6e4f794b03b4f4124f9103e3d71940e872c55957
ci / audit (push) Failing after 1m1s
compose.yaml: host networking (bridge+embedded-DNS broke rooted-name lookups), :8443 via ca.json address, image digest-pinned; init-stepca.sh: scaffold + ECDSA-P256 intermediate signed by /root/ca-root fleet root (verified), ACME provisioner, managed password. Directory serving RFC8555 on tailnet. OPEN: step-ca validation GET fails instantly with zero dial attempts (authz says could-not-connect) — bisected caps, read_only, bridge vs host, container DNS. Debug continues next run (GODEBUG=netdns=2 + strace plan). https://projects.knownelement.com/issues/800
ca
Docs live on Discourse — this repo is the executable source of truth. Topic: https://community.turnsys.com/t/327 Redmine: https://projects.knownelement.com/issues/697 · Split from KNEL/PFVCluster@041d311 per #769
Fleet CA on tsys-ca: init/issue/selftest, fleet TLS rollout, HTTP artifact mirror (pinned wazuh-agent debs + SHA256SUMS). Roadmap: ACME endpoint, k8s CA integration, SSH certificates. [#697]
Layout
scripts/— rule engine + hooks (seebash scripts/check-rules.sh --fast)- (imported content at repo root, mirroring its PFVCluster path layout)
Provenance
Code imported from KNEL/PFVCluster (041d311); full git history retained in PFVCluster. Enforcement layer copied per ADOPTING.md. IaC consumers: KNEL/KNELIAC references this repo.
Languages
Shell
96.5%
Makefile
3.5%