Stop pinning the expired wildcard-kamocrm-com secret

FixSecurityService
Shipped
July 22, 2026 at 2:26 PM UTC
Author
Kamo
Commit
68d68f5

wildcard-kamocrm-com was a legacy multi-SAN secret that cert-manager orphaned when its Certificate was repointed at a per-host secret. Nothing renewed it and it expired 2026-07-20, and pinning it here loaded that expired cert into Traefik's default store where it shadowed the live per-host certs. The api.kamocrm.com notes route now uses the auto-cert-managed default TLSStore, which already serves the live tls-api-kamocrm-com cert.

All changes

Like what you see shipping?

Every one of these updates lands in your workspace automatically. Start free and watch it grow week after week.

Start Free ForeverView Pricing