Recommended Scenario

Dependency TLS/SSL certificate expiration

Check for expiring TLS certificates on your dependencies by advancing the system clock forward one day, one week, and one month. Detect certificates that will expire before they cause outages.

Experiment types

Time Travel

Targets

Dependencies

Length

5 minutes

How it works

How this Scenario works

This Scenario advances the system clock forward by one day, one week, and one month, which triggers certificate validation on connections to your dependencies. This reveals any dependency TLS certificates that will expire within those time windows—giving you advance warning even for certificates you don't directly control.

Use cases

Why run this Scenario?

  • Proactively identify expiring certificates on external dependencies before they cause cascading outages.
  • Validate that your services handle expired dependency certificates gracefully, with clear errors and alerts.
  • Detect dependencies where you have no control over certificate renewal, so you can plan mitigation strategies.
  • Verify that your dependency monitoring covers TLS certificate health, not just availability.
Result

What to expect when you run it

If a dependency's TLS certificate expires without renewal, the dependent service fails gracefully and alerts trigger immediately.

Avoid downtime. Use Gremlin to turn failure into resilience.

Gremlin empowers you to proactively root out failure before it causes downtime. See how you can harness chaos to build resilient systems by requesting a demo of Gremlin.

Product Hero ImageShape