Skip to content

feat(worker): TCP and SSL certificate-expiry checks #64

Description

@amondnet

Context / Motivation

TCP and SSL certificate-expiry checks are declared in the README roadmap, and the config schema already accepts tcp and ssl as check kinds — but packages/core/src/check.ts:38 intentionally falls through to the HTTP path for both. A user who writes kind: tcp today silently gets an HTTP check.

This is table stakes against the alternatives:

The Cloudflare platform makes this feasible at the edge: Workers' connect() TCP sockets cover the TCP check, and certificate expiry can be read by inspecting the TLS handshake.

Proposed scope

  • Implement a real TCP check via Workers connect() — connect success/failure and connect latency.
  • Implement an SSL check that inspects the certificate and reports days-to-expiry, with a configurable expiry threshold that drives degraded before down.
  • Remove the HTTP fall-through in packages/core/src/check.ts for these kinds.
  • Record results through the existing check/history/status pipeline so they behave like HTTP checks.

Acceptance criteria

  • kind: tcp performs an actual TCP connection and yields a real status and latency.
  • kind: ssl reports certificate expiry and flags an approaching expiry per the configured threshold.
  • Both kinds produce history bars and status on the page, identical in behaviour to HTTP checks.
  • Connection failures and timeouts map to sensible statuses rather than errors.

Priority / Effort / Dependencies

  • Priority: p2
  • Effort: M (1–3 days)
  • Dependencies: none. Related to the alert condition DSL (certificate expiry is a natural condition input).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    effort:MEffort: 1-3 daysp2Priority 2 - Mediumtype:featureNew feature or request

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions