Skip to content

Fix new-certificate semantic: CertsPath fallback + --force rotation + clearer description

Placeholder ppxd requested to merge fix/new-certificate-semantic into main

Summary

Three fixes bundled (all surfaced via Linux D4h E2E iterations):

  1. CertsPath fallback: create-instance + new-certificate flow no longer crashes with ArgumentException: path empty. Falls back to InstanceSelector.ResolveCertsPath when settings.CertsPath is empty.
  2. --force flag for actual rotation: deletes existing cert + lets LoadOrCreateCertificate regenerate. Default behavior unchanged (load-or-create). Subscription-id preserved across rotation.
  3. Description text clarified: "Ensure a Tentacle certificate exists (or rotate it with --force)".

Plus a clear post-rotation message reminding operators they MUST register --force (PR #265) to push the new thumbprint to the server's trust list.

Why this matters

Operators reading show-config's "expires in N days ⚠️ run new-certificate" warning were running the command, seeing same thumbprint, mistakenly thinking rotation succeeded — silent failure path leading to cert-expiry production outages.

Test plan

  • dotnet build green
  • CI: existing D4h E2E pin still passes (default load-or-create unchanged)
  • Future: add D4h2 asserting --force actually rotates (separate follow-up PR)

🤖 Generated with Claude Code

Merge request reports

Loading