papa-hq reads 01 research -> 03 decision -> 02 design. The order is a scar, not a choice: 02-DESIGN existed from its initial commit, and when adr/ was finally promoted on 2026-07-13 it took the next free number rather than its place in the sequence. By then design was too settled to renumber. hal-hq was three commits old, so it is not. adr/ becomes 02-DECISIONS and 02-DESIGN becomes 03-DESIGN, and following the folder numbers now walks the process in the order it happens: research produces a decision, the decision authorises a design. 00-GENESIS becomes 00-META, matching papa's rename from the same restructure. Every path reference rewritten across documents, frontmatter, playbooks and skills. All links resolve; all 58 frontmatter blocks parse and their path fields still point at files that exist.
38 lines
1.4 KiB
Markdown
38 lines
1.4 KiB
Markdown
---
|
|
status: open
|
|
opened: 2026-08-22
|
|
located-in: []
|
|
fixed-by:
|
|
amended-design:
|
|
---
|
|
|
|
# 004 — Certificate issuance always targets the authority's production endpoint
|
|
|
|
## Symptom
|
|
|
|
The reverse proxy sets no staging endpoint for its certificate resolver. Issuance therefore
|
|
goes to the public authority's production endpoint in every case, including experiments.
|
|
|
|
## Why this matters
|
|
|
|
Production issuance is rate-limited per domain and per account. Every certificate experiment on
|
|
a real node consumes quota that is not replenished quickly, and exhausting it is not
|
|
recoverable by retrying — it removes the ability to issue a certificate anyone actually needs.
|
|
|
|
The consequence lands hardest on exactly the work most likely to iterate: standing up a new
|
|
node, changing how names resolve, or testing the lab's certificate authority split
|
|
([ADR 0016](../../02-DECISIONS/0016-a-lab-node-is-a-virtual-machine.md)).
|
|
|
|
## Evidence
|
|
|
|
- The resolver configuration declares no staging endpoint.
|
|
- Observed 2026-08-22.
|
|
|
|
## Open questions
|
|
|
|
- Should the endpoint be a node property — production for nodes serving real traffic, staging
|
|
everywhere else — rather than a fixed proxy setting?
|
|
- The lab issues its own certificates and so does not consume public quota at all. Does that
|
|
make this a problem only for experiments run outside the lab, and therefore an argument for
|
|
running them inside it?
|