Skip to content

feat: load temporal certificates via autocert#3464

Merged
omBratteng merged 2 commits intomainfrom
feat-autocert
Jan 21, 2026
Merged

feat: load temporal certificates via autocert#3464
omBratteng merged 2 commits intomainfrom
feat-autocert

Conversation

@omBratteng
Copy link
Copy Markdown
Contributor

@omBratteng omBratteng commented Jan 20, 2026

Instead of using a hardcoded certificate, we use Autocert issue the pod a certificate automagically when starting, and it gets autoinjected to the pod.

This certificate has a default TTL of 30 days, but with it being pods and in kubernetes, it will almost always issue a new certificate for the pods.

Instead of using a hardcoded certificate, we use Autocert issue the pod a
certificate automagically when starting, and it gets autoinjected to the pod.

This certificate has a default TTL of 30 days, but with it being pods and in
kubernetes, it will almost always issue a new certificate for the pods.
@pulumi
Copy link
Copy Markdown

pulumi Bot commented Jan 20, 2026

🍹 The Update (preview) for dailydotdev/api/prod (at 66bee70) was successful.

Resource Changes

    Name                                                   Type                           Operation
~   vpc-native-clean-zombie-images-cron                    kubernetes:batch/v1:CronJob    update
~   vpc-native-post-analytics-clickhouse-cron              kubernetes:batch/v1:CronJob    update
~   vpc-native-hourly-notification-cron                    kubernetes:batch/v1:CronJob    update
~   vpc-native-deployment                                  kubernetes:apps/v1:Deployment  update
~   clickhouse-sync-clickhouse-sync-config                 kubernetes:core/v1:Secret      update
~   vpc-native-ws-deployment                               kubernetes:apps/v1:Deployment  update
~   vpc-native-validate-active-users-cron                  kubernetes:batch/v1:CronJob    update
+-  vpc-native-k8s-secret                                  kubernetes:core/v1:Secret      create-replacement
~   vpc-native-temporal-deployment                         kubernetes:apps/v1:Deployment  update
~   vpc-native-generate-search-invites-cron                kubernetes:batch/v1:CronJob    update
-   vpc-native-api-clickhouse-migration-60f50cdc           kubernetes:batch/v1:Job        delete
~   clickhouse-sync-clickhouse-sync                        kubernetes:apps/v1:Deployment  update
~   vpc-native-user-profile-updated-sync-cron              kubernetes:batch/v1:CronJob    update
~   vpc-native-personalized-digest-cron                    kubernetes:batch/v1:CronJob    update
-   vpc-native-api-db-migration-60f50cdc                   kubernetes:batch/v1:Job        delete
-   vpc-native-temporal-secret                             kubernetes:core/v1:Secret      delete
~   vpc-native-update-source-tag-view-cron                 kubernetes:batch/v1:CronJob    update
~   vpc-native-clean-zombie-users-cron                     kubernetes:batch/v1:CronJob    update
~   vpc-native-update-tag-recommendations-cron             kubernetes:batch/v1:CronJob    update
~   vpc-native-update-highlighted-views-cron               kubernetes:batch/v1:CronJob    update
~   vpc-native-calculate-top-readers-cron                  kubernetes:batch/v1:CronJob    update
~   vpc-native-update-views-cron                           kubernetes:batch/v1:CronJob    update
~   vpc-native-sync-subscription-with-cio-cron             kubernetes:batch/v1:CronJob    update
~   vpc-native-check-analytics-report-cron                 kubernetes:batch/v1:CronJob    update
~   vpc-native-update-current-streak-cron                  kubernetes:batch/v1:CronJob    update
~   vpc-native                                             pulumi:providers:kubernetes    update
~   vpc-native-daily-digest-cron                           kubernetes:batch/v1:CronJob    update
~   vpc-native-personalized-digest-deployment              kubernetes:apps/v1:Deployment  update
~   vpc-native-bg-deployment                               kubernetes:apps/v1:Deployment  update
~   vpc-native-update-source-public-threshold-cron         kubernetes:batch/v1:CronJob    update
~   vpc-native-clean-zombie-opportunities-cron             kubernetes:batch/v1:CronJob    update
~   vpc-native-clean-gifted-plus-cron                      kubernetes:batch/v1:CronJob    update
+   vpc-native-api-db-migration-47516ef7                   kubernetes:batch/v1:Job        create
~   vpc-native-clean-zombie-user-companies-cron            kubernetes:batch/v1:CronJob    update
~   vpc-native-clean-stale-user-transactions-cron          kubernetes:batch/v1:CronJob    update
~   vpc-native-generic-referral-reminder-cron              kubernetes:batch/v1:CronJob    update
~   vpc-native-update-tags-str-cron                        kubernetes:batch/v1:CronJob    update
~   vpc-native-private-deployment                          kubernetes:apps/v1:Deployment  update
+   vpc-native-api-clickhouse-migration-47516ef7           kubernetes:batch/v1:Job        create
~   vpc-native-post-analytics-history-day-clickhouse-cron  kubernetes:batch/v1:CronJob    update
~   vpc-native-update-trending-cron                        kubernetes:batch/v1:CronJob    update
... and 2 other changes

@omBratteng omBratteng merged commit 76b02d1 into main Jan 21, 2026
10 checks passed
@omBratteng omBratteng deleted the feat-autocert branch January 21, 2026 19:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant