Pin new-certificate idempotent semantic (D4h: load-or-create, not always-create-new)
Summary
-
D4h pins the actual production semantic of
new-certificate: it's "ensure-or-create" (callsLoadOrCreateCertificate), NOT "always-rotate-cert" despite what the command name suggests. - The contract this protects: a regression making the command always rotate would silently destroy fleet-automation agents' identities each cycle (Ansible/Salt re-running
new-certificateidempotently breaks server trust pinning). -
Spawned production task (chip): clarify command semantic — rename to
ensure-certificate, OR add--forceflag for explicit rotation, OR change default behavior. The current naming/behavior mismatch is real operator UX confusion.
Why pin this semantic explicitly
show-config's "expires in N days new-certificate — reinforcing the operator's rotation expectation. Without an explicit pin, a future "fix" that adds always-rotate behavior would land silently and break every fleet-automation playbook that ever idempotently runs new-certificate.
Test plan
-
dotnet buildgreen -
CI passes D4h_NewCertificate_IsIdempotent_LoadsExistingCertOnRepeatCalls -
D4h asserts: 2× exit 0 + Thumbprint:/SubscriptionId:/CertsPath: labels present + second-run thumbprint case-insensitive equals first-run -
Existing 48 Linux E2E tests still pass