From 0651b6392650ba0ab5739781d2cb45b9bcb04910 Mon Sep 17 00:00:00 2001 From: jochens Date: Thu, 1 Oct 2026 17:31:58 +0200 Subject: [PATCH] route-proxy README: the node that runs a proxy carries public-acme (hq #258) --- modules/route-proxy/README.md | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/modules/route-proxy/README.md b/modules/route-proxy/README.md index 639024b..35e35ab 100644 --- a/modules/route-proxy/README.md +++ b/modules/route-proxy/README.md @@ -27,6 +27,17 @@ No broker account, no own-secrets, no provisioner: the proxy neither mints a cre an event. It only reads the file the mesh writes. (Contrast `redis`, which mints passwords, and `cloudflare-dns`, which emits record events.) +## Which issuer: the node that runs a proxy carries `public-acme` + +`acme-ca` has two providers in a full mesh — `public-acme` (Let's Encrypt, a facts-only module that +runs nothing) and `step-ca` (the mesh's own authority, which also offers it so a lab without a public +issuer still has one). A proxy beside both resolves by co-location only once a pin names the module +(`pin acme-ca public-acme`, novox/hq #258); a proxy on another machine cannot resolve +at all until it is told. **So every node that runs a route-proxy is assigned `public-acme` too**: the +issuer is then on the proxy's own node, design 23's first rule answers, and `internal-acme-ca` has +one provider mesh-wide. Nothing runs for it; it is the statement "this machine's public issuer is +Let's Encrypt", on the machine that issues. + ## How it ships the Go proxy The proxy is a Go program, unlike the TypeScript tool-runtime modules. The canonical source is