RootTrace

RootTrace / Integrations / Secret expiry

Endpoints & certificates

Expiry dates watched, so renewals are chores, not incidents.

Certificates and credentials expire on schedule and page on weekends. The collector watches certificate files on disk for days-remaining, with a warn threshold far enough out to fix calmly.

What RootTrace watches

Every reading is checked continuously; bad readings become grouped issues with the evidence attached. RootTrace also remembers whether it has seen the same incident before.

Warn and fail thresholds, prefilled

Sensible defaults out of the box, overridable per host with environment variables. No threshold spreadsheet required on day one.

Setup

secret expiry setup
$ export ROOTTRACE_SECRET_EXPIRY_PATH='/etc/roottrace/secret-expiry.json'

Read-only by architecture: no write path, no remediation executor, no inbound ports. Credential-like evidence is redacted before it leaves the host.

One collector, live in minutes

Everything on this page comes from the same read-only collector: one command per host, then point it at your targets.

install on any Linux host
$ # after adding the signed RootTrace dnf or apt repository:
sudo dnf install roottrace-collector  # apt: sudo apt install roottrace-collector
sudoedit /etc/roottrace/collector.env  # set ROOTTRACE_COLLECTOR_TOKEN and API URL
sudo roottrace-collector-setup apply
sudo systemctl enable --now roottrace-collector

Questions, answered honestly

How is this different from TLS certificate monitoring?

TLS checks probe live endpoints over the network. Secret expiry reads files and tracked dates, like the internal CA cert on disk or the API key that expires quarterly. No external probe can see those.

Is this safe to run next to production?

The collector is read-only by architecture, not by policy: there is no write path, no remediation executor, and no privileged mode to switch on. It sends short-lived outbound HTTPS requests, opens no inbound ports, and redacts credential-like evidence before anything leaves the host.

Do I need a separate agent for this?

No. One RootTrace collector per host covers every integration on this site: databases, web servers, containers, endpoints, and the Linux host itself, all from one signed package or container. You point it at targets with environment variables; there is nothing else to deploy.

Free on 5 hosts. Live in minutes.

Create a workspace, install one collector, and watch issues explain themselves.