Katabarwa Labs
← All Azure apps

Secrets & certificates · Cert Sentinel

Get alerted before TLS certificates expire on Azure App Gateway and App Service

A daily digest of every TLS certificate that is expired, expiring, or unreadable, across the stores Azure leaves without native alerting.

Deploys as a managed application in your own subscription. No vendor backend, no data egress. Flat monthly fee, billed by Microsoft.

The gap

An expired TLS certificate takes production down hard, and the places certificates actually live in Azure, Application Gateway listeners and trusted roots, App Service uploads, API Management, have no native expiry alert. Teams find out from customers.

What it does
The daily digest: expired, expiring, and unreadable certificates across every covered store.
The daily digest: expired, expiring, and unreadable certificates across every covered store.
Per-certificate detail with the resource, listener, and days remaining.
Per-certificate detail with the resource, listener, and days remaining.
Thresholds and the Teams destination are plain app settings.
Thresholds and the Teams destination are plain app settings.
Honest about its limits
How it runs, and what it needs

A serverless function on a schedule, with a system-assigned managed identity, deployed into your subscription by the Azure Marketplace. Roles are granted by you after deployment with the one-line script in the package, so nothing runs until you say so. Every role it asks for, and why:

Reader enumerate gateways, App Service certificates, and API Management certificates and read their public data

Alerts go to the Teams webhook you configure. Nothing is sent anywhere else.

FAQ

Does any data leave my subscription?

No. The function runs in your subscription and writes only to your configured alert destination. Katabarwa Labs operates no backend and receives nothing.

How is it billed?

A flat monthly fee on your Azure bill through the Marketplace, plus the small consumption cost of the function itself. No per-resource or per-user pricing.

How do I remove it?

Delete the managed application from the Azure portal. Its resource group and identity go with it, and any role you granted can be removed the same way.

Where do I get support?

support@llmgraph.ai, or the support page.

Deploy Cert Sentinel in your subscription.

A daily digest of every TLS certificate that is expired, expiring, or unreadable, across the stores Azure leaves without native alerting.

Deploy from the Azure Marketplace