Post B5FKYxH034MhXOjV7Q by cult@pony.social
 (DIR) More posts by cult@pony.social
 (DIR) Post #B5FKYxH034MhXOjV7Q by cult@pony.social
       0 likes, 0 repeats
       
       as a sort of early post-mortem of yesterday's tls expiration: I failed to figure out I currently have no monitoring for TLS expiration in place, that used to be on my DO account but I've removed it with a plan to replace that never materialized. So when the cert began ticking down the expiration I didn't exactly notice. Yesterday i was fighting the cert-manager for kubernetes quite a bit to get it issue a new cert, it seems my load-balancer is taking issue with the setup and not quite happy doing HTTP based cert validation. I'll have to setup some more robust monitoring tbh, and do a permanent fix for the cert-manager that isn't a stupid hack.
       
 (DIR) Post #B5FPK9Fjj45C7Qtv6W by korkenzieher@pony.social
       0 likes, 0 repeats
       
       @cult can recommend prometheus blackbox exporter, if ur already using prometheus stack in the cluster.
       
 (DIR) Post #B5WxEmvnzNhtZSVqpk by certkit@infosec.exchange
       0 likes, 0 repeats
       
       @cult If you'd like to offload this, we can do the renewal, distribution, and monitoring of all your certs.