Certificate Lifecycle Service · View 13 of 21 · Runtime
Why this view exists
- Messages 13 to 15 are the failure most certificate platforms cannot see: the certificate was issued, the secret was written, the task was marked complete, and the process never reloaded.
- The registry moves to SERVING only on message 12, which is written by the prober. Message 6 sets ISSUED and nothing more.
- Divergence at T-8 h on a 24-hour leaf is the escalation trigger; the same mechanism at T-30 d governs a 90-day public certificate.
Decisions
- The workload generates its own key and sends only a CSR, so no private key crosses this sequence at any point.
- Attestation is verified against the platform's own credential — a projected service-account token — rather than against a self-asserted name.
- The reload trigger is part of the renewal transaction, not a downstream courtesy.
Assumption
- Private leaf lifetime 24 hours, renewed at 8 hours remaining; issuance p99 ≤ 250 ms; renewal verified serving ≤ 10 minutes p95 after issuance.