Files
hq/04-ISSUES/004-certificate-issuance-targets-production/00-report.md
T
jschoubben 333356cff3 Order the records the way the system is learned
Jochen asked whether the order made sense. It did not -- it followed when
things happened to be decided, which after consolidation is fictional anyway
since record 5 alone folds decisions taken across a week.

Concretely wrong before: the domain statement sat at 8, after five engineering
rules; the constitution was scattered across 5, 12 and 17; the tiers landed at
15, 16, 21 and 22 with process records in between.

Now it walks: what the mesh is (1-3), its tiers from the bottom up (4-8), what
runs on them and how it gets there (9-10), how it is built (11-16), how it is
checked (17-18), how we work (19-23).

Two things made this safe rather than free. It is a permutation, not a
compaction, so the renames go through temporary names -- otherwise two files
want one slot and one is lost. And the reference rewrite is a single
simultaneous pass, because almost every number moved into a slot another number
was vacating; replacing one at a time would have cascaded and pointed things at
the wrong record while still resolving.

Verified: 284 [ADR NNNN](path) links across the repository, all with matching
text and target.

The ordering principle is now stated in 19 rather than left implicit -- the
repository already said "the numbering is the flow" about its folders, and
there was no reason for the records to be the exception.
2026-08-28 23:30:42 +02:00

38 lines
1.3 KiB
Markdown

---
status: open
opened: 2026-08-22
located-in: []
fixed-by:
amended-design:
---
# 004 — Certificate issuance always targets the authority's production endpoint
## Symptom
The reverse proxy sets no staging endpoint for its certificate resolver. Issuance therefore
goes to the public authority's production endpoint in every case, including experiments.
## Why this matters
Production issuance is rate-limited per domain and per account. Every certificate experiment on
a real node consumes quota that is not replenished quickly, and exhausting it is not
recoverable by retrying — it removes the ability to issue a certificate anyone actually needs.
The consequence lands hardest on exactly the work most likely to iterate: standing up a new
node, changing how names resolve, or testing the lab's certificate authority split
([ADR 0016](../../02-DECISIONS/0016-the-lab.md)).
## Evidence
- The resolver configuration declares no staging endpoint.
- Observed 2026-08-22.
## Open questions
- Should the endpoint be a node property — production for nodes serving real traffic, staging
everywhere else — rather than a fixed proxy setting?
- The lab issues its own certificates and so does not consume public quota at all. Does that
make this a problem only for experiments run outside the lab, and therefore an argument for
running them inside it?