Files
hq/04-ISSUES/004-certificate-issuance-targets-production/00-report.md
T
jschoubben c0b35652d0 The numbering is the flow: decisions are 02, design is 03
papa-hq reads 01 research -> 03 decision -> 02 design. The order is a
scar, not a choice: 02-DESIGN existed from its initial commit, and when
adr/ was finally promoted on 2026-07-13 it took the next free number
rather than its place in the sequence. By then design was too settled to
renumber.

hal-hq was three commits old, so it is not. adr/ becomes 02-DECISIONS and
02-DESIGN becomes 03-DESIGN, and following the folder numbers now walks
the process in the order it happens: research produces a decision, the
decision authorises a design.

00-GENESIS becomes 00-META, matching papa's rename from the same
restructure.

Every path reference rewritten across documents, frontmatter, playbooks
and skills. All links resolve; all 58 frontmatter blocks parse and their
path fields still point at files that exist.
2026-08-23 18:05:11 +02:00

1.4 KiB

status, opened, located-in, fixed-by, amended-design
status opened located-in fixed-by amended-design
open 2026-08-22

004 — Certificate issuance always targets the authority's production endpoint

Symptom

The reverse proxy sets no staging endpoint for its certificate resolver. Issuance therefore goes to the public authority's production endpoint in every case, including experiments.

Why this matters

Production issuance is rate-limited per domain and per account. Every certificate experiment on a real node consumes quota that is not replenished quickly, and exhausting it is not recoverable by retrying — it removes the ability to issue a certificate anyone actually needs.

The consequence lands hardest on exactly the work most likely to iterate: standing up a new node, changing how names resolve, or testing the lab's certificate authority split (ADR 0016).

Evidence

  • The resolver configuration declares no staging endpoint.
  • Observed 2026-08-22.

Open questions

  • Should the endpoint be a node property — production for nodes serving real traffic, staging everywhere else — rather than a fixed proxy setting?
  • The lab issues its own certificates and so does not consume public quota at all. Does that make this a problem only for experiments run outside the lab, and therefore an argument for running them inside it?