Outage fix. Since 2026-10-03 ~08:30 every public name on novox served a certificate from Mesh Internal CA: route-proxy's acme-ca was bound to step-ca instead of public-acme.
Both modules offered acme-ca on novox, and route-proxy's pin (acme-ca from novox) names a node, not a module — so the choice depended on provider order, which changed when the controller restarted.
step-ca's own job (internal names) already runs through internal-acme-ca; route-proxy is the only acme-ca consumer. Removing the offer leaves public-acme as the sole provider. route-proxy's cache is per authority, so the previous Let's Encrypt certificates are found again without re-issuance.
Follow-up (controller): a pin should name (node, module), per to-be 23.
**Outage fix.** Since 2026-10-03 ~08:30 every public name on novox served a certificate from *Mesh Internal CA*: route-proxy's `acme-ca` was bound to step-ca instead of public-acme.
Both modules offered `acme-ca` on novox, and route-proxy's pin (`acme-ca from novox`) names a node, not a module — so the choice depended on provider order, which changed when the controller restarted.
step-ca's own job (internal names) already runs through `internal-acme-ca`; route-proxy is the only `acme-ca` consumer. Removing the offer leaves public-acme as the sole provider. route-proxy's cache is per authority, so the previous Let's Encrypt certificates are found again without re-issuance.
Follow-up (controller): a pin should name (node, module), per to-be 23.
step-ca and public-acme both offered acme-ca on novox, and route-proxy's pin names a node, not
a module — so which one certified the public names depended on provider order. After the
controller restart on 2026-10-03 it came out as step-ca, and every public site served a
certificate no browser trusts. step-ca's own names are already certified through
internal-acme-ca; acme-ca is the public authority's alone.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Outage fix. Since 2026-10-03 ~08:30 every public name on novox served a certificate from Mesh Internal CA: route-proxy's
acme-cawas bound to step-ca instead of public-acme.Both modules offered
acme-caon novox, and route-proxy's pin (acme-ca from novox) names a node, not a module — so the choice depended on provider order, which changed when the controller restarted.step-ca's own job (internal names) already runs through
internal-acme-ca; route-proxy is the onlyacme-caconsumer. Removing the offer leaves public-acme as the sole provider. route-proxy's cache is per authority, so the previous Let's Encrypt certificates are found again without re-issuance.Follow-up (controller): a pin should name (node, module), per to-be 23.