Skip to content

feat: warn before a certificate expires - #1

Merged
JoeyHoutenbos merged 1 commit into
mainfrom
feat/ssl-expiration-warning
Sep 15, 2026
Merged

JoeyHoutenbos merged 1 commit into
mainfrom
feat/ssl-expiration-warning

Conversation

@JoeyHoutenbos

@JoeyHoutenbos JoeyHoutenbos commented Sep 15, 2026 •

Copy link
Copy Markdown

Why

An uptime check says nothing about a certificate that stopped renewing. It keeps serving the old one, valid, right up to the hour it expires — so the monitor stays green and the first signal is the outage itself.

Every monitor this operator creates has Verify SSL: Yes, but that only fires once the certificate is already invalid. ssl_expiration is the warning that arrives while there is still time to act, and nothing was setting it.

What this adds

SSL_EXPIRATION, the number of days before expiry that Better Stack warns on.

It follows the maintenance window in every respect:

  • Unset is unmanaged. The field is then neither sent nor compared, so a value someone set by hand stays put.
  • Values are validated at startup against the list Better Stack accepts (1, 2, 3, 7, 14, 30, 60). 10 looks reasonable and is not on it; better to hear that at startup than from a rejected create call.
  • A monitor without the warning is planned as an update, so existing monitors are brought in line on the next resync.

8 tests added, 76 green. deploy/operator.yaml sets it to 14 as an example.

What it does not cover

Recorded in the README too, because it is half the story:

  • Hostnames without a monitor are not covered — EXCLUDE_SUFFIXES leaves some out by design.
  • It warns about the consequence, not the cause. By the time it fires, issuance has already been failing for a while. An alert on the cause — a cert-manager Issuing condition that has been true for hours — fires earlier and covers more.

🤖 Generated with Claude Code

An uptime check notices nothing when renewal stalls. The old certificate stays
valid until the hour it expires, so the monitor is green right up to the point
where it is an outage.

SSL_EXPIRATION sets the ssl_expiration field on every monitor the operator
manages. Unset means unmanaged: the field is then left as it was, the same rule
as the maintenance window. Values are checked at startup against the list Better
Stack accepts, so a typo does not first surface as a rejected create call.

The README also records what this does not cover: hostnames without a monitor,
and that it warns about the consequence rather than the cause.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@JoeyHoutenbos
JoeyHoutenbos force-pushed the feat/ssl-expiration-warning branch from c9e8e33 to fdeb120 Compare September 15, 2026 19:21
@JoeyHoutenbos JoeyHoutenbos changed the title feat: waarschuw voor een certificaat dat bijna verloopt feat: warn before a certificate expires Sep 15, 2026
@JoeyHoutenbos
JoeyHoutenbos merged commit 9a59a4b into main Sep 15, 2026
2 checks passed
@JoeyHoutenbos
JoeyHoutenbos deleted the feat/ssl-expiration-warning branch September 15, 2026 19:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant