From d9bf178546aa5ea83bd2037732ccf1b2f14f5234 Mon Sep 17 00:00:00 2001 From: jochen Date: Thu, 10 Sep 2026 21:05:30 +0200 Subject: [PATCH] whole-mesh-full: serve the internal CA's image ADR 0056 made `acme-ca` a requirement of route-proxy, and step-ca is what answers it. A scenario that does not stock the image cannot run the CA, the proxy does not resolve, and every routed module on the mesh goes with it. This was carried as an uncommitted edit through the first ADR 0056 raise. Kept, because it is right, and committed, because a fix that lives in somebody's working tree is a fix the next raise does not have. --- scenarios/whole-mesh-full.yml | 3 +++ 1 file changed, 3 insertions(+) diff --git a/scenarios/whole-mesh-full.yml b/scenarios/whole-mesh-full.yml index 078d7ab..e8f160f 100644 --- a/scenarios/whole-mesh-full.yml +++ b/scenarios/whole-mesh-full.yml @@ -166,6 +166,9 @@ images: - mesh-runtime-verdaccio:development - mesh-runtime-mailu:development - mesh-route-proxy:development + # ADR 0056: the internal ACME authority. route-proxy now REQUIRES an `acme-ca`, so a bed that does + # not serve this image has an unresolvable proxy — and with it every routed module on the mesh. + - smallstep/step-ca:latest - mesh-runtime-sonarr:development - mesh-runtime-radarr:development - mesh-runtime-lidarr:development