# Crowdsec on k3s w/ Traefik x509 certificate expiration with https enabled

**URL:** <https://discourse.crowdsec.net/t/crowdsec-on-k3s-w-traefik-x509-certificate-expiration-with-https-enabled/1700>\
**Category:** crowdsec\
**Created:** [March 15, 2024, 1:13am UTC](https://discourse.crowdsec.net/t/crowdsec-on-k3s-w-traefik-x509-certificate-expiration-with-https-enabled/1700 "2024-03-15T01:13:21Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![BriianPowell](https://dub1.discourse-cdn.com/flex013/user_avatar/discourse.crowdsec.net/briianpowell/32/667_2.png) [@BriianPowell](https://discourse.crowdsec.net/u/BriianPowell)\
**Post date:** [March 15, 2024, 1:13am UTC](https://discourse.crowdsec.net/t/crowdsec-on-k3s-w-traefik-x509-certificate-expiration-with-https-enabled/1700/1 "2024-03-15T01:13:21Z")

</div>

Hey there,

Looking for some advice on how to handle this issue I keep running into.

I am running Crowdsec on k3s with Traefik. Crowdsec is running in https mode using x509 certs that it creates using it’s ca-issuer.

The certificate will last for 90 days, at the end of the 90 days, the certificate will expire and the bouncer will now get 403 unauthorized errors and basically break all ingress going through traefik. I’ve not found a way to rotate this certificate. When I inspect in inside the cluster, it’s still showing as an active and healthy certificate.

Any seen this issue before or know how to deal with it? It’s driving me crazy.

---

<div class="post-metadata">

**Author:** ![iiAmLoz](https://dub1.discourse-cdn.com/flex013/user_avatar/discourse.crowdsec.net/iiamloz/32/386_2.png) [@iiAmLoz](https://discourse.crowdsec.net/u/iiAmLoz)\
**Post date:** [March 15, 2024, 8:43am UTC](https://discourse.crowdsec.net/t/crowdsec-on-k3s-w-traefik-x509-certificate-expiration-with-https-enabled/1700/2 "2024-03-15T08:43:22Z")

</div>

it is most likely, that the certificate is being renewed but the bouncer only read the certificate at startup so it doesnt know to read read and load the new cert.

> <https://github.com/crowdsecurity/go-cs-bouncer/issues/41>
>
> User are reporting that bouncer are getting stuck in a 403 response loop because… it is not reloading the certificate if the file is modified on disk. Please can we create either a inotify hook or we detect a 403 response code and tls auth failure = check certificate timestamp 🤷🏻

Edit: our k8s person has linked me [GitHub - stakater/Reloader: A Kubernetes controller to watch changes in ConfigMap and Secrets and do rolling upgrades on Pods with their associated Deployment, StatefulSet, DaemonSet and DeploymentConfig – [✩Star] if you're using it!](https://github.com/stakater/Reloader) could be a solution but this adds extra items when we could just do it within the bouncer lib 🤷

---

<div class="post-metadata">

**Author:** ![BriianPowell](https://dub1.discourse-cdn.com/flex013/user_avatar/discourse.crowdsec.net/briianpowell/32/667_2.png) [@BriianPowell](https://discourse.crowdsec.net/u/BriianPowell)\
**Post date:** [March 15, 2024, 6:54pm UTC](https://discourse.crowdsec.net/t/crowdsec-on-k3s-w-traefik-x509-certificate-expiration-with-https-enabled/1700/3 "2024-03-15T18:54:51Z")

</div>

This is exactly what’s happening, thanks for pointing me in the right direction. I’m curious if you’ve come across this and how you remediate?
