SSL

Master Control Review Surface

Loading the live local MCP snapshot. Governance Operator can review and run governed actions on SSL.

Mutation enabledSSLLoading SnapshotAuto 30sUpdated Awaiting first syncFallback Snapshot0/5 Live SourcesCommercial surfaces remain mock-backed
SSL is in governed modeGovernance Operator can review and run privileged changes here. Mutation roles: Governance Operator.

SSL

Certificate lifecycle visibility for validation, issuance, renewal timing, and endpoint trust across governed engine surfaces.

3
Active Bindings
1
Validation Holds
1
Renewal Window
0
Revocations

Certificate Bindings

Wildcard and SAN lifecycle table for validation, issuance, and renewal windows.

3 Visible
Common NameEngineStatusCoverageAuthorityRenewalExpires
POD Engine AlphaIssuedWildcard plus admin SANPlatform CAAutomatic82 days
POD Engine BravoValidation pendingWildcard stagedPlatform CAAutomatic after issuanceWaiting on first issue
POD Engine CharlieRenewal windowWildcard plus admin SANPlatform CAAutomatic with review gate9 days

Certificate Posture

Selected binding context for trust state, validation path, and renewal readiness.

Issued
Issued and bound
DNS challenge passing
Automatic with prebuilt package
Frontend, admin, and API covered

Lifecycle Timeline

Recent issuance and renewal events for the selected certificate family.

Automatic
  • 01
    Issuance completedThe wildcard certificate was issued and applied to ingress without runtime interruption.Observed 19 days ago.
  • 02
    Validation records retainedDNS validation records stay visible for operator review and replay confidence.No renewal blockers are present.
  • 03
    Renewal package stagedA future renewal package is already attached to the billing and audit timeline.Next review begins in 52 days.

Binding Coverage

Endpoints and dependencies currently tied to the selected certificate.

Endpoint Trust
  • 01
    Frontend endpointhttps://acmeprints.example is bound through the wildcard certificate.Traffic remains green across the storefront edge.
  • 02
    Admin endpointhttps://admin.acmeprints.example is covered by the admin SAN binding.Governed sessions use the same certificate family.
  • 03
    API endpointhttps://api.acmeprints.example shares the same trust envelope.Token lease refresh does not require certificate changes.