Severity: warning · Fires after: 1h · Rule: central/prometheus/rules/tls.yml
A public HTTPS endpoint's certificate expires in under 14 days.
(probe_ssl_earliest_cert_expiry - time()) / 86400 < 14
Fed by the cloudflare agent's public_tls blackbox probes
(hosts/cloudflare/apps.alloy). probe_ssl_earliest_cert_expiry exists only for
HTTPS probes, so this rule cannot accidentally match the plain-HTTP vhost probes.
These certificates are Cloudflare-managed and auto-renew ~30 days out. A 14-day warning therefore means renewal has already failed once. Treat it as a broken renewal, not as "time to renew".
The probe doubles as an end-to-end check of the whole edge path, since it goes through Cloudflare rather than to the origin.
# Days remaining per endpoint
curl -sG 'http://192.168.0.5:9090/api/v1/query' \
--data-urlencode 'query=(probe_ssl_earliest_cert_expiry - time()) / 86400'
echo | openssl s_client -connect wikantik.com:443 -servername wikantik.com 2>/dev/null \
| openssl x509 -noout -dates -issuer
Check the issuer: if it is no longer Cloudflare, something is terminating TLS that should not be.
Resolve the renewal in the Cloudflare dashboard (SSL/TLS → Edge Certificates). The alert clears on the next probe after a new certificate is served.
Covered endpoints are listed explicitly in the public_tls exporter block:
jakefear.com, maiiavorobiova.com, wikantik.com, wiki.wikantik.com.
Target names carry a -tls suffix so their job names never collide with the
origin vhost probes that EdgeVhostDown / CrafterVhostDown match on.
A new public hostname is not covered until it is added to that block.