DigiNews

Tech Watch by Johan Denoyer

← Back to articles

A Caddy Cert Expired Because systemd-resolved Was Selectively Broken

Quality: 8/10 Relevance: 9/10

Summary

An in-depth, log-driven case study of a 42-hour certificate renewal outage caused by a broken systemd-resolved DNS path affecting a single zone. The piece explains how DoT to NextDNS, a staging CA fallback, and a delayed renewal backoff combined to produce an untrusted endpoint, and it documents the final fix and lessons on DNS health, alerting, and configuration drift.

🚀 Service construit par Johan Denoyer