Cert Sentinel — App Gateway & App Service TLS Expiry
بواسطة Katabarwa Labs Inc.
Daily expiry alerts for App Gateway, App Service and APIM TLS certs Azure won't warn on.
An expired TLS certificate takes production down hard, and Azure does not natively near-expiry alert on most of the places certificates actually live. Native cert alerts cover only Front Door/CDN managed certs and Key Vault-stored certs — not App Gateway uploaded (BYOC) listener certs, not backend/end-to-end trust certs, and not App Service or API Management uploaded certs. The portal can't even display the expiry of an App Gateway BYOC cert.
Cert Sentinel is a managed application that runs in your own subscription and posts one daily digest of every TLS certificate that is expired, expiring soon, or unreadable — across exactly the stores Azure leaves uncovered:
- App Gateway frontend (BYOC) listener certs — the public cert is a PKCS7 bundle we parse to read the leaf's expiry.
- App Gateway backend / end-to-end trust certs.
- App Service uploaded certs and API Management certs.
Deliberately scoped off Key Vault certs (native events exist) and AFD/CDN managed certs (native alerts exist) so it complements, not duplicates, what you already have. Reader-only, metadata only, private keys never read. The digest goes only to a Teams webhook you configure; delete the managed app and every trace is gone.