Certificate Lifecycle Service · View 18 of 21 · Operations
The clock is observed, not computed
- The expiry clock is raised from the probe's observed not_after, never from the registry's belief. Divergence between the two is itself a signal with its own alarm.
- Renewal health is measured per attempt, not per certificate: a failing attempt at T-30 is an incident even though nothing has broken.
Canaries
- A permanent short-lifetime certificate exercises the full renewal path continuously, because renewal machinery that has not run recently is not known to work.
- A daily synthetic issue-install-revoke canary measures revocation propagation end to end, which is the only honest way to hold a 5-minute p95 target.
Standing metrics
- Managed coverage ≥ 99.5% of discovered TLS endpoints; the unmanaged remainder named, owned and dated.
- Certificates expiring while still serving: zero, treated as Sev-1 with a written review regardless of customer impact.
- Registry-to-reality divergence ≤ 0.1% at any probe cycle (stated assumptions).