From 16b4dc9ab9be99d228d97df5d0bb3f8b88fc6bfc Mon Sep 17 00:00:00 2001 From: jochen Date: Thu, 10 Sep 2026 21:12:48 +0200 Subject: [PATCH] step-ca: certify the machine the mesh reaches it at Its API certificate carried localhost only, so a proxy dialling the address the mesh handed over refused it on hostname verification. The names now compose from the machine the module was assigned to, which a manifest could not know and now does not have to (mesh-control ${machine:...}). Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF --- modules/step-ca/module.json | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/modules/step-ca/module.json b/modules/step-ca/module.json index f9f12b0..de3697b 100644 --- a/modules/step-ca/module.json +++ b/modules/step-ca/module.json @@ -57,7 +57,7 @@ "type": "file", "path": "/var/lib/mesh/step-ca/init.env", "mode": "0600", - "content": "DOCKER_STEPCA_INIT_PASSWORD=${secret:password}\n" + "content": "DOCKER_STEPCA_INIT_PASSWORD=${secret:password}\nDOCKER_STEPCA_INIT_DNS_NAMES=${machine:at},${machine:name},localhost,127.0.0.1\n" }, { "id": "root-cert-file", @@ -94,7 +94,6 @@ ], "env": { "DOCKER_STEPCA_INIT_NAME": "Mesh Internal CA", - "DOCKER_STEPCA_INIT_DNS_NAMES": "localhost,127.0.0.1", "DOCKER_STEPCA_INIT_ACME": "true", "DOCKER_STEPCA_INIT_REMOTE_MANAGEMENT": "false", "DOCKER_STEPCA_INIT_ROOT_FILE": "/run/secrets/root_ca.crt",