Built for PM2
The pre-built PM2 template ships in your CertKit account. No scripting required.
A Node.js HTTPS server loads its certificate and key from disk when it starts and never looks again. Writing a renewed certificate to the same path changes nothing until PM2 reloads the app. Every 47 days.
CertKit issues and renews the certificate centrally, then the CertKit Agent writes the
PEM files where your app reads them and runs pm2 reload.
The pre-built PM2 template ships in your CertKit account. No scripting required.
On every renewal, the agent writes the certificate with its intermediate chain and the
private key to the paths you choose, then runs pm2 reload all. Cluster-mode
apps reload one process at a time. Fork-mode apps restart.
Reload everything or one app, as root or as the account that runs your apps.
The manual process, if you want to do it yourself:
https.createServer(), readable by the account that runs the app.
pm2 reload all, or pm2 reload my-app, as the user who started it. PM2 keeps a separate process list per user.
pm2 list for the restart, then check the served expiry date.
Every one of these steps is manual, and PM2 won't repeat any of them when the certificate renews. With lifetimes shrinking to 47 days, that's twelve times a year, on every server running the app. Miss one and clients start failing with "certificate has expired" errors.
At 47 days, automation is the only sustainable way to run PM2 certificates. Here's how CertKit does it.
Your Node.js server CertKit ACME CA ┌───────────────────┐ ┌──────────────────┐ ┌─────────────┐ │ │ │ │ │ │ │ ┌───────────────┐ │ Issue & Renew │◄──►│ │ │ │ CertKit Agent │◄──┤ Certificates │ │ │ │ └─────────┬─┬───┘ │ ┌───┐ └─────────────┘ │ │ │ │ └───────────┬────│DNS│ │ PEM files ◄─┘ │ │ │ └───┘ │ [x] Written │ │ │ │ │ │ │ │ pm2 reload ◄─┘ │ ◄───────────────┘ │ [x] Reloaded │ Verify └───────────────────┘
CertKit issues and renews certificates centrally using delegated DNS validation. You create a one-time CNAME record, and CertKit handles every ACME challenge after that.
The agent on each server pulls renewals over outbound HTTPS and works locally. Your app never runs ACME and never holds DNS credentials.
The whole process was extremely easy, it's a great product.
Adam Carson, Senior Manager, Drug ARM
pm2.
pm2 reload all by default, or name a single app.
PM2 finds its daemon through a socket in the home directory of the user who started it.
A renewal hook running from cron or a service has no normal home directory, so
pm2 reload all starts a new, empty daemon, finds nothing to reload, and exits
cleanly. The certificate on disk is new and the one being served is old.
CertKit's template sets the home directory before it calls PM2, and checks the served certificate afterward.
Most infrastructures have more than one place where certificates live: nginx or Apache in front of Node, Kubernetes for containerized services, and search clusters like Elasticsearch. CertKit automates all of it from one account.
Free 90-day trial. No credit card required. Direct access to our engineering team to get you set up.