--- status: open opened: 2026-08-22 located-in: [] fixed-by: amended-design: --- # 004 — Certificate issuance always targets the authority's production endpoint ## Symptom The reverse proxy sets no staging endpoint for its certificate resolver. Issuance therefore goes to the public authority's production endpoint in every case, including experiments. ## Why this matters Production issuance is rate-limited per domain and per account. Every certificate experiment on a real node consumes quota that is not replenished quickly, and exhausting it is not recoverable by retrying — it removes the ability to issue a certificate anyone actually needs. The consequence lands hardest on exactly the work most likely to iterate: standing up a new node, changing how names resolve, or testing the lab's certificate authority split ([ADR 0016](../../02-DECISIONS/0016-a-lab-node-is-a-virtual-machine.md)). ## Evidence - The resolver configuration declares no staging endpoint. - Observed 2026-08-22. ## Open questions - Should the endpoint be a node property — production for nodes serving real traffic, staging everywhere else — rather than a fixed proxy setting? - The lab issues its own certificates and so does not consume public quota at all. Does that make this a problem only for experiments run outside the lab, and therefore an argument for running them inside it?