Files
mesh-lab/scenarios/a-public-name.yml
T
jschoubben bfcbee49e9 A public name, against a real ACME server
The other half of the certificate split: the mesh's own authority
certifies internal names, and a name reachable from outside needs one
the world already trusts. Against a real server rather than a stub,
because what is under test is whether an order, a challenge and a
handshake agree, and a stub would be told to agree.

One assertion passes and one fails, and the failure is filed as
novox/hq 04-ISSUES/020: the authority issues a certificate and the
client never collects it. Kept as a failing test rather than deleted or
skipped — it is the reproduction, and it proves everything up to the
last hop.

The passing one is the guard that matters day to day: no certificate is
ordered for a name the mesh does not route, so a scan cannot spend an
account's rate limit.

The failure output gathers both sides before asserting. The first
version reported only what the proxy said, which made a server-side
question unanswerable — "the client never spoke to it" and "it refused
what the client said" are different faults with nothing in common.
2026-08-31 21:40:16 +02:00

27 lines
901 B
YAML

# One machine serving a public name with a certificate from an authority it did not run itself.
#
# The lab keeps production's two-authority split rather than collapsing it (01-RESEARCH/004): the
# mesh's own authority certifies `.internal` names, and a name reachable from outside is certified
# by ACME. A single-authority lab would hide any fault living in that split, so this raises a real
# ACME server and makes the proxy actually order from it.
#
# Pebble rather than a stub, for the reason the lab exists at all: what is under test is whether an
# HTTP-01 challenge is answered at the name being certified, and a fake would be told to agree.
scenario: a-public-name
segments:
hosting:
kind: public
cidr: [192.0.2.0/24]
machines:
anchor:
at: { segment: hosting, address: [192.0.2.10] }
inbound: allow
images:
- ghcr.io/letsencrypt/pebble:2.5.0
place:
all: [runtime]