Limit TLS cache warming to live domains
After the certificates split, WarmCache loaded every ACTIVE certificate. Org deletes cascade-remove custom_domains but leave certificates behind, so orphans could regain a usable SNI cache entry on rebuild. Warm and serve only certs still referenced by a domain, and purge unreferenced cache rows. Signed-off-by: Bryan Frimin <bryan@probo.com>
This commit is contained in:
@@ -685,7 +685,10 @@ WHERE
|
||||
return nil
|
||||
}
|
||||
|
||||
func (certificates *Certificates) LoadActive(
|
||||
// LoadActiveReferenced loads active certificates that are still referenced by
|
||||
// at least one custom domain. Certificates left behind after a domain is
|
||||
// deleted must not be warmed into the TLS cache or served by SNI alone.
|
||||
func (certificates *Certificates) LoadActiveReferenced(
|
||||
ctx context.Context,
|
||||
conn pg.Querier,
|
||||
scope Scoper,
|
||||
@@ -714,6 +717,11 @@ WHERE
|
||||
%s
|
||||
AND status = @status
|
||||
AND ssl_certificate IS NOT NULL
|
||||
AND EXISTS (
|
||||
SELECT 1
|
||||
FROM custom_domains
|
||||
WHERE custom_domains.certificate_id = certificates.id
|
||||
)
|
||||
`
|
||||
|
||||
q = fmt.Sprintf(q, scope.SQLFragment())
|
||||
@@ -723,7 +731,7 @@ WHERE
|
||||
|
||||
rows, err := conn.Query(ctx, q, args)
|
||||
if err != nil {
|
||||
return fmt.Errorf("cannot query active certificates: %w", err)
|
||||
return fmt.Errorf("cannot query active referenced certificates: %w", err)
|
||||
}
|
||||
|
||||
result, err := pgx.CollectRows(rows, pgx.RowToAddrOfStructByName[Certificate])
|
||||
|
||||
Reference in New Issue
Block a user