Certificate Lifecycle Service · View 05 of 21 · People and journeys
Where it actually fails
- Phase 2 is the dangerous one: the renewal has failed and the sentiment line is still calm, because a failed job is not an alert in most certificate tooling.
- The architecture cannot remove the failure. It can only move the moment of discovery, and every choice in this set exists to move it from T-0 to T-30.
The mechanism
- Renewal at one third of life remaining, so the window between first failure and expiry is 30 days on a public certificate and 8 hours on a workload leaf.
- A failed renewal is an open incident from the first failed attempt, escalating at 30 / 21 / 14 / 7 days against remaining validity rather than against job status.
- The last phase is verification by probe, because the fix is not complete when the certificate is issued.
Assumption
- Any managed certificate reaching 7 days remaining is treated as a page-worthy defect whether or not anything has broken. The threshold is invented and arguable.