Recommended Scenario

Dependencies: Certificate Expiry

The Certificate Expiry test opens a secure connection to your dependency, retrieves the certificate chain, and validates that no certificates expire in the next 30 days. If there is no secure connection available, and therefore no certificates, this test will pass.

Experiment types

Certificate Expiry

Targets

Dependencies

Length

6 minutes

How it works

How this Scenario works

This test opens a secure connection to your dependency, retrieves the full certificate chain, and checks every certificate in that chain for an expiration date within the next 30 days. Dependencies that don't offer a secure connection have no certificates to check, so the test passes.

Use cases

Why run this Scenario?

Expired certificates can lead to sudden, high-profile outages. Tools like Certbot and ACME (Automatic Certificate Management Environment) helped automate certificate issuance and renewals, but teams still need to stay on top of upcoming expirations. This Scenario helps flag certificates that are expiring soon, giving you time to renew and replace.

  • Ensure operational awareness of certificate expirations.
  • Validate automation for certificate renewal.
  • Reduce outage risk from unnoticed expired certs.
Result

What to expect when you run it

If a TLS certificate for a dependency expires, the dependent service will surface clear errors and alert ops immediately.

Avoid downtime. Use Gremlin to turn failure into resilience.

Gremlin empowers you to proactively root out failure before it causes downtime. See how you can harness chaos to build resilient systems by requesting a demo of Gremlin.

Product Hero ImageShape