How our sites get HTTPS automatically

Stringify AI VM (31.97.203.241) · July 2026 · Manish Singh

The short version

Every site we host needs a security certificate (the browser padlock). We get ours free from Let's Encrypt, a non-profit certificate authority trusted by all browsers. The entire issue-and-renew cycle is automated by Traefik, the traffic router that sits at the front of our server and handles all incoming requests.

What happens when a new site goes live

  1. A site is deployed. Our deployer app saves the files and adds a routing rule for the new address (e.g. site-abc123.sites.swiftornis.cloud), marked "secure this with Let's Encrypt."
  2. Traefik notices within seconds. It watches the routing config folder — no restart needed, no downtime for other sites.
  3. Traefik requests a certificate from Let's Encrypt for the new address.
  4. Let's Encrypt verifies ownership. It says "put this token at this URL" and then visits the address over plain HTTP (port 80). Since our DNS points that address at our server, Traefik answers the challenge and the check passes.
  5. Certificate issued and stored. Traefik saves it in one storage file on the server and starts using it immediately. The site is live on HTTPS within about a minute.

Renewal

Let's Encrypt certificates last 90 days. Traefik automatically renews each one about 30 days before expiry using the same verification steps. No cron job, no reminders, no human involved. If renewal ever fails repeatedly, Let's Encrypt emails a warning to our contact address before anything expires.

Current numbers

Certificates currently held66 (one per hosted site or app domain)
Cost$0 — Let's Encrypt is free
Certificate lifetime90 days, auto-renewed ~30 days early
Verification methodHTTP challenge over port 80
Contact for expiry warningsmanish@stringifyai.com
Manual work requiredNone

Design choices worth knowing

One certificate per site, not one wildcard. A wildcard covering all *.sites addresses would need a more complex DNS-based verification. The per-site approach needs no extra credentials, and Let's Encrypt's rate limits give us plenty of headroom at our scale.

Everything on the server uses the same mechanism. Our main products (deployer, Woodle, CMS, websites) get certificates the same way — same Traefik, same Let's Encrypt account, same storage. One system to understand and monitor.

The one dependency to respect: the DNS entry for hosted-site addresses must point straight at our server (Cloudflare "DNS only", not "Proxied"). If that gets flipped, Let's Encrypt's ownership check can't reach us and new certificates and renewals start failing. Existing certificates keep working until they expire.

One-line summary

Free certificates from Let's Encrypt, requested and renewed automatically by the traffic router already fronting all our apps — zero cost, zero manual maintenance, HTTPS within a minute of every deploy.