From 3147fac08b9bda5523f667bdd456cd5c199915bc Mon Sep 17 00:00:00 2001 From: jochen Date: Fri, 25 Sep 2026 18:08:28 +0200 Subject: [PATCH] public-acme: the roots field is named roots, not root MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit step-ca (the other acme-ca provider) already spells it correctly; route- proxy's own template reads ${bound:acme-ca:roots}. Found live, assigning public-acme for the first time tonight: the mesh refused the push outright rather than composing a broken binding — 'route-proxy asks its acme-ca binding for roots, and what answers it says ... root'. Empty stays empty: a public CA's root is the system trust store already, per route-proxy's own design (an empty ACME_CA_BUNDLE means exactly that). --- modules/public-acme/module.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/modules/public-acme/module.json b/modules/public-acme/module.json index df25ce7..39e0e07 100644 --- a/modules/public-acme/module.json +++ b/modules/public-acme/module.json @@ -13,7 +13,7 @@ "at": "acme-v02.api.letsencrypt.org", "port": 443, "path": "/directory", - "root": "" + "roots": "" } } } -- 2.54.0