route-proxy: a second authority for internal names, and https targets #64

Merged
jschoubben merged 1 commits from feat/route-proxy-internal-acme into main 2026-09-25 19:54:51 +00:00
Owner

Two changes to the reference proxy, both gaps found in tonight's cutover attempt:

Internal names get certificates from the mesh's own authority. An .internal alias was correctly refused a public certificate (no public CA can validate a private name) and then left plain-HTTP only. The mesh has two name spaces and two authorities (08-connectivity §2), so the proxy now takes an optional INTERNAL_ACME_DIRECTORY and dispatches at the TLS handshake by the question HostPolicy already answers: which authority may certify this name at all. Unset, nothing changes — internal aliases serve plain HTTP as before.

A route may name its target's scheme. scheme: https with optional insecure: true, for a backend that terminates TLS with its own certificate — Mailu's webmail front is the dependent. Everything else stays plain http on the private network, and an unknown scheme is skipped aloud rather than guessed at.

Tested: the full route-proxy suite, including new tests for both authorities' host policies, the https target, and an end-to-end insecure-https proxy round trip.

Two changes to the reference proxy, both gaps found in tonight's cutover attempt: **Internal names get certificates from the mesh's own authority.** An `.internal` alias was correctly refused a public certificate (no public CA can validate a private name) and then left plain-HTTP only. The mesh has two name spaces and two authorities (08-connectivity §2), so the proxy now takes an optional `INTERNAL_ACME_DIRECTORY` and dispatches at the TLS handshake by the question HostPolicy already answers: which authority may certify this name at all. Unset, nothing changes — internal aliases serve plain HTTP as before. **A route may name its target's scheme.** `scheme: https` with optional `insecure: true`, for a backend that terminates TLS with its own certificate — Mailu's webmail front is the dependent. Everything else stays plain http on the private network, and an unknown scheme is skipped aloud rather than guessed at. Tested: the full route-proxy suite, including new tests for both authorities' host policies, the https target, and an end-to-end insecure-https proxy round trip.
jschoubben added 1 commit 2026-09-25 18:52:07 +00:00
Internal aliases were served over plain HTTP only — correctly refused a
public certificate (no public CA can validate a private name), and then
left with nothing. The mesh has two authorities for its two name spaces
(08-connectivity §2), so the proxy now takes an optional internal ACME
directory and dispatches at the handshake by the same question HostPolicy
already answers: which authority may certify this name at all.

A route may also say its target speaks https, with insecure for a backend
whose own certificate nothing would trust — the shape Mailu's webmail
front needs, and the exception: everything else the mesh hands this proxy
stays plain http on the private network.
jschoubben merged commit c3458a2546 into main 2026-09-25 19:54:51 +00:00
jschoubben deleted branch feat/route-proxy-internal-acme 2026-09-25 19:54:51 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-controller#64