Replace Pebble with step-ca for local ACME
Pebble skipped real HTTP-01 validation, which hid integration gaps for compliance-page custom domains. step-ca with a Caddy port-80 proxy exercises the same path production uses while keeping issued certs persistent across compose restarts. Signed-off-by: Bryan Frimin <bryan@probo.com>
This commit is contained in:
26
compose/step-ca/README.md
Normal file
26
compose/step-ca/README.md
Normal file
@@ -0,0 +1,26 @@
|
||||
# step-ca local CA
|
||||
|
||||
This directory holds the persistent [step-ca](https://github.com/smallstep/certificates)
|
||||
state for local custom-domain TLS. It is initialized on first `make stack-up`.
|
||||
|
||||
After the first run, install the root CA once so browsers and server-side TLS
|
||||
clients (e.g. CIMD OAuth) trust issued certificates across restarts:
|
||||
|
||||
```bash
|
||||
step certificate install compose/step-ca/certs/root_ca.crt
|
||||
```
|
||||
|
||||
The ACME directory URL is `https://localhost:9000/acme/acme/directory`.
|
||||
|
||||
step-ca shares the `acme-http-01-proxy` container network so HTTP-01 validation
|
||||
to `http://<hostname>/.well-known/acme-challenge/...` reaches Caddy on port 80,
|
||||
which forwards to probod's trust-center HTTP listener on the host.
|
||||
|
||||
## Custom domain DNS (optional)
|
||||
|
||||
Managed compliance-page domains (`*.probopage.localhost`) resolve via the
|
||||
`.localhost` TLD and skip DNS checks.
|
||||
|
||||
For customer custom domains in local dev, point DNS at the host via
|
||||
`/etc/hosts` and ensure HTTP-01 reaches probod through the
|
||||
`acme-http-01-proxy` service on port 80.
|
||||
Reference in New Issue
Block a user