憑證更新與輪替
資安SSL/TLS 憑證和 API 金鑰的自動化生命週期管理 — 到期提醒、自動更新、部署驗證和舊憑證撤銷。
systemapicli
為什麼需要 OSOP
憑證過期會導致服務中斷,手動管理容易遺漏。OSOP 定義憑證的完整生命週期流程,確保更新動作在到期前自動執行,並驗證新憑證的有效性。
Workflow Steps (5)
1
Monitor Certificate Expiry
system2
Request Renewal
api3
Validate New Certificate
system4
Deploy Certificate
cli5
TLS Connectivity Test
cicdConnections (5)
Monitor Certificate Expiry→Request Renewalconditionaldays_until_expiry <= 30
Request Renewal→Validate New Certificatesequential
Validate New Certificate→Deploy Certificatesequential
Deploy Certificate→TLS Connectivity Testsequential
TLS Connectivity Test→Deploy CertificatefallbackRollback to old cert
5
Steps
5
Connections
4
Node Types