apex / apex/up

Up chooses ineligible certificate from acm

未关闭
#835 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
主要语言
Go
星标
8.8k
派生
383
PR 合并指标
30 天内没有已合并 PR

描述

## Prerequisites

* [x] I am running the latest version. (`up upgrade`)
* [x] I searched to see if the issue already exists.
* [x] I inspected the verbose debug output with the `-v, --verbose` flag.
* [ ] Are you an Up Pro subscriber?

## Description

ApiDomainProduction fails to create.
Error:
```
Resource handler returned message: "Invalid request provided: The specified SSL certificate doesn't exist, isn't in us-east-1 region, isn't valid, or doesn't include a valid certificate chain. (Service: AmazonCloudFront; Status Code: 400; Error Code: InvalidViewerCertificate; Request ID: xxxxxxxxxxxx; Proxy: null) (Service: ApiGateway, Status Code: 400, Request ID: xxxxxxxxxxxx, Extended Request ID: null)" (RequestToken: xxxxxxxxxxxx, HandlerErrorCode: InvalidRequest)
```
Upon checking more details, I found that I have multiple certificates for same domain in my AWS Certificate Manager, out of which, one is **Eligible**, and rest are **Ineligible**, because somehow they failed to renew.
And in the cloudformation template, up chooses to pick the ineligible certificate somehow.
Although this is not the case always, I deployed the same config for other subdomain, and it worked fine. But this seems to be working randomly.


## Steps to Reproduce

Create a new certificate in your AWS Certificate Manager. Now that you have two certificates for a single domain (one is eligible and another ineligible), try deploying a new lambda function. Up will create all the resources except APIDomainProduction.

## Slack

Join us on Slack https://chat.apex.sh/

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。