Skip to content

observer: add CCADB CRL prober#8644

Open
jsha wants to merge 3 commits intomainfrom
crl-fetch-observer
Open

observer: add CCADB CRL prober#8644
jsha wants to merge 3 commits intomainfrom
crl-fetch-observer

Conversation

@jsha
Copy link
Contributor

@jsha jsha commented Feb 24, 2026

Prior work: letsencrypt/crl-monitor#88

Fixes #8618

@jsha jsha marked this pull request as ready for review February 24, 2026 06:38
@jsha jsha requested a review from a team as a code owner February 24, 2026 06:38
@jsha jsha requested a review from aarongable February 24, 2026 06:38
Copy link
Contributor

@aarongable aarongable left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I have a few minor comments about the code, but nothing big.

My major concern is that this simply doesn't feel like a prober. It's doing so much work, and has so many opportunities for failure, all of which get wrapped up in big accumulated errors. In my mind, the ideal prober is short, simple, only emits metrics (not meaningful logs), and we have alerts for every single metric it exposes. I understand that it is useful for this to live within boulder-observer, so we don't have to deploy and monitor Yet Another Component, but I'm registering my moderate discomfort with the complexity here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

boulder-observer: add tool to fetch all CRLs from CCADB

2 participants