@nashbrydges said in Nginx Active-Passive HA:
@jaredbusch said in Nginx Active-Passive HA:
@NashBrydges side question. If you setup the .well-known to work correctly, why do you then need the HA? because nginx will never be down except for the momentary reload after the certs are updated.
That certainly addresses the biggest concern about a long downtime during the renewall process for a high number of certs and probably addresses most concerns with this client. He's already running Veeam replication to a second box so his RTO and RPO are relatively short and within his business tolerance.
Having said that, it's a great learning opportunity for me to set this up in my lab, if for no other reason than to try it and see how it works.
Certainly no reason not to do it for a lab. and for a proxy with as much as it sounds like you have in production, it will still be a likely good solution.