Re: Removed Testflume from our Status Page

Replying/Commenting on:

While I don't really understand what's going on with the problem with Testflume that's been reported on the status page for the past month, the "official" word that there's no ETA for resolution makes me want to ask a couple questions that have been on my mind for a bit:

  1. Is Testflume just "down" and not really usable for the foreseeable future? That is, are staging-environment issuances just testing using other Test-CT-logs instead?
  2. Is whatever issue that happened on Testflume the kind of thing that can happen to the real Oak CT logs? That is, did Testflume expose some sort of fragility or something that we should "worry" about happening "for real"?

Thanks for indulging my curiousity.

3 Likes

That said I'd like to thank @jcjones wholeheartedly for removing Testflume from the status page! It was very, very confusing for many members, including letsdebug :stuck_out_tongue:

3 Likes

Hear! Hear!
Hear! Hear!
Hear! Hear!

:beers:

3 Likes

There’s a lot there. Probably @Phil is the best to answer in full, but in the meantime I’ll point to our post on ct-policy about the outage.

4 Likes

The add-*chain endpoints are dead, Jim. Testflume performed its intended functions fantastically. One of the functions it had was to serve as an early warning for the initial generation of public Let's Encrypt CT logs architectural failings.

Correct. Testflume is one of several staging/test capable CT logs available to the community.

Besides staging logs, the boulder repository maintains a stub CT log called ct-test-srv that we also run internally. When folks email us asking to add development CA roots, I typically point them at ct-test-srv.

Yes, Testflume performed wonderfully in this regard. Should you or the internet worry though, not in the slightest. There is excess redundancy in the CT ecosystem for logs to fall over.

Moving forward though, I have an internal design document where our team has been weighing the trade-offs for the next architectural upgrade. We have a few possible paths that we can proceed on, but have not yet chosen one.

Edit: When will there be a new log to replace Testflume? It depends on how fast we get our current internal projects finished. We're working on a lot of good things and they will be done when they're done. Not too slow, not too quick. :slight_smile:

5 Likes

gandalf

4 Likes

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.