Stringify AI VM (31.97.203.241) · July 2026 · Manish Singh
Every site we host needs a security certificate (the browser padlock). We get ours free from Let's Encrypt, a non-profit certificate authority trusted by all browsers. The entire issue-and-renew cycle is automated by Traefik, the traffic router that sits at the front of our server and handles all incoming requests.
site-abc123.sites.swiftornis.cloud), marked "secure this with Let's Encrypt."Let's Encrypt certificates last 90 days. Traefik automatically renews each one about 30 days before expiry using the same verification steps. No cron job, no reminders, no human involved. If renewal ever fails repeatedly, Let's Encrypt emails a warning to our contact address before anything expires.
| Certificates currently held | 66 (one per hosted site or app domain) |
| Cost | $0 — Let's Encrypt is free |
| Certificate lifetime | 90 days, auto-renewed ~30 days early |
| Verification method | HTTP challenge over port 80 |
| Contact for expiry warnings | manish@stringifyai.com |
| Manual work required | None |
One certificate per site, not one wildcard. A wildcard covering all *.sites addresses would need a more complex DNS-based verification. The per-site approach needs no extra credentials, and Let's Encrypt's rate limits give us plenty of headroom at our scale.
Everything on the server uses the same mechanism. Our main products (deployer, Woodle, CMS, websites) get certificates the same way — same Traefik, same Let's Encrypt account, same storage. One system to understand and monitor.
Free certificates from Let's Encrypt, requested and renewed automatically by the traffic router already fronting all our apps — zero cost, zero manual maintenance, HTTPS within a minute of every deploy.