Two changes to the reference proxy, both gaps found in tonight's cutover attempt:
Internal names get certificates from the mesh's own authority. An .internal alias was correctly refused a public certificate (no public CA can validate a private name) and then left plain-HTTP only. The mesh has two name spaces and two authorities (08-connectivity §2), so the proxy now takes an optional INTERNAL_ACME_DIRECTORY and dispatches at the TLS handshake by the question HostPolicy already answers: which authority may certify this name at all. Unset, nothing changes — internal aliases serve plain HTTP as before.
A route may name its target's scheme.scheme: https with optional insecure: true, for a backend that terminates TLS with its own certificate — Mailu's webmail front is the dependent. Everything else stays plain http on the private network, and an unknown scheme is skipped aloud rather than guessed at.
Tested: the full route-proxy suite, including new tests for both authorities' host policies, the https target, and an end-to-end insecure-https proxy round trip.
Two changes to the reference proxy, both gaps found in tonight's cutover attempt:
**Internal names get certificates from the mesh's own authority.** An `.internal` alias was correctly refused a public certificate (no public CA can validate a private name) and then left plain-HTTP only. The mesh has two name spaces and two authorities (08-connectivity §2), so the proxy now takes an optional `INTERNAL_ACME_DIRECTORY` and dispatches at the TLS handshake by the question HostPolicy already answers: which authority may certify this name at all. Unset, nothing changes — internal aliases serve plain HTTP as before.
**A route may name its target's scheme.** `scheme: https` with optional `insecure: true`, for a backend that terminates TLS with its own certificate — Mailu's webmail front is the dependent. Everything else stays plain http on the private network, and an unknown scheme is skipped aloud rather than guessed at.
Tested: the full route-proxy suite, including new tests for both authorities' host policies, the https target, and an end-to-end insecure-https proxy round trip.
Internal aliases were served over plain HTTP only — correctly refused a
public certificate (no public CA can validate a private name), and then
left with nothing. The mesh has two authorities for its two name spaces
(08-connectivity §2), so the proxy now takes an optional internal ACME
directory and dispatches at the handshake by the same question HostPolicy
already answers: which authority may certify this name at all.
A route may also say its target speaks https, with insecure for a backend
whose own certificate nothing would trust — the shape Mailu's webmail
front needs, and the exception: everything else the mesh hands this proxy
stays plain http on the private network.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Two changes to the reference proxy, both gaps found in tonight's cutover attempt:
Internal names get certificates from the mesh's own authority. An
.internalalias was correctly refused a public certificate (no public CA can validate a private name) and then left plain-HTTP only. The mesh has two name spaces and two authorities (08-connectivity §2), so the proxy now takes an optionalINTERNAL_ACME_DIRECTORYand dispatches at the TLS handshake by the question HostPolicy already answers: which authority may certify this name at all. Unset, nothing changes — internal aliases serve plain HTTP as before.A route may name its target's scheme.
scheme: httpswith optionalinsecure: true, for a backend that terminates TLS with its own certificate — Mailu's webmail front is the dependent. Everything else stays plain http on the private network, and an unknown scheme is skipped aloud rather than guessed at.Tested: the full route-proxy suite, including new tests for both authorities' host policies, the https target, and an end-to-end insecure-https proxy round trip.