Code RoommTLS certificate expired
MediumPrep Room Coding #2444

mTLS certificate expired

On-callSecurityMid–Senior~30 min

At 00:00 UTC, every service-to-service call to the internal 'identity' service starts failing with TLS handshake errors ('certificate has expired'), and login across the whole platform breaks. There was no deploy. Identity's own pods are up and healthy on their dashboards; the failures are all on the client side of mTLS. A cert-rotation automation that normally renews internal certs 30 days early logged a failure 31 days ago that nobody acted on. Triage and mitigate.

What a strong answer looks like

Stop the bleeding first (mitigate), then form hypotheses from real signals. Separate root cause from symptom, communicate status as you go, and close with what prevents a repeat.

0:00 of about 30 min
Which questions mattered is sealed until you submit. Telling you now would just be handing over the edge cases.