The certificate is genuine, from Mesh Internal CA, and nothing on the workstation trusts it — verbatim the error the report gives. The public name on the same proxy verifies cleanly, which puts the fault exactly where the report puts it. What is in the way is not an assignment. `ca-trust` is merged in the catalogue and has never been registered with the mesh — 39 of 76 manifests are — so there is no module to assign. It dry-runs clean and needs no artifact built. Two findings from reproducing it, both their own issues: 157 — every routed name is published with an `.internal` alias that nothing serves. The hosts file says keycloak.novox.be.internal; the proxy serves keycloak.novox.internal and refuses the other by name. The first three names I tried came from the hosts file and failed with a TLS alert rather than a verification error, which pointed at a regression that had not happened. 158 — the proxy re-logs all 52 routes every two seconds, 31 times a minute. The one line that explained 157 sat between two of them. Also recorded, because it was nearly filed as a defect and is not one: step-ca publishes roots as /roots.pem, which is PEM, so ca-trust's fetch and its refuse-a-non-certificate guard are both right. Its other endpoint /roots returns JSON that contains the text the guard greps for, so the guard is sound only because of which path is published.
2.1 KiB
status, opened, located-in, fixed-by, amended-design
| status | opened | located-in | fixed-by | amended-design |
|---|---|---|---|---|
| open | 2026-09-30 |
158 — The proxy re-reads and re-logs every route it serves, every two seconds
What was observed
The route proxy on the control node logs the whole of what it serves about every two seconds — measured 2026-09-30, 31 times in sixty seconds, each line naming all 52 routes:
23:27:19 serving 52 route(s): autoconfig.novox.be, autoconfig.novox.internal, … www.praktijkdespiegel.be
23:27:21 serving 52 route(s): autoconfig.novox.be, autoconfig.novox.internal, … www.praktijkdespiegel.be
23:27:23 serving 52 route(s): autoconfig.novox.be, autoconfig.novox.internal, … www.praktijkdespiegel.be
Nothing is changing. The route set is identical every time.
Why it matters
It buries the only line that matters. Between two of those entries sits the one error that explained a failing name:
23:27:23 http: TLS handshake error from 10.10.0.3:33480:
no public route for "keycloak.novox.be.internal" in this mesh, so no certificate is asked for
One line of signal to roughly 5,000 characters of repetition, and the diagnosis it belonged to (issue 157) was found by grepping past it. A log that says the same true thing every two seconds is a log nobody reads, which is the same failure as one that says nothing — and it is the mesh's own accuracy rule pointed the other way: a report that is loud about the unchanging is not reporting.
Whether the re-read is also wasteful is secondary and unmeasured — it may be a cheap file stat. The logging is not in question.
Where to look
Not localised. The proxy is mesh-controller examples/route-proxy; whether it re-reads on a timer or on
a file watch, and whether it logs unconditionally or only on change, is the first thing to read. Saying
what changed — or saying nothing — is the behaviour wanted, and the mesh already has the rule written
down for its own reports: a log that is quiet on success and loud on failure reads as broken when it is
working, and one that is loud always reads as nothing.