Merge pull request 'route-proxy README: the node that runs a proxy carries public-acme (hq #258)' (#208) from docs/route-proxy-carries-public-acme into main
This commit was merged in pull request #208.
This commit is contained in:
@@ -27,6 +27,17 @@ No broker account, no own-secrets, no provisioner: the proxy neither mints a cre
|
|||||||
an event. It only reads the file the mesh writes. (Contrast `redis`, which mints passwords, and
|
an event. It only reads the file the mesh writes. (Contrast `redis`, which mints passwords, and
|
||||||
`cloudflare-dns`, which emits record events.)
|
`cloudflare-dns`, which emits record events.)
|
||||||
|
|
||||||
|
## Which issuer: the node that runs a proxy carries `public-acme`
|
||||||
|
|
||||||
|
`acme-ca` has two providers in a full mesh — `public-acme` (Let's Encrypt, a facts-only module that
|
||||||
|
runs nothing) and `step-ca` (the mesh's own authority, which also offers it so a lab without a public
|
||||||
|
issuer still has one). A proxy beside both resolves by co-location only once a pin names the module
|
||||||
|
(`pin <node> acme-ca <node> public-acme`, novox/hq #258); a proxy on another machine cannot resolve
|
||||||
|
at all until it is told. **So every node that runs a route-proxy is assigned `public-acme` too**: the
|
||||||
|
issuer is then on the proxy's own node, design 23's first rule answers, and `internal-acme-ca` has
|
||||||
|
one provider mesh-wide. Nothing runs for it; it is the statement "this machine's public issuer is
|
||||||
|
Let's Encrypt", on the machine that issues.
|
||||||
|
|
||||||
## How it ships the Go proxy
|
## How it ships the Go proxy
|
||||||
|
|
||||||
The proxy is a Go program, unlike the TypeScript tool-runtime modules. The canonical source is
|
The proxy is a Go program, unlike the TypeScript tool-runtime modules. The canonical source is
|
||||||
|
|||||||
Reference in New Issue
Block a user