-
-
Notifications
You must be signed in to change notification settings - Fork 0
R4: On-demand TLS with ask endpoint #13
Copy link
Copy link
Closed
Labels
proxyLegacy: the proxy side of cross-repo work (every item in this repo is)Legacy: the proxy side of cross-repo work (every item in this repo is)size:LLarge: multi-dayLarge: multi-day
Milestone
Description
Activity
Metadata
Metadata
Assignees
Labels
proxyLegacy: the proxy side of cross-repo work (every item in this repo is)Legacy: the proxy side of cross-repo work (every item in this repo is)size:LLarge: multi-dayLarge: multi-day
The single biggest differentiator: Caddy-style on-demand TLS for SaaS custom domains — issue a cert at first handshake, gated by an
askURL.Demand: port basecamp/kamal-proxy#63 (18 months open, 23 comments/18 reactions, prod-tested by LocomotiveCMS); discussions #141/#221; basecamp/kamal#1617.
Where: integrate with dash's
CertificateRegistry(internal/server/cert_registry.go) rather than the PR's standalone path; per-handshake gate inrouter.go:293 GetCertificate.Pairs with: gem-side plumbing.
Verify: first request to an approved unknown host provisions a cert; unknown host rejected by the ask endpoint;
make test.