I am trying to fetch the tls certificate using letsencrypt in my ambassador endpoint gateway.
Error (obtaining tlsSecret ""."qa1" (hostnames=[""]): acme: error: 429 :: POST :: :: urn:ietf:params:acme:error:rateLimited :: Error creating new order :: too many certificates already issued for exact set of domains: see, url: )
My web server is (include version): Kubernetes POD

Use one of the 5 previously issued certificates this week.

You're issuing quite a lot of certs for this specific hostname: Use one of those.

Infact, you or your company is pretty good in hogging the Let's Encrypt infrastructure if I may say so, if you look at a label lower: Some I understand, but I say many, many duplicate certificates, which shouldn't be necessary. And that is costing Let's Encrypt resources.


can you help me , how can I use the duplicate ones or if it is possible can you consider for this time and delete all the duplicate .certs and provide a new one. i am waiting for that .due to this our whole automation is down. could you help us in that regard.

That's client application and software specific. I don't have any experience with Kubernetes, sorry. Perhaps someone else on this Community knows how "Kubernetes POD" works.

There is nothing to delete. Also, the resources have been spent when your software requested the certificates and consequently Let's Encrypt issued those certificates.

As said, use any of the previously issued certificates. It's not Let's Encrypts fault you're not running your ACME client the way you should run it. Issue a certificate just once and then actually use it. Store it on a persistent location, not a location part of some container which might be deleted, including the certificate.


Stating this another way:

Your integration with LetsEncrypt is poorly designed. If you are not responsible for this, you should escalate the issue internally with your supervisors.

The LetsEncrypt certificates are not intended to be ephemeral. They should not be generated and discarded as you spin up new virtual machines. Your company likely needs to use a centralized certificate manager or figure out how to store certificates for local re-use.


