Recommendations for LetsEncrypt certificate management across multiple TrueNAS Scale installs

What is the recommended way to manage certs for multiple TrueNAS instances?

What I mean is, is there a way to centralize how TrueNAS scale issues CSRs and obtains certs across a cluster of some type?

I am trying to avoid adding my CloudFlare API key to all of the instances: as if an instance is compromised, then the API key is at risk - and I have no way to block it without replacing it on all the other truenas instances (not to mention the headache of figuring out which truenas instance went rogue on issuing the wrong certs, etc).

Have you considered using API tokens instead of the key?
I believe that is the recommended approach.

1 Like

Ah, I must be old school and didn’t realize there were these tokens now.

I’ll look into it. Thanks!