Released veep on PyPI. Watched the new-customer flow for the first time, end to end. pip install ran clean. VP.from_creds() worked. vp.ping() blew up with an SSL error.
The cert at https://api.vectorpanda.com had been live for weeks. It just didn't list api.vectorpanda.com in its SANs. Browser traffic against vectorpanda.com and www.vectorpanda.com worked fine because those WERE in the cert. The SDK pointed at api.vectorpanda.com because subdomain isolation seemed like the right call. The cert had been generated with a -d list that didn't include the subdomain I'd built the SDK to talk to.
certbot --expand on the rampfee proxy host re-issued with the missing SAN. SDK now connects. "Cert is up" and "cert covers the host the customer's actually pointed at" are two different green checks, and only one of them was on my deploy checklist.
