3 ms·
Would be interesting to hear what database they are using and how they are doing replication? Is it simple master / slave or multi-master?
by nodesocket 10mo ago
Would be interesting to hear what database they are using and how they are doing replication? Is it simple master / slave or multi-master?
- Ayesh 10mo agohttps://github.com/letsencrypt/boulder https://github.com/letsencrypt/boulder You can find a docker-compose.yml file to get some idea. Appears to be using MariaDB. They shut down OCSP responders and expiry email reminders, so there really is no need to have a database apart from rate limits, auth data, and caching. For Certificate Transparency, they are submitted to Google and CloudFlare run trees but I don't think LetsEncrypt run their own logs.
- nodesocket 10mo agoI assume they want to store metadata instead of having to pull from the certificates itself, but maybe that’s actually easier and more performant.
- mcpherrinm 10mo agoLet’s Encrypt does operate CT logs. I wrote a blog post about our current-generation logs at https://letsencrypt.org/2024/03/14/introducing-sunlight https://letsencrypt.org/2024/03/14/introducing-sunlight
- mcpherrinm 10mo agoLet’s Encrypt currently has a single primary with a handful of replicas, split across a primary and backup DC. We’re in progress of adopting Vitess to shard into a handful of smaller instances, as our single big database is getting unwieldy.
- nodesocket 10mo agoThanks. Would love to see a tech blog post once you get Vitess implemented.
- mcpherrinm 10mo agoWe’ve already started drafting it :)
- samlambert 10mo agoLet’s Encrypt is an incredible project and the internet is better off for it. If you ever have questions about vitess or need help please let me know.