SSL/TLS Lifecycle Management with ACME and Vault
SSL/TLS Lifecycle Management with ACME and Vault: High-Security Certificate Automation
Manually managing SSL/TLS certificates often leads to sudden expirations, causing service disruptions and serious security risks. In 2026, fully automating the SSL/TLS lifecycle using the ACME (Automatic Certificate Management Environment) protocol combined with HashiCorp Vault is the enterprise-standard solution. This article provides a detailed guide on how to implement automatic renewal, certificate rotation, and secure secret key storage without saving keys directly on the VPS hard drive.
1. Why Do You Need Professional SSL/TLS Management?
Expired SSL certificates can trigger "Not Secure" warnings in browsers, severely impacting SEO and user trust. Additionally, exposing private keys on a VPS creates major security risks.
- Main Risks: Forgetting renewal, key leaks, MITM attacks.
- Benefits of Automation: Zero-downtime renewal, secrets never touch disk, clear audit trail.
- Core Tools: ACME (Let’s Encrypt / ZeroSSL) + HashiCorp Vault.
// Interface for managing SSL/TLS Certificate Lifecycle
interface SSLCertificate {
domain: string;
issuer: "LetsEncrypt" | "ZeroSSL";
issuedAt: Date;
expiresAt: Date;
daysLeft: number;
status: "valid" | "expiring" | "expired";
keyId: string; // Vault secret reference
}
function checkCertificateHealth(cert: SSLCertificate): boolean {
const daysLeft = Math.ceil((cert.expiresAt.getTime() - Date.now()) / (1000 * 3600 * 24));
console.log(`[SSL Monitor] ${cert.domain} - ${daysLeft} days until expiry`);
if (daysLeft < 30) {
console.warn(`[ALERT] Certificate ${cert.domain} is expiring soon! Starting renewal.`);
return false;
}
return true;
}
2. ACME Protocol and Let’s Encrypt
ACME is the standard protocol that enables automatic certificate issuance and renewal from Let’s Encrypt. Certbot and acme.sh are the two most popular tools.
3. HashiCorp Vault - Secure Secrets Management
Vault allows you to store private keys, certificates, and tokens in encrypted form, accessible via API instead of saving files directly on the VPS.
// Vault Client Example (TypeScript)
import axios from 'axios';
interface VaultSecret {
data: {
certificate: string;
private_key: string;
ca_chain: string;
};
}
const vaultClient = axios.create({
baseURL: 'http://vault.internal:8200/v1/secret/data/ssl',
headers: { 'X-Vault-Token': process.env.VAULT_TOKEN }
});
async function storeCertificateInVault(domain: string, certData: any) {
await vaultClient.post(`/${domain}`, {
data: {
certificate: certData.cert,
private_key: certData.key,
issued_at: new Date().toISOString()
}
});
console.log(`[Vault] Certificate for ${domain} has been securely stored in Vault`);
}
async function retrieveCertificate(domain: string) {
const response = await vaultClient.get(`/${domain}`);
return response.data.data;
}
4. VPS Requirements and Recommended Architecture
| Factor | Recommendation |
|---|---|
| CPU / RAM | 2-4 cores, 4-8GB RAM |
| Storage | NVMe 50GB+ |
| Network | 1Gbps, Datacenter close to users |
| Architecture | Nginx + ACME + Vault Agent |
5. Implementing Automatic Renewal with ACME + Vault
Use cron jobs or systemd timers to automatically check and renew certificates.
// Automation Script - SSL Lifecycle Manager
async function renewSSLCertificate(domain: string) {
console.log(`[ACME] Starting renewal process for ${domain}`);
// Simulate certbot / acme.sh call
const certData = {
cert: "-----BEGIN CERTIFICATE-----...",
key: "-----BEGIN PRIVATE KEY-----...",
expiresAt: new Date(Date.now() + 90 * 24 * 60 * 60 * 1000)
};
// Store in Vault instead of filesystem
await storeCertificateInVault(domain, certData);
// Reload Nginx without downtime
console.log(`[Nginx] Reloading configuration with new certificate from Vault`);
}
function scheduleRenewal() {
// Check daily
setInterval(() => {
const cert: SSLCertificate = {
domain: "example.com",
issuer: "LetsEncrypt",
issuedAt: new Date(),
expiresAt: new Date(Date.now() + 15 * 24 * 60 * 60 * 1000),
daysLeft: 15,
status: "expiring",
keyId: "vault-ssl-example"
};
checkCertificateHealth(cert);
}, 86400000); // 24 hours
}
6. Integrating Vault Agent with Nginx
Vault Agent automatically pulls secrets and renders configuration templates without storing keys on disk.
// Vault Agent Template Example
const nginxTemplate = `
ssl_certificate /etc/ssl/live/{{ .domain }}/fullchain.pem;
ssl_certificate_key /etc/ssl/live/{{ .domain }}/privkey.pem;
server {
listen 443 ssl http2;
server_name {{ .domain }};
ssl_protocols TLSv1.2 TLSv1.3;
ssl_ciphers HIGH:!aNULL:!MD5;
}
`;
console.log("[Vault Agent] Rendering Nginx config from template and Vault secrets");
7. High-Security Best Practices
- Never store private keys in plain text on disk.
- Use short-lived certificates (90 days).
- Enable OCSP Stapling and HTTP Strict Transport Security (HSTS).
- Rotate keys periodically (e.g., every 6 months).
- Audit Vault access logs.
- Use mTLS for internal communications.
8. Conclusion: SSL/TLS Lifecycle Management Checklist
Before going to production, verify the following:
- Have you integrated the ACME client with Vault?
- Do certificates auto-renew 30 days before expiration?
- Are private keys stored in Vault instead of on disk?
- Does Nginx reload automatically after renewal?
- Do you have monitoring alerts for expiring certificates?
- Is there a regular key rotation policy in place?
Combining ACME with HashiCorp Vault helps you build a modern, fully automated, and highly secure SSL/TLS system. This is the standard every production environment should follow in 2026.
Hope this guide helps you confidently manage the SSL/TLS certificate lifecycle on your VPS!
