← Integrations

Automated SSL certificate renewal for PM2 and Node.js

Node reads its certificate once. CertKit makes sure it reads the new one.

A Node.js HTTPS server loads its certificate and key from disk when it starts and never looks again. Writing a renewed certificate to the same path changes nothing until PM2 reloads the app. Every 47 days.

CertKit issues and renews the certificate centrally, then the CertKit Agent writes the PEM files where your app reads them and runs pm2 reload.

Start free trial Watch demo

Built for PM2

The pre-built PM2 template ships in your CertKit account. No scripting required.

On every renewal, the agent writes the certificate with its intermediate chain and the private key to the paths you choose, then runs pm2 reload all. Cluster-mode apps reload one process at a time. Fork-mode apps restart.

Reload everything or one app, as root or as the account that runs your apps.

How to add an SSL certificate to a Node.js app running under PM2

The manual process, if you want to do it yourself:

  1. Get the certificate and key as PEM. Include the intermediate chain in the certificate file, or some clients fail to verify it.
  2. Put them where the app reads them. The paths passed to https.createServer(), readable by the account that runs the app.
  3. Reload the app. Run pm2 reload all, or pm2 reload my-app, as the user who started it. PM2 keeps a separate process list per user.
  4. Confirm it took. Check pm2 list for the restart, then check the served expiry date.
  5. Repeat on every server. Each host running the app needs its own files and its own reload.

Every one of these steps is manual, and PM2 won't repeat any of them when the certificate renews. With lifetimes shrinking to 47 days, that's twelve times a year, on every server running the app. Miss one and clients start failing with "certificate has expired" errors.

At 47 days, automation is the only sustainable way to run PM2 certificates. Here's how CertKit does it.

How it works

 Your Node.js server       CertKit                 ACME CA
┌───────────────────┐     ┌──────────────────┐    ┌─────────────┐
│                   │     │                  │    │             │
│     ┌───────────────┐   │  Issue & Renew   │◄──►│             │
│     │ CertKit Agent │◄──┤   Certificates   │    │             │
│     └─────────┬─┬───┘   │                ┌───┐  └─────────────┘
│               │ │ │     └───────────┬────│DNS│
│ PEM files   ◄─┘ │ │                 │    └───┘
│ [x] Written     │ │                 │
│                 │ │                 │
│ pm2 reload    ◄─┘ │ ◄───────────────┘
│ [x] Reloaded      │       Verify
└───────────────────┘

CertKit issues and renews certificates centrally using delegated DNS validation. You create a one-time CNAME record, and CertKit handles every ACME challenge after that.

The agent on each server pulls renewals over outbound HTTPS and works locally. Your app never runs ACME and never holds DNS credentials.

The whole process was extremely easy, it's a great product.

Adam Carson, Senior Manager, Drug ARM

What CertKit handles

Setup takes about ten minutes

  1. Connect your domain. Add a one-time CNAME record to delegate DNS validation to CertKit.
  2. Install the CertKit Agent. One command on each Linux server running the app.
  3. Add the PM2 deployment script. Set the certificate and key paths to the files your app loads.
  4. Pick the user. If your apps run under an account other than root, switch to advanced mode and reload as that user.

See the full architecture →

PM2 deployment requirements and troubleshooting →

Why pm2 reload from a script often does nothing

PM2 finds its daemon through a socket in the home directory of the user who started it. A renewal hook running from cron or a service has no normal home directory, so pm2 reload all starts a new, empty daemon, finds nothing to reload, and exits cleanly. The certificate on disk is new and the one being served is old.

CertKit's template sets the home directory before it calls PM2, and checks the served certificate afterward.

PM2 is just one part of your stack

Most infrastructures have more than one place where certificates live: nginx or Apache in front of Node, Kubernetes for containerized services, and search clusters like Elasticsearch. CertKit automates all of it from one account.

See all integrations

Start automating PM2 certificates today

Free 90-day trial. No credit card required. Direct access to our engineering team to get you set up.

Start free trial See pricing