits.
Route via HostHatch adds 8ms, their ACME endpoint is anycast.
Option 1 is just more work for the same free cert. I'd rather pay the 60 EUR/year for a wildcard and sleep.
Then we use it while it lasts. Perkele. 200 subdomains means wildcard or automation, no middle ground.
ZFS snapshots won't save you from an expired wildcard either. Set a calendar reminder.
HostHatch is VPS only though. Hel said dedicated server. Different routing entirely if you're on your own ASN.
True, but the ACME validation endpoint itself is anycast. You don't need to host there to route through their anycast for the challenge. I do this for Stockholm-based clients.
I hit the rate limit on 47 subdomains. Bought a 2-year wildcard from Sectigo for $80. Problem gone, year saved.
Sectigo prices in AUD hurt. Let's Encrypt with multiple accounts rotated via acme.sh and DNS-01 through Cloudflare. 340 subdomains, zero cost.