route-proxy: internal names are certified by the mesh's own authority

Two name spaces, two authorities (08-connectivity §2): a public name is
certified by a public CA, an internal one by the mesh's own. step-ca now
offers that second seat as internal-acme-ca beside its existing acme-ca,
and route-proxy requires both — the server dispatches by which authority
may certify the name at all, so an .internal alias stops being plain-HTTP
only without ever asking a public CA for a name it cannot validate.
This commit is contained in:
2026-09-25 20:36:41 +02:00
parent bfe99f8c78
commit 962cba7c04
2 changed files with 48 additions and 5 deletions
+8
View File
@@ -8,12 +8,20 @@
{
"name": "acme-ca",
"scope": "mesh"
},
{
"name": "internal-acme-ca",
"scope": "mesh"
}
],
"serves": {
"acme-ca": {
"path": "/acme/acme/directory",
"roots": "/roots.pem"
},
"internal-acme-ca": {
"path": "/acme/acme/directory",
"roots": "/roots.pem"
}
},
"listens": [