Skip to content

Lcs 1184 auto renewal for ssl certs and enable ssl health check - #321

Merged
mrlockstar merged 2 commits into
mainfrom
LCS-1184-Auto-renewal-for-SSL-certs-and-enable-SSL-health-check
Oct 6, 2026
Merged

mrlockstar merged 2 commits into
mainfrom
LCS-1184-Auto-renewal-for-SSL-certs-and-enable-SSL-health-check

Conversation

@mrlockstar

@mrlockstar mrlockstar commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Description

This was based on a script from another project; however, it did not work the exact way we wanted it to so it was modified via AI and tested using the lungcs environment.

It was used to renew both the preprod and prod certificate (there was no risk to live service).

image

https://github.com/DFE-Digital/teacher-services-cloud/blob/main/.github/workflows/afd-domain-renewal.yml

Evidence if it working can be seen here: -

https://dev.azure.com/nhse-dtos/lung-cancer-screening/_build?definitionId=142&_a=summary

preprod
https://dev.azure.com/nhse-dtos/lung-cancer-screening/_build/results?buildId=46397&view=results

prod
https://dev.azure.com/nhse-dtos/lung-cancer-screening/_build/results?buildId=46388&view=results

Context

Type of changes

  • Refactoring (non-breaking change)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would change existing functionality)
  • Bug fix (non-breaking change which fixes an issue)

Checklist

  • I am familiar with the contributing guidelines
  • I have followed the code style of the project
  • I have added tests to cover my changes
  • I have updated the documentation accordingly
  • This PR is a result of pair or mob programming

Sensitive Information Declaration

To ensure the utmost confidentiality and protect your and others privacy, we kindly ask you to NOT including PII (Personal Identifiable Information) / PID (Personal Identifiable Data) or any other sensitive data in this PR (Pull Request) and the codebase changes. We will remove any PR that do contain any sensitive information. We really appreciate your cooperation in this matter.

  • I confirm that neither PII/PID nor sensitive data are included in this PR and the codebase changes.

@mrlockstar
mrlockstar force-pushed the LCS-1184-Auto-renewal-for-SSL-certs-and-enable-SSL-health-check branch 2 times, most recently from f9adf4c to 77a552e Compare October 2, 2026 10:16
The SSL certificates are semi managed in Front door and you can renew the certificates via the console; however, this does not happen automatically for the apec domain and instead a manual check needs to occur. Please note that this script is triggered off the ADO pipeline and uses the MI that is used to deploy the terraform in Azure.
@mrlockstar
mrlockstar force-pushed the LCS-1184-Auto-renewal-for-SSL-certs-and-enable-SSL-health-check branch from 77a552e to f184524 Compare October 2, 2026 10:18
Comment thread scripts/front-door/ssl-certificate-regeneration.sh Outdated
Comment thread scripts/front-door/ssl-certificate-regeneration.sh
Comment thread scripts/front-door/ssl-certificate-regeneration.sh Outdated
@mrlockstar
mrlockstar force-pushed the LCS-1184-Auto-renewal-for-SSL-certs-and-enable-SSL-health-check branch from 09768ba to 63cf8e8 Compare October 6, 2026 14:17
@mrlockstar
mrlockstar force-pushed the LCS-1184-Auto-renewal-for-SSL-certs-and-enable-SSL-health-check branch from 63cf8e8 to feb9740 Compare October 6, 2026 15:17
@sonarqubecloud

sonarqubecloud Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Quality Gate Passed Quality Gate passed

Issues
0 New issues
1 Accepted issue

Measures
0 Security Hotspots
No data about Coverage
0.0% Duplication on New Code

See analysis details on SonarQube Cloud

@mrlockstar
mrlockstar added this pull request to the merge queue Oct 6, 2026
Merged via the queue into main with commit f5709c6 Oct 6, 2026
13 checks passed
@mrlockstar
mrlockstar deleted the LCS-1184-Auto-renewal-for-SSL-certs-and-enable-SSL-health-check branch October 6, 2026 15:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants