From 1c964cd571ba733630ced5103c47351a49ce9b19 Mon Sep 17 00:00:00 2001 From: jochen Date: Mon, 21 Sep 2026 22:53:29 +0200 Subject: [PATCH] route-proxy: the trust gate retries with a timeout and checks for a certificate; its images are declared artifacts (ADRs 0096, 0097, 0098) --- modules/route-proxy/module.json | 15 +++++++++++++-- 1 file changed, 13 insertions(+), 2 deletions(-) diff --git a/modules/route-proxy/module.json b/modules/route-proxy/module.json index 1e615e5..93be06e 100644 --- a/modules/route-proxy/module.json +++ b/modules/route-proxy/module.json @@ -74,7 +74,6 @@ "type": "container", "name": "route-proxy-trust", "run-once": true, - "image": "alpine@sha256:28bd5fe8b56d1bd048e5babf5b10710ebe0bae67db86916198a6eec434943f8b", "network": "host", "env-file": [ "/var/lib/route-proxy/acme.env" @@ -85,7 +84,7 @@ "args": [ "sh", "-c", - "wget -q --no-check-certificate -O /ca/root.crt \"$ACME_ROOTS\" && test -s /ca/root.crt" + "for i in $(seq 1 60); do wget -q -T 10 --no-check-certificate -O /ca/root.crt \"$ACME_ROOTS\" && grep -q 'BEGIN CERTIFICATE' /ca/root.crt && exit 0; sleep 2; done; echo \"the authority at $ACME_ROOTS did not serve its roots within two minutes\" >&2; exit 1" ] }, { @@ -112,6 +111,18 @@ } ], "build": { + "artifacts": [ + { + "name": "server", + "kind": "image", + "from": "Dockerfile" + }, + { + "name": "trust", + "kind": "upstream", + "from": "alpine@sha256:28bd5fe8b56d1bd048e5babf5b10710ebe0bae67db86916198a6eec434943f8b" + } + ], "on": [ { "arg": "GO_BASE",