Security / REFERENCE BLUEPRINT

Expiry Sweep

Expired certificates are the most preventable outage in existence, and they still happen everywhere. This loop makes them structurally impossible: every credential with a clock on it is inventoried weekly, and anything inside 30 days gets a rotation PR with an owner attached.

DESIGN INTENT

This is documentation for a proposed implementation. No automation runs from this page. Commands, configuration, output and timing are illustrative; package availability and measured performance have not been verified here.

THE LOOP / 4 STEPS

From the first signal to the final action.

  1. 01

    TRIGGER

    cron Mon 09:00 IST weekly

  2. 02

    SWEEP

    ACM, KMS, GCP SA keys, Vault leases, custom cert paths

  3. 03

    GATE

    expiry < 30 days AND no rotation PR already open

  4. 04

    ACT

    rotation PR from runbook template + owner ping in Slack

01 / USAGE

How the intended workflow fits together

  1. 01

    Sweeps every credential source weekly and keeps a full inventory — the report shows what's healthy, not just what's dying.

  2. 02

    Inside 30 days: it opens the rotation PR from your runbook template and assigns the owner from resource tags.

  3. 03

    Zero-noise design: one PR per credential, deduplicated across weeks, escalating to a human ping only at 7 days.

02 / CONFIGURATION

Read the configuration contract

Each credential type maps to a rotation runbook. Unknown types get an inventory alert, not a PR.

Illustrative configuration. Adapt only after verifying the implementation, schema and service permissions.

# sweep.yaml
schedule: '0 9 * * 1'   # Mon IST
sources: [acm, kms, gcp-sa, vault]
extra_paths:
  - k8s://cert-manager/certificates
threshold: 30d
rotate:
  acm: runbooks/rotate-acm.md
  gcp-sa: runbooks/rotate-sa.md
notify: owner_from_tags   # falls back to #platform

03 / EVIDENCE

What an output could look like

This authored example describes the intended result format. It is not evidence that a live run occurred.

$ expiry-sweep report
swept 214 credentials across 4 sources
  ● 209 healthy (> 30d)
  ⚠ 4 rotation PRs open (oldest: 12d)
  🚨 1 at 6 days → escalated to @rahul
lapses in last 18 months: 0 ✓

04 / IMPLEMENTATION REFERENCE

Review the setup sketch

The original command sketch is preserved for design context. It is not a verified installation recipe. Confirm that the package or repository exists and review its implementation before running anything.

Show illustrative setup commands
brew install supraj/tap/expiry-sweep
expiry-sweep init --aws --gcp --vault https://vault.acme.dev