Agent/auto_encrypt "leaf certificate watch fired" erroneously firing every couple seconds #10071
Labels
theme/connect
Anything related to Consul Connect, Service Mesh, Side Car Proxies
theme/consul-vault
Relating to Consul & Vault interactions
type/question
Not an "enhancement" or "bug". Please post on discuss.hashicorp
Overview of the Issue
With Agents configured with
auto_encrypt
along Server configured with Vault provider along Connect CA, Agents renew theirleaf
certificates every couple seconds or so, despite thenotAfter
timestamp being 72h in the future.Reproduction Steps
Steps to reproduce this issue, eg:
IntermediateCertTTL=336h
andRotationPeriod=168h
(Vault's
RootCertTTL
-pki/consul
CA - is several years)Consul info for both Client and Server
version 1.8.8 on both Server and Client
Operating system and Environment details
N/A (I believe)
Log Fragments
(mark the
notAfter
timestamp correctly being 72h in the future)The text was updated successfully, but these errors were encountered: