apex / apex/up

Up chooses ineligible certificate from acm

オープン
#835 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る
主要言語
Go
スター
8.8k
フォーク
383
PR マージ指標
30日以内にマージされた PR はありません

説明

## Prerequisites

* [x] I am running the latest version. (`up upgrade`)
* [x] I searched to see if the issue already exists.
* [x] I inspected the verbose debug output with the `-v, --verbose` flag.
* [ ] Are you an Up Pro subscriber?

## Description

ApiDomainProduction fails to create.
Error:
```
Resource handler returned message: "Invalid request provided: The specified SSL certificate doesn't exist, isn't in us-east-1 region, isn't valid, or doesn't include a valid certificate chain. (Service: AmazonCloudFront; Status Code: 400; Error Code: InvalidViewerCertificate; Request ID: xxxxxxxxxxxx; Proxy: null) (Service: ApiGateway, Status Code: 400, Request ID: xxxxxxxxxxxx, Extended Request ID: null)" (RequestToken: xxxxxxxxxxxx, HandlerErrorCode: InvalidRequest)
```
Upon checking more details, I found that I have multiple certificates for same domain in my AWS Certificate Manager, out of which, one is **Eligible**, and rest are **Ineligible**, because somehow they failed to renew.
And in the cloudformation template, up chooses to pick the ineligible certificate somehow.
Although this is not the case always, I deployed the same config for other subdomain, and it worked fine. But this seems to be working randomly.


## Steps to Reproduce

Create a new certificate in your AWS Certificate Manager. Now that you have two certificates for a single domain (one is eligible and another ineligible), try deploying a new lambda function. Up will create all the resources except APIDomainProduction.

## Slack

Join us on Slack https://chat.apex.sh/

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。