nix(tls): host hive-CA + gateway leaf for self-signed mode
Replace the gateway's bare in-container self-signed leaf with a leaf signed by a host-held hive CA. A bare self-signed leaf is its own trust anchor, so every regeneration is a fresh anchor every consumer would have to re-trust, and a runtime-generated in-container leaf cannot be wired into an agent's build-time trust store at all. A stable CA fixes both: a single anchor that agents and federation peers trust once, surviving leaf rotation. New hive-tls module: a host oneshot generates a long-lived CA (default ~20y) under services.hyperhive.tls.stateDir and signs a gateway leaf (default ~10y, SAN covering the bare domain, forge., matrix. and the wildcard). It is ordered before the gateway container so the leaf exists when nginx starts. Active only when the gateway uses self-signed TLS (default) and a domain is set; inert under operator-cert or ACME modes. Gateway: bind-mount the host CA dir read-only at /run/hive-ca; the existing in-container cert unit now imports the host leaf into nginx's state dir (copy as root, key left root:nginx 0640 for the pre-start config test) instead of generating one. Cert/key paths nginx serves are unchanged. Foundational step toward agent + federation trust of self-signed hives; no behaviour change for agents yet (they still reach the forge over plain http on port 80). Eval-proven across self-signed, certDir and the inert default paths.
This commit is contained in:
parent
4297436d94
commit
74a90fd7d6
4 changed files with 216 additions and 71 deletions
|
|
@ -120,6 +120,7 @@ in
|
|||
./hive-gateway.nix
|
||||
./hive-matrix.nix
|
||||
./hive-network.nix
|
||||
./hive-tls.nix
|
||||
];
|
||||
|
||||
# Top-level hyperhive enable flag. When true, automatically enables
|
||||
|
|
|
|||
Loading…
Reference in a new issue