Post B5FKYxH034MhXOjV7Q by cult@pony.social
(DIR) More posts by cult@pony.social
(DIR) Post #B5FKYxH034MhXOjV7Q by cult@pony.social
0 likes, 0 repeats
as a sort of early post-mortem of yesterday's tls expiration: I failed to figure out I currently have no monitoring for TLS expiration in place, that used to be on my DO account but I've removed it with a plan to replace that never materialized. So when the cert began ticking down the expiration I didn't exactly notice. Yesterday i was fighting the cert-manager for kubernetes quite a bit to get it issue a new cert, it seems my load-balancer is taking issue with the setup and not quite happy doing HTTP based cert validation. I'll have to setup some more robust monitoring tbh, and do a permanent fix for the cert-manager that isn't a stupid hack.
(DIR) Post #B5FPK9Fjj45C7Qtv6W by korkenzieher@pony.social
0 likes, 0 repeats
@cult can recommend prometheus blackbox exporter, if ur already using prometheus stack in the cluster.
(DIR) Post #B5WxEmvnzNhtZSVqpk by certkit@infosec.exchange
0 likes, 0 repeats
@cult If you'd like to offload this, we can do the renewal, distribution, and monitoring of all your certs.