# Are the LE certs stored persistently with k8s?

**URL:** <https://community.traefik.io/t/are-the-le-certs-stored-persistently-with-k8s/3887>\
**Category:** Traefik v2\
**Tags:** letsencrypt-acme\
**Created:** [January 16, 2020, 10:42am UTC](https://community.traefik.io/t/are-the-le-certs-stored-persistently-with-k8s/3887 "2020-01-16T10:42:51Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![desmap](https://avatars.discourse-cdn.com/v4/letter/d/51bf81/32.png) [@desmap](https://community.traefik.io/u/desmap)\
**Post date:** [January 16, 2020, 10:42am UTC](https://community.traefik.io/t/are-the-le-certs-stored-persistently-with-k8s/3887/1 "2020-01-16T10:42:51Z")

</div>

I assume so but couldn't find anything about it.

Does Traefik uses k8s' secrets for this or volumes? Does they stay persistent (1) after I deleted all deployments and (2) after I resetted k8s?

Or are the other extreme, are they requested again and again with every new run?

---

<div class="post-metadata">

**Author:** ![ekjuanrejon](https://avatars.discourse-cdn.com/v4/letter/e/9fc29f/32.png) [@ekjuanrejon](https://community.traefik.io/u/ekjuanrejon)\
**Post date:** [January 16, 2020, 10:48am UTC](https://community.traefik.io/t/are-the-le-certs-stored-persistently-with-k8s/3887/2 "2020-01-16T10:48:20Z")

</div>

am having the same issue. Not only that I want to be able to use the secrets across different clusters. we are spinning up clusters on demand. Constantly hitting the rate limit...

Would love to hear what is the solution

---

<div class="post-metadata">

**Author:** ![desmap](https://avatars.discourse-cdn.com/v4/letter/d/51bf81/32.png) [@desmap](https://community.traefik.io/u/desmap)\
**Post date:** [January 16, 2020, 11:08am UTC](https://community.traefik.io/t/are-the-le-certs-stored-persistently-with-k8s/3887/3 "2020-01-16T11:08:07Z")

</div>

I just checked myself, just applied/deleted manifests 2 times and voila, it generates new certificates everytime and doesn't save the prior one. I kept k8s running inbetween:

1st run:  
 ![image](https://us1.discourse-cdn.com/flex020/uploads/containo/original/2X/d/d243b0af73ad88df4a5cfa7e263e104a09a061e5.png)

2nd run:  
 ![image](https://us1.discourse-cdn.com/flex020/uploads/containo/original/2X/7/735d00f262c64db8afb66a9da4bbe2c9f5c5711b.png)

The certs serial number also differ

I alos checked the debug log for legolog and both runs are identical, hence Traefik let LE everytime generate new certs 😕

---

<div class="post-metadata">

**Author:** ![desmap](https://avatars.discourse-cdn.com/v4/letter/d/51bf81/32.png) [@desmap](https://community.traefik.io/u/desmap)\
**Post date:** [January 16, 2020, 11:18am UTC](https://community.traefik.io/t/are-the-le-certs-stored-persistently-with-k8s/3887/4 "2020-01-16T11:18:22Z")

</div>

just posted a feature request in their issues, I think this is a must feature since k8s and other orchestrators offer a pers storage: [https://github.com/containous/traefik/issues/6189](https://github.com/containous/traefik/issues/6189)

---

<div class="post-metadata">

**Author:** ![lopz](https://avatars.discourse-cdn.com/v4/letter/l/4af34b/32.png) [@lopz](https://community.traefik.io/u/lopz)\
**Post date:** [January 16, 2020, 12:22pm UTC](https://community.traefik.io/t/are-the-le-certs-stored-persistently-with-k8s/3887/5 "2020-01-16T12:22:10Z")

</div>

I had the same problem. The only way I have found to solve it is using a volume to store the certificate (Azure files in my case).

---

<div class="post-metadata">

**Author:** ![desmap](https://avatars.discourse-cdn.com/v4/letter/d/51bf81/32.png) [@desmap](https://community.traefik.io/u/desmap)\
**Post date:** [January 16, 2020, 12:52pm UTC](https://community.traefik.io/t/are-the-le-certs-stored-persistently-with-k8s/3887/6 "2020-01-16T12:52:58Z")

</div>

so how did you do this? putting acme.json into somefolder/ and somefolder/ is a volume mapped to the physical system?

---

<div class="post-metadata">

**Author:** ![lopz](https://avatars.discourse-cdn.com/v4/letter/l/4af34b/32.png) [@lopz](https://community.traefik.io/u/lopz)\
**Post date:** [January 16, 2020, 1:58pm UTC](https://community.traefik.io/t/are-the-le-certs-stored-persistently-with-k8s/3887/8 "2020-01-16T13:58:41Z")

</div>

Yes. I mount a volume mapped to a directory previouly configured in traefik to save the certificates.

```yaml
volumeMounts:
  - mountPath: "/certs"
    name: certs

```

Configured volume:

```yaml
volumes:
  - name: certs
    persistentVolumeClaim:
      claimName: traefik-certs

```

---

<div class="post-metadata">

**Author:** ![SantoDE](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/santode/32/393_2.png) [@SantoDE](https://community.traefik.io/u/SantoDE)\
**Post date:** [January 16, 2020, 3:06pm UTC](https://community.traefik.io/t/are-the-le-certs-stored-persistently-with-k8s/3887/9 "2020-01-16T15:06:50Z")

</div>

That's actually how its ment to be 🙂 Mount a volume to store the file and it will be persistent

---

<div class="post-metadata">

**Author:** ![ekjuanrejon](https://avatars.discourse-cdn.com/v4/letter/e/9fc29f/32.png) [@ekjuanrejon](https://community.traefik.io/u/ekjuanrejon)\
**Post date:** [January 20, 2020, 12:19pm UTC](https://community.traefik.io/t/are-the-le-certs-stored-persistently-with-k8s/3887/10 "2020-01-20T12:19:07Z")

</div>

I wanted to do just that but I ready the following ticket

> <https://github.com/containous/traefik-helm-chart/issues/40>
>
> Can the chart be updated to use PVC to store the certs. right now every time the pod restarts it has...

---

<div class="post-metadata">

**Author:** ![jite](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/jite/32/163_2.png) [@jite](https://community.traefik.io/u/jite)\
**Post date:** [January 21, 2020, 7:21pm UTC](https://community.traefik.io/t/are-the-le-certs-stored-persistently-with-k8s/3887/11 "2020-01-21T19:21:53Z")

</div>

Either a persistent volume or a backend like Consul or Etcd is the recommended way of doing it. If you run multiple instances that share a configuration, I would highly recommend to not just use a volume as that might create some issues with read/write deadlocks etc.
