CloudSketch AI Logo
FeaturesTemplatesPricingEnterpriseAboutContactLog in
🌙☀️
Log inStart free
Home/Templates/DevOps & SRE

🛠️ DevOps & SRE · Flowchart

TLS Certificate Expiry Runbook

Renew a TLS certificate before it expires, or recover quickly when it already has.

More DevOps & SRE templates

Drawing diagram…

What this diagram shows

  • Automatic renewal is checked first
  • Covers both expiring and already-expired certificates
  • Ends with monitoring so it never surprises you again

Prompt used

TLS certificate expiry runbook flowchart: alert that a certificate expires in under 14 days, or users see certificate errors. Check if renewal is automatic (ACME/cert-manager). If automatic, find why renewal failed (DNS, HTTP challenge blocked, rate limit), fix and trigger renewal. If manual, request a new certificate from the CA, then install it on the load balancer or ingress. Verify the new expiry date and the full chain from outside. If already expired, treat as SEV2. Finish by adding expiry monitoring at 30 and 14 days.

Mermaid code
flowchart TD
  A(["Alert: cert expires in under 14 days<br/>or users see cert errors"]) --> B{"Already expired?"}
  B -->|"Yes"| C["Declare SEV2"]
  B -->|"No"| D{"Automatic renewal?"}
  C --> D
  D -->|"Yes, ACME / cert-manager"| E["Find why renewal failed:<br/>DNS, challenge blocked, rate limit"]
  E --> F["Fix and trigger renewal"]
  D -->|"No, manual"| G["Request new certificate from CA"]
  G --> H["Install on load balancer / ingress"]
  F --> I{"New expiry and full chain<br/>valid from outside?"}
  H --> I
  I -->|"No"| E
  I -->|"Yes"| J(["Add expiry alerts at 30 and 14 days"])

Related templates

FlowchartDevOps & SRE

GitOps Deployment Flow

How a code change reaches production with GitOps: CI builds and tests, the image tag is written to a config repo, and Argo CD syncs the cluster to match Git.

C4 ArchitectureProDevOps & SRE

Observability Stack (Metrics, Logs, Traces)

A complete observability setup: OpenTelemetry collects metrics, logs and traces from services, which are stored separately and viewed together in Grafana with alerting.

State MachineDevOps & SRE

Incident Lifecycle

The stages of a production incident from the first alert to the postmortem, with severity escalation along the way.

SequenceDevOps & SRE

Incident Response Sequence

Who does what when production breaks: monitoring pages the on-call engineer, an incident channel is opened, customers are updated and the fix is rolled out.

DeploymentProDevOps & SRE

Blue-Green Deployment

A blue-green setup where a new version is deployed next to the live one and traffic is switched only after it passes checks, allowing instant rollback.

FlowchartDevOps & SRE

Infrastructure as Code Pipeline

How infrastructure changes are made safely with Terraform: plan on pull request, policy checks, approval, apply and drift detection.