Two name spaces, two authorities (08-connectivity §2): a public name is certified by a public CA, an internal one by the mesh's own. step-ca now offers that second seat as internal-acme-ca beside its existing acme-ca, and route-proxy requires both — the server dispatches by which authority may certify the name at all, so an .internal alias stops being plain-HTTP only without ever asking a public CA for a name it cannot validate.
185 lines
5.3 KiB
JSON
185 lines
5.3 KiB
JSON
{
|
|
"module": "route-proxy",
|
|
"version": "1",
|
|
"slug": "rproxy",
|
|
"capabilities": [
|
|
"container-runtime"
|
|
],
|
|
"provides": [
|
|
{
|
|
"name": "route",
|
|
"scope": "mesh"
|
|
}
|
|
],
|
|
"serves": {
|
|
"route": {}
|
|
},
|
|
"receives": {
|
|
"route": "/var/lib/route-proxy/routes/mesh.json"
|
|
},
|
|
"requires": [
|
|
"acme-ca",
|
|
"internal-acme-ca"
|
|
],
|
|
"binds": {
|
|
"acme-ca": "/var/lib/route-proxy/acme-ca.json",
|
|
"internal-acme-ca": "/var/lib/route-proxy/internal-acme-ca.json"
|
|
},
|
|
"listens": [
|
|
{
|
|
"port": 80,
|
|
"protocol": "tcp",
|
|
"from": "anywhere",
|
|
"why": "public HTTP, and the ACME HTTP-01 challenge answered at the name being certified"
|
|
},
|
|
{
|
|
"port": 443,
|
|
"protocol": "tcp",
|
|
"from": "anywhere",
|
|
"why": "public HTTPS for every name the mesh routes here"
|
|
}
|
|
],
|
|
"resources": [
|
|
{
|
|
"id": "state",
|
|
"type": "directory",
|
|
"path": "/var/lib/route-proxy",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "routes-dir",
|
|
"type": "directory",
|
|
"path": "/var/lib/route-proxy/routes",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "acme-cache",
|
|
"type": "directory",
|
|
"path": "/var/lib/route-proxy/acme",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "ca-dir",
|
|
"type": "directory",
|
|
"path": "/var/lib/route-proxy/ca",
|
|
"mode": "0755"
|
|
},
|
|
{
|
|
"id": "acme-env",
|
|
"type": "file",
|
|
"path": "/var/lib/route-proxy/acme.env",
|
|
"mode": "0600",
|
|
"content": "ACME_DIRECTORY=https://${bound:acme-ca:at}:${bound:acme-ca:port}${bound:acme-ca:path}\nACME_ROOTS=https://${bound:acme-ca:at}:${bound:acme-ca:port}${bound:acme-ca:roots}\nACME_ROOTS_PATH=${bound:acme-ca:roots}\n"
|
|
},
|
|
{
|
|
"id": "internal-acme-env",
|
|
"type": "file",
|
|
"path": "/var/lib/route-proxy/internal-acme.env",
|
|
"mode": "0600",
|
|
"content": "INTERNAL_ACME_DIRECTORY=https://${bound:internal-acme-ca:at}:${bound:internal-acme-ca:port}${bound:internal-acme-ca:path}\nINTERNAL_ACME_ROOTS=https://${bound:internal-acme-ca:at}:${bound:internal-acme-ca:port}${bound:internal-acme-ca:roots}\nINTERNAL_ACME_ROOTS_PATH=${bound:internal-acme-ca:roots}\n"
|
|
},
|
|
{
|
|
"id": "trust",
|
|
"type": "container",
|
|
"name": "route-proxy-trust",
|
|
"artifact": "trust",
|
|
"run-once": true,
|
|
"network": "host",
|
|
"env-file": [
|
|
"/var/lib/route-proxy/acme.env"
|
|
],
|
|
"volumes": [
|
|
"/var/lib/route-proxy/ca:/ca"
|
|
],
|
|
"args": [
|
|
"sh",
|
|
"-c",
|
|
"if [ -z \"$ACME_ROOTS_PATH\" ]; then cp /etc/ssl/certs/ca-certificates.crt /ca/root.crt; exit 0; fi; for i in $(seq 1 60); do wget -q -T 10 --no-check-certificate -O /ca/root.crt \"$ACME_ROOTS\" && grep -q 'BEGIN CERTIFICATE' /ca/root.crt && exit 0; sleep 2; done; echo \"the authority at $ACME_ROOTS did not serve its roots within two minutes\" >&2; exit 1"
|
|
],
|
|
"restart-on": [
|
|
"acme-env"
|
|
]
|
|
},
|
|
{
|
|
"id": "internal-trust",
|
|
"type": "container",
|
|
"name": "route-proxy-internal-trust",
|
|
"artifact": "trust",
|
|
"run-once": true,
|
|
"network": "host",
|
|
"env-file": [
|
|
"/var/lib/route-proxy/internal-acme.env"
|
|
],
|
|
"volumes": [
|
|
"/var/lib/route-proxy/ca:/ca"
|
|
],
|
|
"args": [
|
|
"sh",
|
|
"-c",
|
|
"if [ -z \"$INTERNAL_ACME_ROOTS_PATH\" ]; then cp /etc/ssl/certs/ca-certificates.crt /ca/internal-root.crt; exit 0; fi; for i in $(seq 1 60); do wget -q -T 10 --no-check-certificate -O /ca/internal-root.crt \"$INTERNAL_ACME_ROOTS\" && grep -q 'BEGIN CERTIFICATE' /ca/internal-root.crt && exit 0; sleep 2; done; echo \"the authority at $INTERNAL_ACME_ROOTS did not serve its roots within two minutes\" >&2; exit 1"
|
|
],
|
|
"restart-on": [
|
|
"internal-acme-env"
|
|
]
|
|
},
|
|
{
|
|
"id": "server",
|
|
"type": "container",
|
|
"name": "route-proxy",
|
|
"artifact": "server",
|
|
"network": "host",
|
|
"env-file": [
|
|
"/var/lib/route-proxy/acme.env",
|
|
"/var/lib/route-proxy/internal-acme.env"
|
|
],
|
|
"volumes": [
|
|
"/var/lib/route-proxy/routes:/routes:ro",
|
|
"/var/lib/route-proxy/acme:/acme",
|
|
"/var/lib/route-proxy/ca:/ca:ro"
|
|
],
|
|
"env": {
|
|
"ROUTES": "/routes/mesh.json",
|
|
"LISTEN": ":80",
|
|
"TLS_LISTEN": ":443",
|
|
"ACME_CACHE": "/acme",
|
|
"ACME_CA_BUNDLE": "/ca/root.crt",
|
|
"INTERNAL_ACME_CA_BUNDLE": "/ca/internal-root.crt"
|
|
},
|
|
"restart-on": [
|
|
"trust",
|
|
"acme-env",
|
|
"internal-trust",
|
|
"internal-acme-env"
|
|
]
|
|
}
|
|
],
|
|
"build": {
|
|
"artifacts": [
|
|
{
|
|
"name": "server",
|
|
"kind": "image",
|
|
"from": "Dockerfile",
|
|
"context": {
|
|
"repository": "https://git.novox.be/novox/mesh-controller.git",
|
|
"ref": "main"
|
|
}
|
|
},
|
|
{
|
|
"name": "trust",
|
|
"kind": "upstream",
|
|
"from": "alpine@sha256:28bd5fe8b56d1bd048e5babf5b10710ebe0bae67db86916198a6eec434943f8b"
|
|
}
|
|
],
|
|
"on": [
|
|
{
|
|
"arg": "GO_BASE",
|
|
"image": "golang@sha256:699337d620559a59b4a2bb298ad59611e535d2ee755a34cf2d2a98f37578dc80"
|
|
},
|
|
{
|
|
"arg": "ALPINE_BASE",
|
|
"image": "alpine@sha256:d9e853e87e55526f6b2917df91a2115c36dd7c696a35be12163d44e6e2a4b6bc"
|
|
}
|
|
]
|
|
}
|
|
}
|