Repository navigation
fix(domains): verify Cloud certificates on the serving edge - #1135
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
A Cloud provider can report SSL active while its edge serves the apex certificate for
www. Openship then reports HTTPS ready even though browsers reject it. Certificate renewal also treated an expiry timestamp as success without requiring a verified certificate.Verify the certificate actually served for the requested hostname, and feed that observation through the existing domain status and monitoring issues.
Changes
Verification
www, trust, expiry and stalled handshakes; public-address rejection is covered alongside the existing SSRF/safe-fetch tests.wwwhandling.The local full run hit setup/import timeouts in six API files under load. All 112 tests in those files passed separately with
--maxWorkers=1and unchanged timeouts. Focused TLS, renewal, database, and diagnostics regressions also passed.The observation path sends no HTTP request and does not recreate routes or restart services. Provider edge binding faults still require a provider repair. See
docs/cloud-https-health.mdfor job controls and behavior.Related issue
None — fixes from the deployment reliability audit requested by the maintainer.