IncidentTLSCertExpiringSoon

Severity: warning · Fires after: 1h · Rule: central/prometheus/rules/tls.yml

What it means

A public HTTPS endpoint's certificate expires in under 14 days.

Expression

(probe_ssl_earliest_cert_expiry - time()) / 86400 < 14

Fed by the cloudflare agent's public_tls blackbox probes (hosts/cloudflare/apps.alloy). probe_ssl_earliest_cert_expiry exists only for HTTPS probes, so this rule cannot accidentally match the plain-HTTP vhost probes.

Why it should normally never fire

These certificates are Cloudflare-managed and auto-renew ~30 days out. A 14-day warning therefore means renewal has already failed once. Treat it as a broken renewal, not as "time to renew".

The probe doubles as an end-to-end check of the whole edge path, since it goes through Cloudflare rather than to the origin.

First checks

# Days remaining per endpoint
curl -sG 'http://192.168.0.5:9090/api/v1/query' \
  --data-urlencode 'query=(probe_ssl_earliest_cert_expiry - time()) / 86400'

echo | openssl s_client -connect wikantik.com:443 -servername wikantik.com 2>/dev/null \
  | openssl x509 -noout -dates -issuer

Check the issuer: if it is no longer Cloudflare, something is terminating TLS that should not be.

How to clear

Resolve the renewal in the Cloudflare dashboard (SSL/TLS → Edge Certificates). The alert clears on the next probe after a new certificate is served.

Notes

Covered endpoints are listed explicitly in the public_tls exporter block: jakefear.com, maiiavorobiova.com, wikantik.com, wiki.wikantik.com. Target names carry a -tls suffix so their job names never collide with the origin vhost probes that EdgeVhostDown / CrafterVhostDown match on.

A new public hostname is not covered until it is added to that block.