check_cluster_certificate_health
Scan TLS secrets and system certificates across clusters to detect expiring certificates, prevent service disruptions, and provide renewal recommendations with customizable thresholds.
Instructions
Scan for expiring certificates across the cluster to prevent service disruptions.
Scans TLS secrets, system certificates, and provides renewal recommendations.
Args:
warning_threshold_days: Days before expiration for warning (default: 30).
critical_threshold_days: Days before expiration for critical alert (default: 7).
include_system_certs: Include system certificates (default: True).
include_user_certs: Include user certificates (default: True).
namespaces: Namespaces to scan (default: all accessible).
certificate_types: Types to check: "tls", "ca", "client", "server" (default: all).
Returns:
Dict: Certificate health with expiration timeline, recommendations, and security findings.
Input Schema
TableJSON Schema
| Name | Required | Description | Default |
|---|---|---|---|
| warning_threshold_days | No | ||
| critical_threshold_days | No | ||
| include_system_certs | No | ||
| include_user_certs | No | ||
| namespaces | No | ||
| certificate_types | No |