route-proxy: internal names are certified by the mesh's own authority

Two name spaces, two authorities (08-connectivity §2): a public name is
certified by a public CA, an internal one by the mesh's own. step-ca now
offers that second seat as internal-acme-ca beside its existing acme-ca,
and route-proxy requires both — the server dispatches by which authority
may certify the name at all, so an .internal alias stops being plain-HTTP
only without ever asking a public CA for a name it cannot validate.
This commit is contained in:
2026-09-25 20:36:41 +02:00
parent bfe99f8c78
commit 962cba7c04
2 changed files with 48 additions and 5 deletions
+40 -5
View File
@@ -18,10 +18,12 @@
"route": "/var/lib/route-proxy/routes/mesh.json"
},
"requires": [
"acme-ca"
"acme-ca",
"internal-acme-ca"
],
"binds": {
"acme-ca": "/var/lib/route-proxy/acme-ca.json"
"acme-ca": "/var/lib/route-proxy/acme-ca.json",
"internal-acme-ca": "/var/lib/route-proxy/internal-acme-ca.json"
},
"listens": [
{
@@ -69,6 +71,13 @@
"mode": "0600",
"content": "ACME_DIRECTORY=https://${bound:acme-ca:at}:${bound:acme-ca:port}${bound:acme-ca:path}\nACME_ROOTS=https://${bound:acme-ca:at}:${bound:acme-ca:port}${bound:acme-ca:roots}\nACME_ROOTS_PATH=${bound:acme-ca:roots}\n"
},
{
"id": "internal-acme-env",
"type": "file",
"path": "/var/lib/route-proxy/internal-acme.env",
"mode": "0600",
"content": "INTERNAL_ACME_DIRECTORY=https://${bound:internal-acme-ca:at}:${bound:internal-acme-ca:port}${bound:internal-acme-ca:path}\nINTERNAL_ACME_ROOTS=https://${bound:internal-acme-ca:at}:${bound:internal-acme-ca:port}${bound:internal-acme-ca:roots}\nINTERNAL_ACME_ROOTS_PATH=${bound:internal-acme-ca:roots}\n"
},
{
"id": "trust",
"type": "container",
@@ -91,6 +100,28 @@
"acme-env"
]
},
{
"id": "internal-trust",
"type": "container",
"name": "route-proxy-internal-trust",
"artifact": "trust",
"run-once": true,
"network": "host",
"env-file": [
"/var/lib/route-proxy/internal-acme.env"
],
"volumes": [
"/var/lib/route-proxy/ca:/ca"
],
"args": [
"sh",
"-c",
"if [ -z \"$INTERNAL_ACME_ROOTS_PATH\" ]; then cp /etc/ssl/certs/ca-certificates.crt /ca/internal-root.crt; exit 0; fi; for i in $(seq 1 60); do wget -q -T 10 --no-check-certificate -O /ca/internal-root.crt \"$INTERNAL_ACME_ROOTS\" && grep -q 'BEGIN CERTIFICATE' /ca/internal-root.crt && exit 0; sleep 2; done; echo \"the authority at $INTERNAL_ACME_ROOTS did not serve its roots within two minutes\" >&2; exit 1"
],
"restart-on": [
"internal-acme-env"
]
},
{
"id": "server",
"type": "container",
@@ -98,7 +129,8 @@
"artifact": "server",
"network": "host",
"env-file": [
"/var/lib/route-proxy/acme.env"
"/var/lib/route-proxy/acme.env",
"/var/lib/route-proxy/internal-acme.env"
],
"volumes": [
"/var/lib/route-proxy/routes:/routes:ro",
@@ -110,11 +142,14 @@
"LISTEN": ":80",
"TLS_LISTEN": ":443",
"ACME_CACHE": "/acme",
"ACME_CA_BUNDLE": "/ca/root.crt"
"ACME_CA_BUNDLE": "/ca/root.crt",
"INTERNAL_ACME_CA_BUNDLE": "/ca/internal-root.crt"
},
"restart-on": [
"trust",
"acme-env"
"acme-env",
"internal-trust",
"internal-acme-env"
]
}
],
+8
View File
@@ -8,12 +8,20 @@
{
"name": "acme-ca",
"scope": "mesh"
},
{
"name": "internal-acme-ca",
"scope": "mesh"
}
],
"serves": {
"acme-ca": {
"path": "/acme/acme/directory",
"roots": "/roots.pem"
},
"internal-acme-ca": {
"path": "/acme/acme/directory",
"roots": "/roots.pem"
}
},
"listens": [