Files
hq/04-ISSUES/004-certificate-issuance-targets-production/00-report.md
T
jschoubben 5e83ac2c22 Consolidate: 65 decision records to 52
Jochen: a normal application has 3-5 ADRs, maybe 10 for a large one, and we are
at 65. Fair, and the cause is mine -- I recorded every FINDING as a decision
rather than every fork in the road.

Two merges, both cases where one decision had been split across many records
because it was taken over several days rather than at once.

0019 absorbs ten records about how this repository works: what it is and that
it is public, the folder flow, the two design layers, the issue front door,
status in frontmatter, playbooks, the naming rule, the product name. Those were
never ten decisions -- they were one, seen from ten angles as the repository
took shape.

0016 absorbs the five about the lab: a node is a virtual machine, a router is
scenery, a scenario declares the underlay, a scenario is a closed address
space, and the two scenario classes. Same pattern -- one design, split by the
order it was worked out in.

The consolidated 0019 also raises the bar for what earns a record, since that
is what produced 65: a record is warranted when there is a genuine fork -- a
direction reversed, an alternative that will be proposed again, something
contested. A finding is not a decision, and a bug is certainly not. Everything
else belongs in the design document where the reasoning is actually read.

The checker earned its place here. Deleting nine records left 13 dangling links
across the repository and it named every one, including in AGENTS.md. Nothing
was found by reading.

Remaining clusters worth the same treatment: the host (8 records), delivery
(5), modules (6), connectivity (4), substrate and control plane (4). That would
be 52 down to roughly 30.
2026-08-28 18:53:19 +02:00

1.3 KiB

status, opened, located-in, fixed-by, amended-design
status opened located-in fixed-by amended-design
open 2026-08-22

004 — Certificate issuance always targets the authority's production endpoint

Symptom

The reverse proxy sets no staging endpoint for its certificate resolver. Issuance therefore goes to the public authority's production endpoint in every case, including experiments.

Why this matters

Production issuance is rate-limited per domain and per account. Every certificate experiment on a real node consumes quota that is not replenished quickly, and exhausting it is not recoverable by retrying — it removes the ability to issue a certificate anyone actually needs.

The consequence lands hardest on exactly the work most likely to iterate: standing up a new node, changing how names resolve, or testing the lab's certificate authority split (ADR 0016).

Evidence

  • The resolver configuration declares no staging endpoint.
  • Observed 2026-08-22.

Open questions

  • Should the endpoint be a node property — production for nodes serving real traffic, staging everywhere else — rather than a fixed proxy setting?
  • The lab issues its own certificates and so does not consume public quota at all. Does that make this a problem only for experiments run outside the lab, and therefore an argument for running them inside it?