route-proxy README: the node that runs a proxy carries public-acme (hq #258) #208

Merged
mesh-admin merged 1 commits from docs/route-proxy-carries-public-acme into main 2026-10-01 15:32:05 +00:00
+11
View File
@@ -27,6 +27,17 @@ No broker account, no own-secrets, no provisioner: the proxy neither mints a cre
an event. It only reads the file the mesh writes. (Contrast `redis`, which mints passwords, and
`cloudflare-dns`, which emits record events.)
## Which issuer: the node that runs a proxy carries `public-acme`
`acme-ca` has two providers in a full mesh — `public-acme` (Let's Encrypt, a facts-only module that
runs nothing) and `step-ca` (the mesh's own authority, which also offers it so a lab without a public
issuer still has one). A proxy beside both resolves by co-location only once a pin names the module
(`pin <node> acme-ca <node> public-acme`, novox/hq #258); a proxy on another machine cannot resolve
at all until it is told. **So every node that runs a route-proxy is assigned `public-acme` too**: the
issuer is then on the proxy's own node, design 23's first rule answers, and `internal-acme-ca` has
one provider mesh-wide. Nothing runs for it; it is the statement "this machine's public issuer is
Let's Encrypt", on the machine that issues.
## How it ships the Go proxy
The proxy is a Go program, unlike the TypeScript tool-runtime modules. The canonical source is