Certificate Rotation Routine

Rotate certs with a tested fallback and health checks.

  1. Issue new cert
  2. Stage to non-critical edge
  3. Validate chain and OCSP
  4. Rollout by region
  5. Keep previous cert for rollback window