SSL Certificates

Last updated 28 Sept 2026
View as Markdown

Overview

CloudPe TLS/SSL certificate management allows you to issue, upload, validate, and deploy SSL/TLS certificates across your cloud infrastructure. You can request free automated certificates via Let's Encrypt with automatic DNS-01 challenge validation and automated renewal rotation, or upload existing custom certificates and private keys.

Certificates are organization-scoped and can be deployed directly to OpenStack Octavia load balancer HTTPS listeners and Kubernetes PaaS application ingresses with automated synchronization when certificates renew.

Before you start

  • Viewing certificates and their statuses requires the certificates:read permission.
  • Requesting automated certificates or uploading custom certificates requires the certificates:create permission.
  • Triggering validation verification on pending challenges requires the certificates:update permission.
  • Deploying certificates to infrastructure resources requires the certificates:deploy permission, as well as load_balancers:update on the project hosting the load balancer.
  • Deleting or revoking certificates requires the certificates:delete permission.
  • For zero-touch automated domain validation, host your domain in CloudPe DNS under the same organization. See DNS zones and records.
  • Deploying a certificate to a load balancer requires an existing listener configured with the TERMINATED_HTTPS protocol. See Load balancers.

Steps

Request an automated Let's Encrypt certificate

  1. In the sidebar, open SSL Certificates under NETWORK.

  1. Select New Certificate (or Issue Certificate if no certificates exist).
  2. On the Issue / Upload Certificate page, select the Automated Let's Encrypt (Free) tab.
  3. Enter a friendly name for identification.
  4. Provide the primary domain name (such as app.example.com or a wildcard domain like *.example.com).
  5. Optionally, add additional Subject Alternative Names (SANs) one per line.
  6. Select Request Certificate.

Complete Domain Control Validation (DCV)

  1. Navigate to the certificate detail page.
  2. In the Domain Control Validation (DCV) Required section, inspect the challenge domain, host record, and TXT value.
  3. If the domain is hosted in CloudPe DNS, the validation record is injected automatically into your zone.
  4. If the domain is hosted on an external DNS provider, create the specified DNS TXT record at your DNS provider.
  5. After DNS records propagate, select Verify DCV Now to validate domain ownership and issue the certificate.

Upload a custom certificate (BYOC)

  1. In the sidebar, open SSL Certificates under NETWORK.
  2. Select New Certificate.
  3. Select the Upload Custom Certificate (BYOC) tab.
  4. Enter a name for the certificate.
  5. Paste the certificate in PEM format into the certificate field.
  6. Paste the corresponding unencrypted private key into the private key field.
  7. Optionally, paste intermediate and root certificates into the CA chain field.
  8. Select Save & Validate Certificate.

Manage certificates and view infrastructure bindings

  1. On the TLS / SSL Certificates list, use the filter tabs (All Certificates, Free (Let's Encrypt), Paid, Uploaded) to filter by source.
  2. Select a certificate name or select Manage to open the certificate detail view.
  3. Review certificate parameters under Issuer & Type, Validity Period, Serial & Fingerprint, and Active Infrastructure Bindings.
  4. To remove a certificate, select Delete.

API

Manage certificates and bindings programmatically using the certificates endpoints.

Method and path Permission
GET /api/v1/certificates certificates:read
POST /api/v1/certificates/acme certificates:create
POST /api/v1/certificates/upload certificates:create
GET /api/v1/certificates/{certificate_id} certificates:read
POST /api/v1/certificates/{certificate_id}/verify-dcv certificates:update
POST /api/v1/certificates/{certificate_id}/bindings certificates:deploy
DELETE /api/v1/certificates/{certificate_id}/bindings/{binding_id} certificates:deploy
DELETE /api/v1/certificates/{certificate_id} certificates:delete

List all certificates in your organization:

curl https://app.cloudpe.com/api/v1/certificates \
  -H "Authorization: Bearer <API_KEY>"

Request an automated Let's Encrypt certificate:

curl -X POST https://app.cloudpe.com/api/v1/certificates/acme \
  -H "Authorization: Bearer <API_KEY>" \
  -H "Content-Type: application/json" \
  -d '{
        "name": "Production Web App",
        "primary_domain": "app.example.com"
      }'

Upload a custom certificate bundle:

curl -X POST https://app.cloudpe.com/api/v1/certificates/upload \
  -H "Authorization: Bearer <API_KEY>" \
  -H "Content-Type: application/json" \
  -d '{
        "name": "Custom Wildcard",
        "certificate_pem": "-----BEGIN CERTIFICATE-----\n...\n-----END CERTIFICATE-----",
        "private_key_pem": "-----BEGIN RSA PRIVATE KEY-----\n...\n-----END RSA PRIVATE KEY-----"
      }'

Trigger immediate DCV validation for a pending certificate:

curl -X POST https://app.cloudpe.com/api/v1/certificates/<certificate_id>/verify-dcv \
  -H "Authorization: Bearer <API_KEY>"

Deploy a certificate to an active load balancer listener:

curl -X POST https://app.cloudpe.com/api/v1/certificates/<certificate_id>/bindings \
  -H "Authorization: Bearer <API_KEY>" \
  -H "Content-Type: application/json" \
  -d '{
        "target_type": "LOAD_BALANCER_LISTENER",
        "target_id": "<listener_id>"
      }'

Delete a certificate:

curl -X DELETE https://app.cloudpe.com/api/v1/certificates/<certificate_id> \
  -H "Authorization: Bearer <API_KEY>"

Limits & billing

  • Automated Let's Encrypt certificates are issued at no additional cost.
  • Automated certificates include automatic renewal and zero-touch validation for domains hosted on CloudPe DNS.
  • Certificates are organization-scoped and can be bound across multiple projects within the same organization.
  • Binding certificates to load balancer listeners requires the listener to be configured with the TERMINATED_HTTPS protocol.

Troubleshooting

Message What it means What to do
Load balancer listener not found The target load balancer listener ID does not exist or does not belong to your organization. Verify the listener UUID in the Load Balancers dashboard or call GET /api/v1/load-balancers/{lb_id}/listeners.
Private key not available for binding deployment The certificate's private key could not be retrieved from secure storage to configure TLS termination. Ensure the certificate was created with a private key, or re-upload the certificate and private key bundle.
Certificate not found The requested certificate UUID does not exist or has been deleted. Check the certificate UUID in the certificates list or call GET /api/v1/certificates.
Binding not found The specified infrastructure binding UUID does not exist or was already removed. Verify active bindings on the certificate detail page or query GET /api/v1/certificates/{certificate_id}.
PaaS app not found The target PaaS application ID does not exist or does not belong to your organization. Verify the application UUID in your project before creating the certificate binding.

FAQ

How does automatic certificate renewal work? Automated Let's Encrypt certificates have automatic renewal enabled by default. Prior to expiration, CloudPe initiates validation challenges and renews the certificate. Active infrastructure bindings on load balancers and PaaS applications are updated automatically.

Can I attach a certificate to multiple load balancers? Yes. Because certificates are scoped to your organization, you can create multiple bindings to deploy the same certificate across different load balancer listeners and PaaS apps.

What domain validation method is used for automated certificates? Automated certificates use DNS-01 validation. If your DNS zone is hosted on CloudPe DNS, challenge TXT records are created automatically. For external DNS providers, you can manually create the required TXT record.

Can I bind a certificate to an HTTP listener? No. Load balancer listeners require the TERMINATED_HTTPS protocol for TLS termination. To use SSL on a load balancer, configure a TERMINATED_HTTPS listener.

Related

Did this guide answer your question?If you need customized assistance with your deployment, reach out to our team.
Contact Support