monitor: read the ACME cache where it actually is, and report the soonest expiry !146

merged merged by cmc on 2026-09-01 05:19 UTC · krz/gitbay:monitor-cert-path into main

Discussion

cmc

Follow-up to !145, found while deploying it to bay1.

The cert check pointed at /var/lib/gitbay/autocert. The cache is /var/lib/gitbay/acme, so it reported n/a on every run and always had. This was invisible while the monitor logged nothing; !145 made it speak, and the n/a was the first thing it said.

It also took whichever filename sorted first, which says nothing about the certificate actually about to lapse. On bay1 that meant audit-labs.dev rather than gitbay.org. It now reports the soonest expiry across the cache and alerts under 21 days — inside Let's Encrypt's 30-day renewal window, so a stalled renewal surfaces while there is still time to act.

Verified on bay1 before committing: reports gitbay.org at 81 days, the soonest of 8 certificates, where the old script said n/a.

No Go code, so the suite is unaffected, but CI will confirm.

Ref #28