Skip to content

Pin new-certificate idempotent semantic (D4h: load-or-create, not always-create-new)

Summary

  • D4h pins the actual production semantic of new-certificate: it's "ensure-or-create" (calls LoadOrCreateCertificate), NOT "always-rotate-cert" despite what the command name suggests.
  • The contract this protects: a regression making the command always rotate would silently destroy fleet-automation agents' identities each cycle (Ansible/Salt re-running new-certificate idempotently breaks server trust pinning).
  • Spawned production task (chip): clarify command semantic — rename to ensure-certificate, OR add --force flag for explicit rotation, OR change default behavior. The current naming/behavior mismatch is real operator UX confusion.

Why pin this semantic explicitly

show-config's "expires in N days ⚠️" warning even recommends running new-certificate — reinforcing the operator's rotation expectation. Without an explicit pin, a future "fix" that adds always-rotate behavior would land silently and break every fleet-automation playbook that ever idempotently runs new-certificate.

Test plan

  • dotnet build green
  • CI passes D4h_NewCertificate_IsIdempotent_LoadsExistingCertOnRepeatCalls
  • D4h asserts: 2× exit 0 + Thumbprint:/SubscriptionId:/CertsPath: labels present + second-run thumbprint case-insensitive equals first-run
  • Existing 48 Linux E2E tests still pass

🤖 Generated with Claude Code

Merge request reports

Loading