Close cert provisioning correctness gaps
Several race and validity gaps could leave certificate provisioning stuck, unusable, or noisy: - Accept the HTTP-01 challenge only after the key authorization is committed, so the CA cannot hit the token before this instance can serve it and invalidate the order. - Persist challenge metadata under a blocking write-back lock; a row merely locked by a competing transaction no longer silently drops the accepted order. - Abandon a recovered VALID order and restart instead of issuing it with a freshly generated key that cannot match the existing cert. - Exclude rate-limited rows from the ten-minute stale reset so the resumable order survives the ACME cooldown. - Size the provisioning poll lease to exceed the max processing window so a released claim lock cannot let another worker process the same row concurrently. - Parse Retry-After as unsigned seconds and clamp overflow so malformed values fall back to the default cooldown instead of disabling it. - Normalize the acme_errors problem_type label to the RFC 8555 set to bound Prometheus cardinality. Signed-off-by: Bryan Frimin <bryan@probo.com>
This commit is contained in:
@@ -52,7 +52,7 @@ func TestNewMetrics_SharedRegistererDoesNotPanic(t *testing.T) {
|
||||
assert.Same(t, first.provisionSteps, second.provisionSteps)
|
||||
assert.Same(t, first.acmeErrors, second.acmeErrors)
|
||||
assert.Same(t, first.stepDuration, second.stepDuration)
|
||||
assert.Equal(t, first.acmeCooldown, second.acmeCooldown)
|
||||
assert.Same(t, first.acmeCooldown, second.acmeCooldown)
|
||||
}
|
||||
|
||||
func TestNewACMEError_RateLimited(t *testing.T) {
|
||||
|
||||
Reference in New Issue
Block a user