public-acme: the roots field is named roots, not root #65

Merged
jschoubben merged 1 commits from fix/public-acme-field-name-matches-what-route-proxy-reads into main 2026-09-25 16:08:39 +00:00
Owner

step-ca (the other acme-ca provider) already spells it correctly; route-proxy's own template reads ${bound:acme-ca:roots}. Found live, assigning public-acme for the first time tonight: the mesh refused the push outright rather than composing a broken binding — "route-proxy asks its acme-ca binding for roots, and what answers it says ... root". Empty stays empty: a public CA's root is the system trust store already, per route-proxy's own design.

`step-ca` (the other `acme-ca` provider) already spells it correctly; `route-proxy`'s own template reads `${bound:acme-ca:roots}`. Found live, assigning `public-acme` for the first time tonight: the mesh refused the push outright rather than composing a broken binding — "route-proxy asks its acme-ca binding for roots, and what answers it says ... root". Empty stays empty: a public CA's root is the system trust store already, per route-proxy's own design.
jschoubben added 1 commit 2026-09-25 16:08:34 +00:00
step-ca (the other acme-ca provider) already spells it correctly; route-
proxy's own template reads ${bound:acme-ca:roots}. Found live, assigning
public-acme for the first time tonight: the mesh refused the push outright
rather than composing a broken binding — 'route-proxy asks its acme-ca
binding for roots, and what answers it says ... root'. Empty stays empty:
a public CA's root is the system trust store already, per route-proxy's
own design (an empty ACME_CA_BUNDLE means exactly that).
jschoubben merged commit 547937034f into main 2026-09-25 16:08:39 +00:00
jschoubben deleted branch fix/public-acme-field-name-matches-what-route-proxy-reads 2026-09-25 16:08:40 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-catalog#65