10 days ago
My custom domain's Let's Encrypt certificate has never been renewed and expires on 2026-08-27. Per your docs, renewal should begin at 30 days remaining (around 2026-07-28), but no new certificate has ever been issued for this domain.
Project: LUMIERE - 7546d8ab-992c-4a10-b9f2-c87359474b70
Service: lumiere-backend - 0a7ff9ca-7942-4266-bba9-871caee171f2
Environment: 87a73b9b-46cd-46bc-a7b1-ca2cfcef0cb4
Custom domain: lumiere.ai.kr (port 8080), shows a green check in Settings / Networking
Plan: Pro
- Certificate currently served on lumiere.ai.kr (measured 2026-08-11):
issuer = C=US, O=Let's Encrypt, CN=YE1
notBefore = May 29 06:27:50 2026 GMT
notAfter = Aug 27 06:27:49 2026 GMT
serial = 05D92F804FE8EC2D22CFB20A74C168E7DE3E
This is still the original certificate from first issuance.
- Railway's own wildcard on the same edge DID renew on schedule:
lumiere-backend-production-ccd0.up.railway.app
notBefore = Jul 29 02:40:55 2026 GMT
notAfter = Oct 27 02:40:54 2026 GMT
serial = 06DA79BB561DA3EFEB0E751CA21ABD3999FE
That is a renewal on Jul 29, 29 days before an Aug 27 expiry, exactly what the 30-day policy predicts. So the ACME machinery is alive; the custom domain looks like it was skipped by it.
-
Certificate Transparency logs show no issuance for lumiere.ai.kr since 2026-05-29 (checked via Cert Spotter). Only three entries exist in total: one unrelated Sectigo certificate (2026-05-24, not served by Railway) and the precert/leaf pair of the Let's Encrypt certificate above. So there is no already-issued renewal waiting to be deployed, it was never issued at all.
-
I ruled out every cause listed in your SSL troubleshooting docs:
DNS: lumiere.ai.kr A resolves to 66.33.22.145, correctly
CAA: no CAA records on lumiere.ai.kr or on the parent zone ai.kr (NODATA on both)
DNSSEC: zone is not signed (AD=false)
Cloudflare: not proxied, direct to the Railway edge
The domain shows as verified (green) in the dashboard
Could you re-trigger issuance for this domain from your side?
I would rather not delete and re-add the domain, since your docs warn about Let's Encrypt rate limits and I want to avoid downtime. This domain is the landing page for an ad campaign that may begin delivering any day, so an outage during re-issuance would spend budget against an unreachable page.
2 Replies
Status changed to Awaiting Railway Response Railway • 10 days ago
10 days ago
Hi, quick update. The certificate for lumiere.ai.kr didn't get picked up by our automatic renewal, and the fix needs a change from our platform team.
Your current certificate is valid through August 27, so the site keeps working normally in the meantime and there's nothing you need to change. I'm following up with the platform team to get a fresh certificate issued well before that date, and I'll reply here as soon as it's live.
Thanks for your patience, and for the really thorough report.
Des
Status changed to Awaiting User Response Railway • 10 days ago
Status changed to In Progress dizzydes90 • 10 days ago
10 days ago
We're posting a fix for this internally and then will regenerate your ECDSA cert in the coming hours.
Also can you point your CNAME to us in your DNS settings? There complications without.