Proven live, closing a months-old silent fault: Traefik's own ACME machinery owns /.well-known/acme-challenge on :80 outright (unknown tokens get its 404) and its entrypoint redirect owns every other path — the hand-authored passthrough never matched anything, which is why mailu's certbot state quietly expired in April while copied cert files carried the name (a real user hit the expired cert on IMAPS tonight when letsencrypt flavor served the stale state).
cert flavor serves the copied files (valid to Nov 27). Mailu certifying itself becomes possible the day route-proxy takes port 80 — its handler falls through unknown challenge tokens by design — and that flip is one line here, made then. Before Nov 27 either that cutover lands or the cert files need one manual refresh from Traefik's acme.json.
Proven live, closing a months-old silent fault: Traefik's own ACME machinery owns `/.well-known/acme-challenge` on :80 outright (unknown tokens get *its* 404) and its entrypoint redirect owns every other path — the hand-authored passthrough **never matched anything**, which is why mailu's certbot state quietly expired in April while copied cert files carried the name (a real user hit the expired cert on IMAPS tonight when `letsencrypt` flavor served the stale state).
`cert` flavor serves the copied files (valid to Nov 27). Mailu certifying itself becomes possible the day route-proxy takes port 80 — its handler falls through unknown challenge tokens by design — and that flip is one line here, made then. Before Nov 27 either that cutover lands or the cert files need one manual refresh from Traefik's acme.json.
letsencrypt was the aspiration and cannot work yet, proven live: the
predecessor's own ACME machinery owns /.well-known/acme-challenge on
port 80 outright (unknown tokens get its 404) and its entrypoint
redirect owns every other path — the hand-authored passthrough never
matched anything, which is why mailu's certbot state had quietly
expired in April while the copied files carried the name. cert flavor
serves those files (valid to Nov 27). Mailu certifying itself becomes
possible the day route-proxy takes port 80, whose handler falls through
unknown tokens by design — that flip is one line here, made then.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Proven live, closing a months-old silent fault: Traefik's own ACME machinery owns
/.well-known/acme-challengeon :80 outright (unknown tokens get its 404) and its entrypoint redirect owns every other path — the hand-authored passthrough never matched anything, which is why mailu's certbot state quietly expired in April while copied cert files carried the name (a real user hit the expired cert on IMAPS tonight whenletsencryptflavor served the stale state).certflavor serves the copied files (valid to Nov 27). Mailu certifying itself becomes possible the day route-proxy takes port 80 — its handler falls through unknown challenge tokens by design — and that flip is one line here, made then. Before Nov 27 either that cutover lands or the cert files need one manual refresh from Traefik's acme.json.