The ontology declared monitoring [cert-expiry] on the certificate type and a working checkCertExpiry probe existed, but checkdefaults had no cert-expiry builder and no certificate entities were seeded — so certificate expiry, a real failure mode, was invisible. Add a KindCertExpiry builder (dials the cert's hostname on :443 hourly, warns at 30d / crit at 7d) and seed certificate entities for the 20 public *.hubris.network routes plus uses-certificate edges from each ingress route.
16 KiB
16 KiB