# Renewal-hooks per domain

**URL:** <https://community.letsencrypt.org/t/renewal-hooks-per-domain/175621>\
**Category:** Help\
**Created:** [April 11, 2022, 8:37pm UTC](https://community.letsencrypt.org/t/renewal-hooks-per-domain/175621 "2022-04-11T20:37:52Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![idc77](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/idc77/32/59880_2.png) [@idc77](https://community.letsencrypt.org/u/idc77)\
**Post date:** [April 11, 2022, 8:37pm UTC](https://community.letsencrypt.org/t/renewal-hooks-per-domain/175621/1 "2022-04-11T20:37:52Z")

</div>

I have read the documentation,  
I have searched stackoverflow,  
using certbot 1.25.0 on Linux  
I did not find a way to run per domain post-renewal hooks.

I see that `/etc/letsencrypt/renewal-hooks/post` has room for shell scripts. But those are global.  
Do those shell scripts receive any arguments?  
When are those scripts ran exactly, after each domain's renewal or once after all renewals have completed (with or without error)?

I see someone had a similar question [When are renewal-hooks run?](https://community.letsencrypt.org/t/when-are-renewal-hooks-run/103997) which remained completely unanswered, not just that but autoclosed.  
I think maybe I should open a github issue to receive a response.

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [April 11, 2022, 8:47pm UTC](https://community.letsencrypt.org/t/renewal-hooks-per-domain/175621/2 "2022-04-11T20:47:33Z")

</div>

> [@idc77](#):
>
> When are those scripts ran exactly, after each domain's renewal or once after all renewals have completed (with or without error)?

Please see the appropriate sections of the Certbot documentation:

[Renewing certificates](https://eff-certbot.readthedocs.io/en/stable/using.html#renewing-certificates)

That section also refers to more details about the hooks by running `certbot --help renew`.

At the bottom of the documentation you can find that output, among everything else from `certbot --help`: [Certbot command-line options](https://eff-certbot.readthedocs.io/en/stable/using.html#certbot-command-line-options)

---

<div class="post-metadata">

**Author:** ![\_az](https://avatars.discourse-cdn.com/v4/letter/_/22d042/32.png) [@\_az](https://community.letsencrypt.org/u/_az)\
**Post date:** [April 11, 2022, 8:55pm UTC](https://community.letsencrypt.org/t/renewal-hooks-per-domain/175621/3 "2022-04-11T20:55:27Z")

</div>

There are two ways to use hooks in Certbot:

- The directory hooks in `/etc/letsencrypt/renewal-hooks/{pre,post,deploy}`, which will run for every certificate.
- Specifying a hook when creating or renewing a specific certificate with `--pre-hook`, `--post-hook` and `--deploy-hook`.

`--deploy-hook` (and its directory equivalent) receives `$RENEWED_LINEAGE` as an environment variable, which points to the `/etc/letsencrypt/live/example.com` directory. You may use `$(basename $RENEWED_LINEAGE)` to get the certificate name.

`--pre-hook` and `--post-hook` do not receive any arguments or environment variables.

> [@idc77](#):
>
> When are those scripts ran exactly, after each domain's renewal or once after all renewals have completed (with or without error)?

Each `--pre-hook` is executed immediately before the renewal attempt for any certificate which asks for it to run. If multiple certificates have the same `--pre-hook`, it will only be executed a single time. It is deduplicated.

Each `--post-hook` are gathered and executed after _every_ certificate renewal attempt has completed. The success or failure of each certificate renewal attempt has no effect on whether the hook runs. As with `--pre-hook`, they are deduplicated.

Each `--deploy-hook` is executed immediately after a successful renewal attempt for its respective certificate. It is not executed if the renewal attempt for that certificate fails.

---

<div class="post-metadata">

**Author:** ![idc77](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/idc77/32/59880_2.png) [@idc77](https://community.letsencrypt.org/u/idc77)\
**Post date:** [April 12, 2022, 4:11pm UTC](https://community.letsencrypt.org/t/renewal-hooks-per-domain/175621/4 "2022-04-12T16:11:29Z")

</div>

Thank you.  
Can there ever be a situation where `$RENEWED_DOMAINS` is more than one domain?  
I can't think of one, because it's in context of the single renewed domain, as far as I understood the documentation?

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [April 12, 2022, 4:20pm UTC](https://community.letsencrypt.org/t/renewal-hooks-per-domain/175621/5 "2022-04-12T16:20:15Z")

</div>

A certificate can contain multiple domains, so I don't see why `$RENEWED_DOMAINS` wouldn't be able to contain more than a single domain name?

From the documentation linked above:

> the shell variable $RENEWED\_DOMAINS will contain a space-delimited list of renewed certificate domains (for example, "[example.com](http://example.com) [www.example.com](http://www.example.com)")

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [April 12, 2022, 4:27pm UTC](https://community.letsencrypt.org/t/renewal-hooks-per-domain/175621/6 "2022-04-12T16:27:48Z")

</div>

In short:  
If you can get a cert, you can save the required `pre` and `post` hooks for it.

Rinse and repeat...

You can have many certs with their individualized `pre` and `post` hooks (per cert) saved and then reused on their specific renewals.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [May 12, 2022, 4:27pm UTC](https://community.letsencrypt.org/t/renewal-hooks-per-domain/175621/7 "2022-05-12T16:27:53Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
