Skip to content

Jobs

The Jobs page displays all background operations processed by the platform — certificate issuance, renewals, deployments, discovery scans, CA refreshes, and more.

Navigation: Sidebar → Jobs

Jobs


ColumnDescription
Job IDUnique identifier
NameDescriptive name (e.g., “Issue cert for api.example.com”)
TypeJob category (see Job Types below)
StatusCurrent state: QUEUED, RUNNING, SUCCESS, FAILED
CA / StoreRelated CA or Store (if applicable)
AgentAgent that executed (or will execute) the job
Triggered ByWho initiated: username, “System”, or “Scheduler”
ScheduledWhen the job was created
StartedWhen execution began
CompletedWhen execution finished
DurationExecution time

TypeDescription
ISSUE_CERTCertificate issuance via a CA
RENEW_CERTCertificate renewal
REVOKE_CERTCertificate revocation
DEPLOY_CERTCertificate deployment to a store
CA_REFRESHInventory sync from a CA
DISCOVER_NETWORKNetwork-based TLS discovery scan
DISCOVER_STOREStore-level certificate discovery
DISCOVER_CACA-level certificate inventory comparison
VALIDATE_DEPLOYMENTPost-deployment validation check
BIND_CERTBind certificate to service endpoint

StatusColorMeaning
QUEUEDGrayJob created, waiting for execution
RUNNINGBlueCurrently being executed
SUCCESSGreenCompleted successfully
FAILEDRedExecution failed — see error details

Click any job row to see its full details:

FieldDescription
Job IDUnique identifier
NameOperation description
TypeJob type
StatusCurrent state
CA IDAssociated Certificate Authority
Store IDAssociated Certificate Store
Agent IDAgent that executed the job
Triggered ByInitiator (user, system, scheduler)
Scheduled AtJob creation time
Started AtExecution start time
Completed AtExecution end time
DurationTotal execution time

The input data provided to the job (e.g., CSR PEM for issuance, certificate ID for deployment).

For successful jobs:

{
"certificateId": "cert-abc123",
"serialNumber": "1A2B3C4D5E6F",
"externalRequestId": "ca-req-789"
}

For failed jobs:

{
"error": "Connection refused",
"details": "Unable to reach CA endpoint at https://ca.internal:9000",
"retryable": true
}
  • Retry — Re-queue a failed job (if retryable)
  • Cancel — Cancel a queued job (before execution starts)

  • Status filter — Show only QUEUED, RUNNING, SUCCESS, or FAILED jobs
  • Type filter — Filter by job type
  • Date range — Filter by scheduled/completed date
  • Search — Free text search by job name, ID, or related entity

QUEUED → RUNNING → SUCCESS
→ FAILED (→ retry → QUEUED)
  1. Job is created when an operation is triggered (manually or by scheduler)
  2. Platform assigns the job to the appropriate executor (agent or backend)
  3. Executor picks up the job and begins processing
  4. On completion, result is reported back
  5. Status updated to SUCCESS or FAILED
  6. Audit log entry created

Failed jobs with retryable: true can be retried:

  • Click Retry in the job detail view
  • The job re-enters QUEUED status
  • Default retry limit: 3 attempts
  • Exponential backoff between retries

Non-retryable failures (e.g., invalid credentials, policy violation) require manual intervention.


Some jobs are created automatically by the scheduler:

TriggerJob Created
CA refresh interval elapsedCA_REFRESH
Certificate enters renewal windowRENEW_CERT
Saved discovery scan cron firesDISCOVER_NETWORK
Auto-deploy after renewalDEPLOY_CERT
Agent heartbeat timeoutStatus update (not a job, but generates alert)

  • Check for FAILED jobs and investigate root causes
  • Monitor RUNNING jobs that have been executing for an unusually long time
  • Review job success rates by type
  • Identify recurring failures (same CA, same agent, same store)
  • Failed job count is surfaced on the Dashboard health panel
  • Configure alerts for job failures via Settings → Alerts & Notifications