# One machine serving a public name with a certificate from an authority it did not run itself. # # The lab keeps production's two-authority split rather than collapsing it (01-RESEARCH/004): the # mesh's own authority certifies `.internal` names, and a name reachable from outside is certified # by ACME. A single-authority lab would hide any fault living in that split, so this raises a real # ACME server and makes the proxy actually order from it. # # Pebble rather than a stub, for the reason the lab exists at all: what is under test is whether an # HTTP-01 challenge is answered at the name being certified, and a fake would be told to agree. scenario: a-public-name segments: hosting: kind: public cidr: [192.0.2.0/24] machines: anchor: at: { segment: hosting, address: [192.0.2.10] } inbound: allow images: - ghcr.io/letsencrypt/pebble:2.5.0 place: all: [runtime]