route-proxy: the trust step skips the fetch when the CA names no roots to get #67

Merged
jschoubben merged 1 commits from fix/route-proxy-trust-skips-when-there-is-nothing-to-fetch into main 2026-09-25 16:15:09 +00:00
Owner

Composed ACME_ROOTS unconditionally from ${bound:acme-ca:roots} even when that field is empty — public-acme's own case, where an empty roots means "the system trust store", not "fetch from the bare authority host". The run-once step wget'd https://acme-v02.api.letsencrypt.org:443 (host, no path) for two minutes every apply and failed, blocking every resource after it — found live tonight, assigning route-proxy for the first time.

Carries the raw, uncomposed roots value alongside the composed URL (ACME_ROOTS_PATH) so the step can tell "nothing to fetch" apart from "the authority didn't answer". Empty copies the image's own system CA bundle to /ca/root.crt instead of fetching one, so ACME_CA_BUNDLE stays the one path it has always been rather than needing to become conditional itself.

Composed `ACME_ROOTS` unconditionally from `${bound:acme-ca:roots}` even when that field is empty — `public-acme`'s own case, where an empty roots means "the system trust store", not "fetch from the bare authority host". The run-once step `wget`'d `https://acme-v02.api.letsencrypt.org:443` (host, no path) for two minutes every apply and failed, blocking every resource after it — found live tonight, assigning route-proxy for the first time. Carries the raw, uncomposed roots value alongside the composed URL (`ACME_ROOTS_PATH`) so the step can tell "nothing to fetch" apart from "the authority didn't answer". Empty copies the image's own system CA bundle to `/ca/root.crt` instead of fetching one, so `ACME_CA_BUNDLE` stays the one path it has always been rather than needing to become conditional itself.
jschoubben added 1 commit 2026-09-25 16:15:05 +00:00
Composed ACME_ROOTS unconditionally from ${bound:acme-ca:roots} even when
that field is empty — public-acme's own case, where an empty roots means
'the system trust store', not 'fetch from the bare authority host'. The
run-once step wget'd https://acme-v02.api.letsencrypt.org:443 (host, no
path) for two minutes every apply and failed, blocking every resource
after it — found live tonight, assigning route-proxy for the first time.

Carries the raw, uncomposed roots value alongside the composed URL
(ACME_ROOTS_PATH) so the step can tell 'nothing to fetch' apart from 'the
authority didn't answer' — a distinction the composed URL alone cannot
make. Empty copies the image's own system CA bundle to /ca/root.crt
instead of fetching one, so ACME_CA_BUNDLE stays the one path it has
always been rather than needing to become conditional itself.
jschoubben merged commit cb38bf08a6 into main 2026-09-25 16:15:09 +00:00
jschoubben deleted branch fix/route-proxy-trust-skips-when-there-is-nothing-to-fetch 2026-09-25 16:15:10 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-catalog#67