Certificate Lifecycle Service  ·  View 18 of 21  ·  Operations

Observability and the Expiry Clock

Six signal families across emit, collect, store, consume and act — including the one that proves the machinery still works on a quiet day.

Editable source SVG draw.io All views
Emit Collect Store Consume Act Expiry clock Probe result observed not_after Divergence detector Observed index Shortest-life board Page under 7 days Renewal health Attempt outcome Attempt ledger Registry Escalation ladder 30 / 21 / 14 / 7 d Incident at first fail Issuance and signing CA metrics latency · rate limit OTel collector Metric store SLO dashboard p99 ≤ 250 ms Shift CA account Trust distribution Bundle version Report collector Coverage table Rotation readiness Block the rotation Discovery coverage Scan + CT watch Reconciler Unmanaged findings Coverage metric target ≥ 99.5% Owner + deadline Revocation reach Synthetic revoke canary, daily Propagation probe Reach history Propagation p95 ≤ 5 min Escalate soft-fail Observability and the Expiry Clock Application we own Interface / broker Data store Security / platform The expiry clock is raised from the probe, not from the registry. A daily synthetic issue-install-revoke canary is what proves the whole path still works on a day nothing has gone wrong. v 1.0 · owner Reliability Architecture · date 2026-09

The clock is observed, not computed

  • The expiry clock is raised from the probe's observed not_after, never from the registry's belief. Divergence between the two is itself a signal with its own alarm.
  • Renewal health is measured per attempt, not per certificate: a failing attempt at T-30 is an incident even though nothing has broken.

Canaries

  • A permanent short-lifetime certificate exercises the full renewal path continuously, because renewal machinery that has not run recently is not known to work.
  • A daily synthetic issue-install-revoke canary measures revocation propagation end to end, which is the only honest way to hold a 5-minute p95 target.

Standing metrics

  • Managed coverage ≥ 99.5% of discovered TLS endpoints; the unmanaged remainder named, owned and dated.
  • Certificates expiring while still serving: zero, treated as Sev-1 with a written review regardless of customer impact.
  • Registry-to-reality divergence ≤ 0.1% at any probe cycle (stated assumptions).