watcher: warn of an expiring certificate on every TLS check (closes #204) #208

Merged
clawbot merged 1 commits from issue-204-expiry-warning-rule into next 2026-10-02 01:58:28 +02:00
1 Commits
Author SHA1 Message Date
sneak 1c2f1ec158 watcher: warn of an expiring certificate on every TLS check (closes #204)
check / check (push) Failing after 2m23s
An expiry warning was skipped when the last one for that hostname and
address was sent less than DNSWATCHER_TLS_INTERVAL ago. Each TLS check
runs after a DNS pass of varying length, so two checks can be less than
the interval apart, and a certificate about to expire was warned about on
every check or every other check, at random. TLS checks already start
once per interval, so the in-memory record of when each warning was sent
is removed and every check warns, as the README says.

The test that expected the second check to stay silent is replaced by one
that runs TLS checks on state built in the test, with no DNS.

Model: opus-5-5
2026-10-01 23:56:29 +00:00