step-ca: certify the machine the mesh reaches it at

Its API certificate carried localhost only, so a proxy dialling the address the
mesh handed over refused it on hostname verification. The names now compose from
the machine the module was assigned to, which a manifest could not know and now
does not have to (mesh-control ${machine:...}).

Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
This commit is contained in:
2026-09-10 21:12:48 +02:00
parent d9fbc72565
commit 16b4dc9ab9
+1 -2
View File
@@ -57,7 +57,7 @@
"type": "file", "type": "file",
"path": "/var/lib/mesh/step-ca/init.env", "path": "/var/lib/mesh/step-ca/init.env",
"mode": "0600", "mode": "0600",
"content": "DOCKER_STEPCA_INIT_PASSWORD=${secret:password}\n" "content": "DOCKER_STEPCA_INIT_PASSWORD=${secret:password}\nDOCKER_STEPCA_INIT_DNS_NAMES=${machine:at},${machine:name},localhost,127.0.0.1\n"
}, },
{ {
"id": "root-cert-file", "id": "root-cert-file",
@@ -94,7 +94,6 @@
], ],
"env": { "env": {
"DOCKER_STEPCA_INIT_NAME": "Mesh Internal CA", "DOCKER_STEPCA_INIT_NAME": "Mesh Internal CA",
"DOCKER_STEPCA_INIT_DNS_NAMES": "localhost,127.0.0.1",
"DOCKER_STEPCA_INIT_ACME": "true", "DOCKER_STEPCA_INIT_ACME": "true",
"DOCKER_STEPCA_INIT_REMOTE_MANAGEMENT": "false", "DOCKER_STEPCA_INIT_REMOTE_MANAGEMENT": "false",
"DOCKER_STEPCA_INIT_ROOT_FILE": "/run/secrets/root_ca.crt", "DOCKER_STEPCA_INIT_ROOT_FILE": "/run/secrets/root_ca.crt",