<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Alexandre Berthaud, Author at Clever Cloud</title>
	<atom:link href="https://stagingv6.cleverapps.io/blog/author/alexandre-berthaudclever-cloud-com/feed/" rel="self" type="application/rss+xml" />
	<link></link>
	<description>From Code to Product</description>
	<lastBuildDate>Tue, 15 Jan 2019 17:36:00 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://staging-cc-assetsv6.cellar-c2.services.clever-cloud.com/uploads/2023/03/cropped-cropped-favicon-32x32.png</url>
	<title>Alexandre Berthaud, Author at Clever Cloud</title>
	<link></link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Let&#8217;s Encrypt Certificates For Everyone</title>
		<link>https://stagingv6.cleverapps.io/blog/features/2019/01/15/automatic-lets-encrypt-certificates/</link>
		
		<dc:creator><![CDATA[Alexandre Berthaud]]></dc:creator>
		<pubDate>Tue, 15 Jan 2019 17:36:00 +0000</pubDate>
				<category><![CDATA[Features]]></category>
		<category><![CDATA[feature]]></category>
		<category><![CDATA[HTTPS]]></category>
		<category><![CDATA[SSL]]></category>
		<guid isPermaLink="false">https://www2.cleverapps.io/wp/blog/technology/2019/01/15/automatic-lets-encrypt-certificates/</guid>

					<description><![CDATA[<p><img width="1400" height="540" src="https://staging-cc-assetsv6.cellar-c2.services.clever-cloud.com/uploads/2021/08/letsencrypt-1.png" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://staging-cc-assetsv6.cellar-c2.services.clever-cloud.com/uploads/2021/08/letsencrypt-1.png 1400w, https://staging-cc-assetsv6.cellar-c2.services.clever-cloud.com/uploads/2021/08/letsencrypt-1-300x116.png 300w, https://staging-cc-assetsv6.cellar-c2.services.clever-cloud.com/uploads/2021/08/letsencrypt-1-1024x395.png 1024w, https://staging-cc-assetsv6.cellar-c2.services.clever-cloud.com/uploads/2021/08/letsencrypt-1-768x296.png 768w, https://staging-cc-assetsv6.cellar-c2.services.clever-cloud.com/uploads/2021/08/letsencrypt-1-1368x528.png 1368w" sizes="(max-width: 1400px) 100vw, 1400px" /></p><p>We have been issuing and automatically installing Let&#39;s Encrypt® certificates for a while now. The only manual thing was the trigger of this process. But today, we are glad to <strong>announce fully automated Let&#39;s Encrypt certificates for everyone!</strong></p>
<span id="more-2950"></span>

<p>When you add a domain — which targets Clever Cloud — to an application; it will have its own certificate a few minutes later (up to 12 minutes later).</p>
<p>This has been live since 2018-11-16. Hundreds of certificates have been issued since then. This has been possible thanks to <a href="https://letsencrypt.org">Let&#39;s Encrypt</a>, who also extended their rate limiting on their API.</p>
<h2 id="how-do-we-do-this">How do we do this?</h2>
<p>As explained in the <a href="/blog/features/2018/05/30/about-lets-encrypt/">previous blog post</a>, queries to the path used by Let&#39;s Encrypt to check the ownership of the domain are routed to our Let&#39;s Encrypt integration service. This allows us to process the Let&#39;s Encrypt queries, get the certificate and give it to our certificates manager.</p>
<p>Here is what&#39;s new. Once a user adds a new domain, we periodically check that we can reach our Let&#39;s Encrypt integration service. When we do, we start the usual process <em>et voilà</em>.</p>
<h2 id="what-if-i-want-another-kind-of-certificate">What if I want another kind of certificate?</h2>
<p>That&#39;s not a problem:</p>
<p>If you already have a certificate, we will not create a Let&#39;s Encrypt certificate.</p>
<h2 id="how-about-existing-domains">How about existing domains?</h2>
<p>Existing domains which do not yet have a certificate will all get a Let&#39;s Encrypt certificate.</p>
<p>This will be done over the next weeks to come. We can&#39;t do this in a single batch for two reasons:</p>
<ul>
<li>Let&#39;s Encrypt rate limiting (we have extended limits but we still cannot send such a big batch all at once)</li>
<li>We need to spread this out so that we don&#39;t have a big batch of renewals every 3 months</li>
</ul>
<p>If you don&#39;t want to wait, you can simply ask us to enable it.</p>
<h2 id="next-steps">Next steps</h2>
<p>There are a few things yet to come:</p>
<ul>
<li>Interface in the console to track the status of the certificates</li>
<li>Support of wildcard certificates (which will not be quite as automatic because it requires DNS validation; this will require an action from you at first)</li>
</ul>
<h2 id="one-last-thing">One last thing</h2>
<p>We are now proud sponsors of Let&#39;s Encrypt!</p>
]]></description>
										<content:encoded><![CDATA[<p><img width="1400" height="540" src="https://staging-cc-assetsv6.cellar-c2.services.clever-cloud.com/uploads/2021/08/letsencrypt-1.png" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" srcset="https://staging-cc-assetsv6.cellar-c2.services.clever-cloud.com/uploads/2021/08/letsencrypt-1.png 1400w, https://staging-cc-assetsv6.cellar-c2.services.clever-cloud.com/uploads/2021/08/letsencrypt-1-300x116.png 300w, https://staging-cc-assetsv6.cellar-c2.services.clever-cloud.com/uploads/2021/08/letsencrypt-1-1024x395.png 1024w, https://staging-cc-assetsv6.cellar-c2.services.clever-cloud.com/uploads/2021/08/letsencrypt-1-768x296.png 768w, https://staging-cc-assetsv6.cellar-c2.services.clever-cloud.com/uploads/2021/08/letsencrypt-1-1368x528.png 1368w" sizes="(max-width: 1400px) 100vw, 1400px" /></p><p>We have been issuing and automatically installing Let&#39;s Encrypt® certificates for a while now. The only manual thing was the trigger of this process. But today, we are glad to <strong>announce fully automated Let&#39;s Encrypt certificates for everyone!</strong></p>
<span id="more-2950"></span>

<p>When you add a domain — which targets Clever Cloud — to an application; it will have its own certificate a few minutes later (up to 12 minutes later).</p>
<p>This has been live since 2018-11-16. Hundreds of certificates have been issued since then. This has been possible thanks to <a href="https://letsencrypt.org">Let&#39;s Encrypt</a>, who also extended their rate limiting on their API.</p>
<h2 id="how-do-we-do-this">How do we do this?</h2>
<p>As explained in the <a href="/blog/features/2018/05/30/about-lets-encrypt/">previous blog post</a>, queries to the path used by Let&#39;s Encrypt to check the ownership of the domain are routed to our Let&#39;s Encrypt integration service. This allows us to process the Let&#39;s Encrypt queries, get the certificate and give it to our certificates manager.</p>
<p>Here is what&#39;s new. Once a user adds a new domain, we periodically check that we can reach our Let&#39;s Encrypt integration service. When we do, we start the usual process <em>et voilà</em>.</p>
<h2 id="what-if-i-want-another-kind-of-certificate">What if I want another kind of certificate?</h2>
<p>That&#39;s not a problem:</p>
<p>If you already have a certificate, we will not create a Let&#39;s Encrypt certificate.</p>
<h2 id="how-about-existing-domains">How about existing domains?</h2>
<p>Existing domains which do not yet have a certificate will all get a Let&#39;s Encrypt certificate.</p>
<p>This will be done over the next weeks to come. We can&#39;t do this in a single batch for two reasons:</p>
<ul>
<li>Let&#39;s Encrypt rate limiting (we have extended limits but we still cannot send such a big batch all at once)</li>
<li>We need to spread this out so that we don&#39;t have a big batch of renewals every 3 months</li>
</ul>
<p>If you don&#39;t want to wait, you can simply ask us to enable it.</p>
<h2 id="next-steps">Next steps</h2>
<p>There are a few things yet to come:</p>
<ul>
<li>Interface in the console to track the status of the certificates</li>
<li>Support of wildcard certificates (which will not be quite as automatic because it requires DNS validation; this will require an action from you at first)</li>
</ul>
<h2 id="one-last-thing">One last thing</h2>
<p>We are now proud sponsors of Let&#39;s Encrypt!</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>About Let&#8217;s Encrypt</title>
		<link>https://stagingv6.cleverapps.io/blog/features/2018/05/30/about-lets-encrypt/</link>
		
		<dc:creator><![CDATA[Alexandre Berthaud]]></dc:creator>
		<pubDate>Wed, 30 May 2018 16:15:00 +0000</pubDate>
				<category><![CDATA[Features]]></category>
		<category><![CDATA[feature]]></category>
		<category><![CDATA[HTTPS]]></category>
		<category><![CDATA[SSL]]></category>
		<guid isPermaLink="false">https://www2.cleverapps.io/wp/blog/technology/2018/05/30/about-lets-encrypt/</guid>

					<description><![CDATA[<p><img width="1400" height="540" src="https://staging-cc-assetsv6.cellar-c2.services.clever-cloud.com/uploads/2021/08/aboutletsencrypt-1.png" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" srcset="https://staging-cc-assetsv6.cellar-c2.services.clever-cloud.com/uploads/2021/08/aboutletsencrypt-1.png 1400w, https://staging-cc-assetsv6.cellar-c2.services.clever-cloud.com/uploads/2021/08/aboutletsencrypt-1-300x116.png 300w, https://staging-cc-assetsv6.cellar-c2.services.clever-cloud.com/uploads/2021/08/aboutletsencrypt-1-1024x395.png 1024w, https://staging-cc-assetsv6.cellar-c2.services.clever-cloud.com/uploads/2021/08/aboutletsencrypt-1-768x296.png 768w, https://staging-cc-assetsv6.cellar-c2.services.clever-cloud.com/uploads/2021/08/aboutletsencrypt-1-1368x528.png 1368w" sizes="(max-width: 1400px) 100vw, 1400px" /></p><p>We have been working on Let&#39;s Encrypt support for quite some time now.</p>
<p>We have a working prototype used for hundreds of domains and it has been running since August 2017 and has handled thousands of renewals without a single hiccup.</p>
<p>To go further, we need to make a small change to the way we route incoming requests.</p>
<span id="more-2936"></span>

<h2 id="how-does-lets-encrypt-work">How does Let&#39;s Encrypt work?</h2>
<p>Let&#39;s Encrypt needs to validate the ownership of a domain before delivering a certificate. As does any public certificate authority.</p>
<p>For our Let&#39;s Encrypt integration, we are using the HTTP challenge to validate that we own the web server that a domain points to.</p>
<p>Here is how the HTTP challenge works, basically:</p>
<ul>
<li>The client asks for a certificate for a domain (with a <a href="https://en.wikipedia.org/wiki/Certificate_signing_request">CSR</a>)</li>
<li>Let&#39;s Encrypt responds with a challenge id and a token</li>
<li>The client sets up this token to be sent when receving a request on <code>http://domain.tld/.well-known/acme-challenge/&lt;the challenge id&gt;</code></li>
<li>The client tells Let&#39;s Encrypt that it&#39;s ready</li>
<li>Let&#39;s Encrypt makes the request to <code>http://domain.tld/.well-known/acme-challenge/&lt;the challenge id&gt;</code></li>
<li>If the challenge is validated, it will then reply to the client with the certificate</li>
</ul>
<h2 id="how-does-clever-cloud-implement-this">How does Clever Cloud implement this?</h2>
<p>What we have been doing since last August is routing the <code>/.well-known/acme-challenge</code> to our Let&#39;s Encrypt integration service when a customer asks us to.</p>
<p>Sadly, this means that we have a bunch of rules in our reverse proxies to handle this. As the list of domains grow, it&#39;s becoming quite clear that this is simply not technically feasible. This huge list of rules is adding a lot of work to HAProxy&#39;s configuration parsing.</p>
<p>As we have hundreds of configuration changes per minute (batched together, but still), this has too much of an impact on the performance of our reverse proxies and the feature is not even released yet!</p>
<h2 id="what-changes">What changes</h2>
<p>Starting today, <em>all</em> requests starting with the path <code>/.well-known/acme-challenge</code> will be sent to our Let&#39;s Encrypt integration.</p>
<p>This can be disabled on dedicated reverse proxies for our <a href="https://stagingv6.cleverapps.io/clever-cloud-premium">Premium</a> customers only.</p>
<h2 id="when-will-this-feature-be-available-in-the-console">When will this feature be available in the console?</h2>
<p>Right now, we only enable this on demand, domain per domain.</p>
<p>The goal, obviously, is to have an interface for this in the console and in clever-tools.</p>
<p>We still have ways to go, but the current target is by the end of this year.</p>
]]></description>
										<content:encoded><![CDATA[<p><img width="1400" height="540" src="https://staging-cc-assetsv6.cellar-c2.services.clever-cloud.com/uploads/2021/08/aboutletsencrypt-1.png" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://staging-cc-assetsv6.cellar-c2.services.clever-cloud.com/uploads/2021/08/aboutletsencrypt-1.png 1400w, https://staging-cc-assetsv6.cellar-c2.services.clever-cloud.com/uploads/2021/08/aboutletsencrypt-1-300x116.png 300w, https://staging-cc-assetsv6.cellar-c2.services.clever-cloud.com/uploads/2021/08/aboutletsencrypt-1-1024x395.png 1024w, https://staging-cc-assetsv6.cellar-c2.services.clever-cloud.com/uploads/2021/08/aboutletsencrypt-1-768x296.png 768w, https://staging-cc-assetsv6.cellar-c2.services.clever-cloud.com/uploads/2021/08/aboutletsencrypt-1-1368x528.png 1368w" sizes="auto, (max-width: 1400px) 100vw, 1400px" /></p><p>We have been working on Let&#39;s Encrypt support for quite some time now.</p>
<p>We have a working prototype used for hundreds of domains and it has been running since August 2017 and has handled thousands of renewals without a single hiccup.</p>
<p>To go further, we need to make a small change to the way we route incoming requests.</p>
<span id="more-2936"></span>

<h2 id="how-does-lets-encrypt-work">How does Let&#39;s Encrypt work?</h2>
<p>Let&#39;s Encrypt needs to validate the ownership of a domain before delivering a certificate. As does any public certificate authority.</p>
<p>For our Let&#39;s Encrypt integration, we are using the HTTP challenge to validate that we own the web server that a domain points to.</p>
<p>Here is how the HTTP challenge works, basically:</p>
<ul>
<li>The client asks for a certificate for a domain (with a <a href="https://en.wikipedia.org/wiki/Certificate_signing_request">CSR</a>)</li>
<li>Let&#39;s Encrypt responds with a challenge id and a token</li>
<li>The client sets up this token to be sent when receving a request on <code>http://domain.tld/.well-known/acme-challenge/&lt;the challenge id&gt;</code></li>
<li>The client tells Let&#39;s Encrypt that it&#39;s ready</li>
<li>Let&#39;s Encrypt makes the request to <code>http://domain.tld/.well-known/acme-challenge/&lt;the challenge id&gt;</code></li>
<li>If the challenge is validated, it will then reply to the client with the certificate</li>
</ul>
<h2 id="how-does-clever-cloud-implement-this">How does Clever Cloud implement this?</h2>
<p>What we have been doing since last August is routing the <code>/.well-known/acme-challenge</code> to our Let&#39;s Encrypt integration service when a customer asks us to.</p>
<p>Sadly, this means that we have a bunch of rules in our reverse proxies to handle this. As the list of domains grow, it&#39;s becoming quite clear that this is simply not technically feasible. This huge list of rules is adding a lot of work to HAProxy&#39;s configuration parsing.</p>
<p>As we have hundreds of configuration changes per minute (batched together, but still), this has too much of an impact on the performance of our reverse proxies and the feature is not even released yet!</p>
<h2 id="what-changes">What changes</h2>
<p>Starting today, <em>all</em> requests starting with the path <code>/.well-known/acme-challenge</code> will be sent to our Let&#39;s Encrypt integration.</p>
<p>This can be disabled on dedicated reverse proxies for our <a href="https://stagingv6.cleverapps.io/clever-cloud-premium">Premium</a> customers only.</p>
<h2 id="when-will-this-feature-be-available-in-the-console">When will this feature be available in the console?</h2>
<p>Right now, we only enable this on demand, domain per domain.</p>
<p>The goal, obviously, is to have an interface for this in the console and in clever-tools.</p>
<p>We still have ways to go, but the current target is by the end of this year.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Introducing Notifications</title>
		<link>https://stagingv6.cleverapps.io/blog/features/2016/11/16/notifications/</link>
		
		<dc:creator><![CDATA[Alexandre Berthaud]]></dc:creator>
		<pubDate>Wed, 16 Nov 2016 17:05:00 +0000</pubDate>
				<category><![CDATA[Features]]></category>
		<category><![CDATA[CLI]]></category>
		<category><![CDATA[console]]></category>
		<category><![CDATA[feature]]></category>
		<category><![CDATA[notifications]]></category>
		<guid isPermaLink="false">https://www2.cleverapps.io/wp/blog/technology/2016/11/16/notifications/</guid>

					<description><![CDATA[<p><img width="48" height="48" src="https://staging-cc-assetsv6.cellar-c2.services.clever-cloud.com/uploads/2021/04/notifications.svg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" loading="lazy" /></p>Historically, deployment result e-mails (deployment succeeded or failed) were always sent to the owners of an application, namely the user themselves or the organisation's members.

This changes today.

<span id="more-2878"></span>

You will now find a <em>Notifications</em> tab in your personal space and organisations. Our CLI tool, <a href="https://stagingv6.cleverapps.io/doc/clever-tools/getting_started/">clever-tools</a>, also gained two commands: <code>notify-email</code> and <code>webhooks</code>.

This will allow you to disable the default deployment e-mails but also to set up more e-mail notifications and, of course, webhooks!
<h2 id="whats-a-webhook-though">What's a Webhook though?</h2>
Here is what Wikipedia has to say:
<blockquote>A webhook in web development is a method of augmenting or altering the behavior of a web page, or web application, with custom callbacks. These callbacks may be maintained, modified, and managed by third-party users and developers who may not necessarily be affiliated with the originating website or application.</blockquote>
In practical terms, this means that you can choose to receive notifications corresponding to events happening on Clever Cloud in a specific format, directly to the application of your choice.

For example, you can choose to receive the deployment results of your applications in a Slack channel!

<center>
<figure>
    <img style="width:100%" src="https://www2.cleverapps.io/app/uploads/2021/08/notifications-slack.png"></figure>
</center>
<h2 id="neat-how-do-you-do-that">Neat! How do you do that?</h2>
You're in luck, it's explained in our documentation. You can do it via the <a href="https://stagingv6.cleverapps.io/doc/account/notifications/">dashboard</a> or via the <a href="https://stagingv6.cleverapps.io/doc/reference/clever-tools/notifications/">CLI</a>.

Enjoy!
<h2 id="coming-soon">Coming soon</h2>
Aside from more e-mail notifications and more events handled, we also intend to add a way to define notifications targeting every member of an organisation <em>except</em> some users (right now, you have to define the full list of people) as well as a way to edit an existing hook in the dashboard.]]></description>
										<content:encoded><![CDATA[<p><img width="48" height="48" src="https://staging-cc-assetsv6.cellar-c2.services.clever-cloud.com/uploads/2021/04/notifications.svg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" loading="lazy" /></p>Historically, deployment result e-mails (deployment succeeded or failed) were always sent to the owners of an application, namely the user themselves or the organisation's members.

This changes today.

<span id="more-2878"></span>

You will now find a <em>Notifications</em> tab in your personal space and organisations. Our CLI tool, <a href="https://stagingv6.cleverapps.io/doc/clever-tools/getting_started/">clever-tools</a>, also gained two commands: <code>notify-email</code> and <code>webhooks</code>.

This will allow you to disable the default deployment e-mails but also to set up more e-mail notifications and, of course, webhooks!
<h2 id="whats-a-webhook-though">What's a Webhook though?</h2>
Here is what Wikipedia has to say:
<blockquote>A webhook in web development is a method of augmenting or altering the behavior of a web page, or web application, with custom callbacks. These callbacks may be maintained, modified, and managed by third-party users and developers who may not necessarily be affiliated with the originating website or application.</blockquote>
In practical terms, this means that you can choose to receive notifications corresponding to events happening on Clever Cloud in a specific format, directly to the application of your choice.

For example, you can choose to receive the deployment results of your applications in a Slack channel!

<center>
<figure>
    <img style="width:100%" src="https://www2.cleverapps.io/app/uploads/2021/08/notifications-slack.png"></figure>
</center>
<h2 id="neat-how-do-you-do-that">Neat! How do you do that?</h2>
You're in luck, it's explained in our documentation. You can do it via the <a href="https://stagingv6.cleverapps.io/doc/account/notifications/">dashboard</a> or via the <a href="https://stagingv6.cleverapps.io/doc/reference/clever-tools/notifications/">CLI</a>.

Enjoy!
<h2 id="coming-soon">Coming soon</h2>
Aside from more e-mail notifications and more events handled, we also intend to add a way to define notifications targeting every member of an organisation <em>except</em> some users (right now, you have to define the full list of people) as well as a way to edit an existing hook in the dashboard.]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
