step-ca (the other acme-ca provider) already spells it correctly; route-
proxy's own template reads ${bound:acme-ca:roots}. Found live, assigning
public-acme for the first time tonight: the mesh refused the push outright
rather than composing a broken binding — 'route-proxy asks its acme-ca
binding for roots, and what answers it says ... root'. Empty stays empty:
a public CA's root is the system trust store already, per route-proxy's
own design (an empty ACME_CA_BUNDLE means exactly that).
20 lines
300 B
JSON
20 lines
300 B
JSON
{
|
|
"module": "public-acme",
|
|
"version": "1",
|
|
"slug": "pubacme",
|
|
"provides": [
|
|
{
|
|
"name": "acme-ca",
|
|
"scope": "mesh"
|
|
}
|
|
],
|
|
"serves": {
|
|
"acme-ca": {
|
|
"at": "acme-v02.api.letsencrypt.org",
|
|
"port": 443,
|
|
"path": "/directory",
|
|
"roots": ""
|
|
}
|
|
}
|
|
}
|