step-ca: certify the machine the mesh reaches it at
Its API certificate carried localhost only, so a proxy dialling the address the
mesh handed over refused it on hostname verification. The names now compose from
the machine the module was assigned to, which a manifest could not know and now
does not have to (mesh-control ${machine:...}).
Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
This commit is contained in:
@@ -57,7 +57,7 @@
|
||||
"type": "file",
|
||||
"path": "/var/lib/mesh/step-ca/init.env",
|
||||
"mode": "0600",
|
||||
"content": "DOCKER_STEPCA_INIT_PASSWORD=${secret:password}\n"
|
||||
"content": "DOCKER_STEPCA_INIT_PASSWORD=${secret:password}\nDOCKER_STEPCA_INIT_DNS_NAMES=${machine:at},${machine:name},localhost,127.0.0.1\n"
|
||||
},
|
||||
{
|
||||
"id": "root-cert-file",
|
||||
@@ -94,7 +94,6 @@
|
||||
],
|
||||
"env": {
|
||||
"DOCKER_STEPCA_INIT_NAME": "Mesh Internal CA",
|
||||
"DOCKER_STEPCA_INIT_DNS_NAMES": "localhost,127.0.0.1",
|
||||
"DOCKER_STEPCA_INIT_ACME": "true",
|
||||
"DOCKER_STEPCA_INIT_REMOTE_MANAGEMENT": "false",
|
||||
"DOCKER_STEPCA_INIT_ROOT_FILE": "/run/secrets/root_ca.crt",
|
||||
|
||||
Reference in New Issue
Block a user