You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Plugin routes on an installation-origin mount are served at <slug>.<ATOMIC_ROUTES_ORIGIN> (#1749). Behind Caddy with on-demand TLS, every such host must be allowed before Caddy will get a certificate for it. The user-testing droplet does that by hand today, by touching files in /etc/caddy/routes-allowed/ (ontola/atomic-plugins#216).
Proposed (Michiel decided yes, Q-050):
a small endpoint for Caddy's on_demand_tls { ask … }, e.g. GET /plugin-routes/tls-ask?domain=<host>;
it answers 200 only if <host> is exactly <slug>.<routes origin host> for a live, active installation on this server (or a drive host bound to a live drive-host installation, if applicable), and 404 otherwise;
Plugin routes on an
installation-originmount are served at<slug>.<ATOMIC_ROUTES_ORIGIN>(#1749). Behind Caddy with on-demand TLS, every such host must be allowed before Caddy will get a certificate for it. The user-testing droplet does that by hand today, by touching files in/etc/caddy/routes-allowed/(ontola/atomic-plugins#216).Proposed (Michiel decided yes, Q-050):
on_demand_tls { ask … }, e.g.GET /plugin-routes/tls-ask?domain=<host>;<host>is exactly<slug>.<routes origin host>for a live, active installation on this server (or a drive host bound to a livedrive-hostinstallation, if applicable), and 404 otherwise;--trusted-proxies) so it isn't a public oracle;plugin-routesfeature and a configured routes origin;docs/src/atomicserver/installation.md;Related: #1903 (trusted proxies), #1749 (mounts), ontola/atomic-plugins#216.