Merge pull request 'route-proxy README: the node that runs a proxy carries public-acme (hq #258)' (#208) from docs/route-proxy-carries-public-acme into main
This commit was merged in pull request #208.
This commit is contained in:
@@ -27,6 +27,17 @@ No broker account, no own-secrets, no provisioner: the proxy neither mints a cre
|
||||
an event. It only reads the file the mesh writes. (Contrast `redis`, which mints passwords, and
|
||||
`cloudflare-dns`, which emits record events.)
|
||||
|
||||
## Which issuer: the node that runs a proxy carries `public-acme`
|
||||
|
||||
`acme-ca` has two providers in a full mesh — `public-acme` (Let's Encrypt, a facts-only module that
|
||||
runs nothing) and `step-ca` (the mesh's own authority, which also offers it so a lab without a public
|
||||
issuer still has one). A proxy beside both resolves by co-location only once a pin names the module
|
||||
(`pin <node> acme-ca <node> public-acme`, novox/hq #258); a proxy on another machine cannot resolve
|
||||
at all until it is told. **So every node that runs a route-proxy is assigned `public-acme` too**: the
|
||||
issuer is then on the proxy's own node, design 23's first rule answers, and `internal-acme-ca` has
|
||||
one provider mesh-wide. Nothing runs for it; it is the statement "this machine's public issuer is
|
||||
Let's Encrypt", on the machine that issues.
|
||||
|
||||
## How it ships the Go proxy
|
||||
|
||||
The proxy is a Go program, unlike the TypeScript tool-runtime modules. The canonical source is
|
||||
|
||||
Reference in New Issue
Block a user