step-ca: stop offering acme-ca, so public names are certified by public-acme

step-ca and public-acme both offered acme-ca on novox, and route-proxy's pin names a node, not
a module — so which one certified the public names depended on provider order. After the
controller restart on 2026-10-03 it came out as step-ca, and every public site served a
certificate no browser trusts. step-ca's own names are already certified through
internal-acme-ca; acme-ca is the public authority's alone.
This commit is contained in:
2026-10-03 10:54:43 +02:00
parent 6afc1160b6
commit 0778f8f0ae
-8
View File
@@ -5,20 +5,12 @@
"container-runtime" "container-runtime"
], ],
"provides": [ "provides": [
{
"name": "acme-ca",
"scope": "mesh"
},
{ {
"name": "internal-acme-ca", "name": "internal-acme-ca",
"scope": "mesh" "scope": "mesh"
} }
], ],
"serves": { "serves": {
"acme-ca": {
"path": "/acme/acme/directory",
"roots": "/roots.pem"
},
"internal-acme-ca": { "internal-acme-ca": {
"path": "/acme/acme/directory", "path": "/acme/acme/directory",
"roots": "/roots.pem" "roots": "/roots.pem"