step-ca offers a second seat, internal-acme-ca, beside its existing acme-ca — the same directory and roots, distinctly named so route-proxy can require both authorities at once (one bind per provision name). route-proxy binds it into INTERNAL_ACME_DIRECTORY/INTERNAL_ACME_CA_BUNDLE with its own trust step, mirroring the public one.
gitea's /api/internal refusal moves into its route contribution (ADR 0108: a route carries the policy applied to a request). The 2026-09-12 incident-response file in the predecessor's dynamic directory said its durable home is the mesh's routing — this is that. route-adapter skips the port-less contribution aloud (nothing to write); route-proxy enforces it on both the public name and the internal alias the moment it serves the route. The hand-authored file stands until the proxy it configures retires.
Companion to mesh-controller's route-proxy PR of the same branch name.
**step-ca offers a second seat, `internal-acme-ca`**, beside its existing `acme-ca` — the same directory and roots, distinctly named so route-proxy can require both authorities at once (one bind per provision name). route-proxy binds it into `INTERNAL_ACME_DIRECTORY`/`INTERNAL_ACME_CA_BUNDLE` with its own trust step, mirroring the public one.
**gitea's `/api/internal` refusal moves into its route contribution** (ADR 0108: a route carries the policy applied to a request). The 2026-09-12 incident-response file in the predecessor's dynamic directory said its durable home is the mesh's routing — this is that. route-adapter skips the port-less contribution aloud (nothing to write); route-proxy enforces it on both the public name and the internal alias the moment it serves the route. The hand-authored file stands until the proxy it configures retires.
Companion to mesh-controller's route-proxy PR of the same branch name.
Two name spaces, two authorities (08-connectivity §2): a public name is
certified by a public CA, an internal one by the mesh's own. step-ca now
offers that second seat as internal-acme-ca beside its existing acme-ca,
and route-proxy requires both — the server dispatches by which authority
may certify the name at all, so an .internal alias stops being plain-HTTP
only without ever asking a public CA for a name it cannot validate.
The 2026-09-12 incident response blocked /api/internal by hand in the
predecessor's dynamic directory, with a note that its durable home is the
mesh's routing. A route carries the policy applied to a request (ADR
0108), so the refusal now travels with the grant: route-proxy enforces
it on both the public name and the internal alias the moment it serves
this route, and the adapter skips it aloud (no port, nothing to write)
while the predecessor's own file still stands. The hand-authored file
retires with the proxy it configures.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
step-ca offers a second seat,
internal-acme-ca, beside its existingacme-ca— the same directory and roots, distinctly named so route-proxy can require both authorities at once (one bind per provision name). route-proxy binds it intoINTERNAL_ACME_DIRECTORY/INTERNAL_ACME_CA_BUNDLEwith its own trust step, mirroring the public one.gitea's
/api/internalrefusal moves into its route contribution (ADR 0108: a route carries the policy applied to a request). The 2026-09-12 incident-response file in the predecessor's dynamic directory said its durable home is the mesh's routing — this is that. route-adapter skips the port-less contribution aloud (nothing to write); route-proxy enforces it on both the public name and the internal alias the moment it serves the route. The hand-authored file stands until the proxy it configures retires.Companion to mesh-controller's route-proxy PR of the same branch name.