From 95a0a5672c84cc900aaf22c3ea828592f5bb6147 Mon Sep 17 00:00:00 2001 From: jochen Date: Fri, 25 Sep 2026 18:14:58 +0200 Subject: [PATCH] route-proxy: the trust step skips the fetch when the CA names no roots to get MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Composed ACME_ROOTS unconditionally from ${bound:acme-ca:roots} even when that field is empty — public-acme's own case, where an empty roots means 'the system trust store', not 'fetch from the bare authority host'. The run-once step wget'd https://acme-v02.api.letsencrypt.org:443 (host, no path) for two minutes every apply and failed, blocking every resource after it — found live tonight, assigning route-proxy for the first time. Carries the raw, uncomposed roots value alongside the composed URL (ACME_ROOTS_PATH) so the step can tell 'nothing to fetch' apart from 'the authority didn't answer' — a distinction the composed URL alone cannot make. Empty copies the image's own system CA bundle to /ca/root.crt instead of fetching one, so ACME_CA_BUNDLE stays the one path it has always been rather than needing to become conditional itself. --- modules/route-proxy/module.json | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/modules/route-proxy/module.json b/modules/route-proxy/module.json index 534970a..3e24339 100644 --- a/modules/route-proxy/module.json +++ b/modules/route-proxy/module.json @@ -67,7 +67,7 @@ "type": "file", "path": "/var/lib/route-proxy/acme.env", "mode": "0600", - "content": "ACME_DIRECTORY=https://${bound:acme-ca:at}:${bound:acme-ca:port}${bound:acme-ca:path}\nACME_ROOTS=https://${bound:acme-ca:at}:${bound:acme-ca:port}${bound:acme-ca:roots}\n" + "content": "ACME_DIRECTORY=https://${bound:acme-ca:at}:${bound:acme-ca:port}${bound:acme-ca:path}\nACME_ROOTS=https://${bound:acme-ca:at}:${bound:acme-ca:port}${bound:acme-ca:roots}\nACME_ROOTS_PATH=${bound:acme-ca:roots}\n" }, { "id": "trust", @@ -85,7 +85,7 @@ "args": [ "sh", "-c", - "for i in $(seq 1 60); do wget -q -T 10 --no-check-certificate -O /ca/root.crt \"$ACME_ROOTS\" && grep -q 'BEGIN CERTIFICATE' /ca/root.crt && exit 0; sleep 2; done; echo \"the authority at $ACME_ROOTS did not serve its roots within two minutes\" >&2; exit 1" + "if [ -z \"$ACME_ROOTS_PATH\" ]; then cp /etc/ssl/certs/ca-certificates.crt /ca/root.crt; exit 0; fi; for i in $(seq 1 60); do wget -q -T 10 --no-check-certificate -O /ca/root.crt \"$ACME_ROOTS\" && grep -q 'BEGIN CERTIFICATE' /ca/root.crt && exit 0; sleep 2; done; echo \"the authority at $ACME_ROOTS did not serve its roots within two minutes\" >&2; exit 1" ], "restart-on": [ "acme-env"