Certificate Lifecycle Service  ·  View 13 of 21  ·  Runtime

Renewal Is Not Done Until It Is Observed

The critical flow, including the alternate path where everything succeeded and the endpoint still has the old certificate.

Editable source SVG draw.io All views
Workload Order manager Attestation verifier AWS Private CA Mesh SDS Registry Endpoint prober Escalation 1. CSR + projected token 2. verify IRSA token 3. identity = ns/svc 4. issue, 24 h profile 5. leaf + chain 6. state = ISSUED 7. push leaf + chain 8. new secret 9. reload listener 10. TLS handshake 11. observed serial 12. state = SERVING 13. serial unchanged 14. divergence at T-8 h 15. re-push and re-trigger reload Critical Flow — Renewal Is Not Done Until It Is Observed Messages 13 to 15 are the alternate path, and the reason this view exists: the certificate was issued successfully, the secret was written successfully, and the workload is still presenting the old one. v 1.0 · owner Security Platform Architecture · date 2026-09

Why this view exists

  • Messages 13 to 15 are the failure most certificate platforms cannot see: the certificate was issued, the secret was written, the task was marked complete, and the process never reloaded.
  • The registry moves to SERVING only on message 12, which is written by the prober. Message 6 sets ISSUED and nothing more.
  • Divergence at T-8 h on a 24-hour leaf is the escalation trigger; the same mechanism at T-30 d governs a 90-day public certificate.

Decisions

  • The workload generates its own key and sends only a CSR, so no private key crosses this sequence at any point.
  • Attestation is verified against the platform's own credential — a projected service-account token — rather than against a self-asserted name.
  • The reload trigger is part of the renewal transaction, not a downstream courtesy.

Assumption

  • Private leaf lifetime 24 hours, renewed at 8 hours remaining; issuance p99 ≤ 250 ms; renewal verified serving ≤ 10 minutes p95 after issuance.