# ACME provider generates empty acme.json

**URL:** <https://community.traefik.io/t/acme-provider-generates-empty-acme-json/20608>\
**Category:** Traefik v2\
**Tags:** letsencrypt-acme\
**Created:** [November 28, 2023, 8:52pm UTC](https://community.traefik.io/t/acme-provider-generates-empty-acme-json/20608 "2023-11-28T20:52:44Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![ofgirichardsonb](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/ofgirichardsonb/32/7278_2.png) [@ofgirichardsonb](https://community.traefik.io/u/ofgirichardsonb)\
**Post date:** [November 28, 2023, 8:52pm UTC](https://community.traefik.io/t/acme-provider-generates-empty-acme-json/20608/1 "2023-11-28T20:52:44Z")

</div>

I have the following configuration defined in my helm values file:

```auto
deployment:
  initContainers:
    - name: volume-permissions
      image: busybox:latest
      command: ["sh", "-c", "touch /data/acme.json; chmod -v 600 /data/acme.json"]
      securityContext:
        runAsNonRoot: true
        runAsGroup: 65532
        runAsUser: 65532
      volumeMounts:
        - name: data
          mountPath: /data
additionalArguments:
  - --log.level=DEBUG
  - --metrics.prometheus=true
  - --metrics.prometheus.entryPoint=metrics
  - --metrics.prometheus.buckets=0.1,0.3,1.2,5.0
  - --providers.kubernetescrd.ingressclass=traefik-internal
  - --entryPoints.otel-grpc.address=:4317
  - --entryPoints.otel-http.address=:4318
  - --certificatesresolvers.le.acme.email=richardsonb@olympiafinancial.com
  - --certificatesresolvers.le.acme.storage=/data/acme.json
  - --certificatesresolvers.le.acme.dnschallenge.provider=dnsmadeeasy
  - --certificatesresolvers.le.acme.dnschallenge.delaybeforecheck=0
ports:
  web:
    redirectTo:
      port: websecure
service:
  spec:
    loadBalancerIP: a.b.c.d
  annotations:
    prometheus.io/scrape: "true"
    prometheus.io/port: "9100"
    service.beta.kubernetes.io/azure-load-balancer-internal: "true"
  nodeSelector:
    agentpool: traefik
env:
- name: POD_NAME
  valueFrom:
    fieldRef:
      fieldPath: metadata.name
- name: POD_NAMESPACE
  valueFrom:
    fieldRef:
      fieldPath: metadata.namespace
- name: DNSMADEEASY_API_KEY
  valueFrom:
    secretKeyRef:
      name: dnsmadeeasy-api
      key: apikey
- name: DNSMADEEASY_API_SECRET
  valueFrom:
    secretKeyRef:
      name: dnsmadeeasy-api
      key: apisecret

```

The ingressroute is defined as follows:

```auto
apiVersion: traefik.io/v1alpha1
kind: IngressRoute
metadata:
  name: dashboard-internal
  namespace: traefik
  annotations:
    kubernetes.io/ingress.class: traefik-internal
spec:
  entryPoints:
    - web
    - websecure
  routes:
    - match: Host(`qa-traefik-int-arm64.olympiafinancial.com`)
      kind: Rule
      services:
        - name: api@internal
          kind: TraefikService
  tls:
    certResolver: le
    domains:
      - main: "*.olympiafinancial.com"
        sans:
          - qa-traefik-int-arm64.olympiafinancial.com

```

But all I see in the logs are the following:

```auto
time="2023-11-28T20:40:08Z" level=info msg="Testing certificate renew..." providerName=le.acme ACME CA="https://acme-v02.api.letsencrypt.org/directory"
...
time="2023-11-28T20:40:09Z" level=debug msg="Looking for provided certificate(s) to validate [\"*.olympiafinancial.com\" \"qa-traefik-int-arm64.olympiafinancial.com\"]..." ACME CA="https://acme-v02.api.letsencrypt.org/directory" providerName=le.acme
time="2023-11-28T20:40:09Z" level=debug msg="No ACME certificate generation required for domains [\"*.olympiafinancial.com\" \"qa-traefik-int-arm64.olympiafinancial.com\"]." ACME CA="https://acme-v02.api.letsencrypt.org/directory" providerName=le.acme

```

When I login to the container, I indeed see an acme.json file in /data, but it is empty. I would expect that it should fetch the certificate for \*.olympiafinancial.com and store it in acme.json. If I delete the empty acme.json (which I can), it gets recreated empty when I restart the deployment. I've verified that the environment variables DNSMADEEASY\_API\_KEY and DNSMADEEASY\_API\_SECRET are set correctly. What am I missing?

---

<div class="post-metadata">

**Author:** ![ofgirichardsonb](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/ofgirichardsonb/32/7278_2.png) [@ofgirichardsonb](https://community.traefik.io/u/ofgirichardsonb)\
**Post date:** [November 29, 2023, 3:23am UTC](https://community.traefik.io/t/acme-provider-generates-empty-acme-json/20608/2 "2023-11-29T03:23:28Z")

</div>

It seems there were some stale ingressroutes that still referred to a different version of the wildcard certificate for the domain. After deleting the ingress routes, ACME began to function as expected.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex020/uploads/containo/original/2X/b/bd81ebdb578656e76e56ff3cc3eed021d3ba132d.png) [@system](https://community.traefik.io/u/system)\
**Post date:** [December 2, 2023, 3:24am UTC](https://community.traefik.io/t/acme-provider-generates-empty-acme-json/20608/3 "2023-12-02T03:24:23Z")

</div>

This topic was automatically closed 3 days after the last reply. New replies are no longer allowed.
