SingaporeRep
Member
Benchmark Addict
- Joined:
- Jul 2024
- Posts:
- 227
- From:
- Singapore, SG
$ systemd-analyze timer
NEXT LEFT LAST PASSED UNIT
Thu 2026-08-21 03:00:00 CEST 4h 12min Wed 2026-08-20 03:00:13 CEST 19h ago certbot.timer
$ ps aux | grep certbot
root 1847 0.0 1.2 45212 8924 ? S 03:00 0:00 certbot renew
root 1852 0.0 1.2 45212 8912 ? S 03:00 0:00 certbot renew
Decent disk IO, meh network
Race confirmed. Two PIDs same second.
$ timedatectl status
Local time: Thu 2026-08-21 22:47:33 CEST
Universal time: Thu 2026-08-21 20:47:33 UTC
RTC time: Thu 2026-08-21 20:43:33
Time zone: Europe/Berlin (CEST, +0200)
RTC 4 min slow. Host clock drift.
fio, iperf, geekbench. results or gtfo.
haroldgsm
Member
Grumpy Old Sysadmin
- Joined:
- May 2024
- Posts:
- 329
- From:
- Ohio, US
Cron should not fire twice.
Cron doesn't. Something else does.
You said systemd timers are disabled, but is certbot.timer masked or just stopped? On Debian bookworm, installing certbot from snap or apt sometimes drops both a cron job AND a systemd timer. They fight.
systemctl list-timers --all | grep certbot
systemctl status certbot.timer
I have seen this exact failure mode on Linode and Vultr both. Two triggers, same binary, race to the lock file.
IPv4, IRC, and irssi — fight me
SingaporeRep
Member
Benchmark Addict
- Joined:
- Jul 2024
- Posts:
- 227
- From:
- Singapore, SG
Classic. I have done worse.
The day 89 thing is LE's renewal window. Certbot starts trying 30 days before expiry, but your cron logs show it only actually executes the full renewal path when within 10 days. The 429 from staging on day 89 suggests it is hitting the failed auth limit because the first attempt partially succeeds, second attempt confuses LE, both get throttled.
Staging and prod share rate limits per IP range on some endpoints. OVH's Singapore routing goes through the same anycast nodes.
fio, iperf, geekbench. results or gtfo.