Documentation
¶
Index ¶
- Variables
- func BrowserTrustAvailable() bool
- func CARoot() (string, error)
- func CATrusted() bool
- func CertExists(domain string) bool
- func EnsureCert(site config.Site) error
- func InstallCA() error
- func IssueCert(primaryDomain string, allDomains []string, certsDir string) error
- func IssueCertForce(primaryDomain string, allDomains []string, certsDir string) error
- func MkcertPath() string
- func ReissueCertForWorktree(site config.Site) error
- func SecureSite(site config.Site) error
- func SystemTrustAnchorPresent() bool
- func TrustCAInSystemStore(caPEM []byte) error
- func UnsecureSite(site config.Site) error
- func UntrustCAFromSystemStore() error
- func WorktreeCertDomains(siteDomains []string, worktreeDomains []string) []string
Constants ¶
This section is empty.
Variables ¶
var ErrDNSDisabled = fmt.Errorf("HTTPS requires lerd-managed DNS, set dns.enabled: true and re-run lerd install")
ErrDNSDisabled signals that the operation requires the lerd-managed DNS / mkcert CA stack, which the user has opted out of. Surfaces through the CLI `lerd secure` command and the dashboard HTTPS toggle.
var ErrNoSystemTrustStore = errors.New("no system CA trust store found")
ErrNoSystemTrustStore reports that no known CA anchor directory exists on this system, as on NixOS and other distros where trust is declarative.
var RegenerateHostProxyWorktreeVhost func(site config.Site, wtPath, wtDomain string, secured bool) error
RegenerateHostProxyWorktreeVhost regenerates the proxy vhost for a single worktree of a host-proxy site, switching it between HTTP and HTTPS. It is populated by the cli package (which owns host-proxy port allocation) so certs can do this without importing cli. nil in builds that don't link cli, in which case host-proxy worktree vhosts are left untouched.
Functions ¶
func BrowserTrustAvailable ¶ added in v1.29.0
func BrowserTrustAvailable() bool
BrowserTrustAvailable reports whether mkcert can install the root CA into the browser NSS trust stores. That needs certutil, shipped in nss-tools. Without it mkcert still writes the CA to the system trust store, so curl, PHP and openssl trust .test, but Firefox and Chrome are skipped and warn on HTTPS.
func CARoot ¶ added in v1.31.0
CARoot returns mkcert's CAROOT directory, so a caller escalating to root can name the user's real CA location instead of assuming the default.
func CATrusted ¶ added in v1.28.0
func CATrusted() bool
CATrusted reports whether mkcert's root CA is already present in the system trust store. Callers use it to skip the sudo announcement (and mkcert's chatty banner) on a reinstall where the CA is already installed.
func CertExists ¶
CertExists returns true if the certificate for the domain already exists.
func EnsureCert ¶ added in v1.28.0
EnsureCert reuses the site's existing certificate when it is still valid and clear of the reissue window, otherwise reissues one covering the site's own domains plus every current worktree domain. Unlike ReissueCertForWorktree it never forces, so it is cheap to call on every boot/watcher pass as the routine self-heal that keeps a long-lived secured site's leaf cert from expiring.
func InstallCA ¶
func InstallCA() error
InstallCA installs the mkcert root CA into the system trust store.
func IssueCert ¶
IssueCert issues a TLS certificate covering all the given domains using mkcert. The cert files are named after primaryDomain. Each domain also gets a wildcard entry. An existing cert/key pair is reused without re-running mkcert only while the cert is still valid and more than certReissueWindow from NotAfter; a cert that is expired, near expiry, or unreadable falls through to the atomic reissue so an ordinary start or watcher pass self-heals an aging cert.
func IssueCertForce ¶ added in v1.20.0
IssueCertForce regenerates the certificate for primaryDomain even if files exist. Writes to temp paths and renames atomically so a transient mkcert failure leaves the previous cert/key intact (which is critical: a missing cert trips RepairVhosts into flipping the site to plain HTTP).
func ReissueCertForWorktree ¶ added in v1.20.0
ReissueCertForWorktree reissues the site's TLS certificate to include wildcard SANs for all current worktree domains (*.branch.domain.test). Call this after a new worktree is created on a secured site so that subdomains like app.branch.domain.test are covered by the certificate.
func SecureSite ¶ added in v0.1.29
SecureSite issues a TLS certificate for the site and switches its nginx vhost to HTTPS.
func SystemTrustAnchorPresent ¶ added in v1.31.0
func SystemTrustAnchorPresent() bool
SystemTrustAnchorPresent reports whether a lerd-written anchor is on disk, so an uninstall only escalates to root when there is something to remove.
func TrustCAInSystemStore ¶ added in v1.31.0
TrustCAInSystemStore installs the given mkcert root CA PEM into whichever system trust store this distro uses. The caller must be root. Idempotent: a byte-identical CA already in place is a no-op, so re-running on every package upgrade is cheap.
mkcert normally does this itself via an interactive sudo, which a package maintainer script cannot answer. `lerd bootstrap --trust-ca` runs as root and installs the user-generated CA directly instead.
func UnsecureSite ¶ added in v0.1.29
UnsecureSite regenerates a plain HTTP vhost for the site, removing TLS.
func UntrustCAFromSystemStore ¶ added in v1.31.0
func UntrustCAFromSystemStore() error
UntrustCAFromSystemStore removes the anchor TrustCAInSystemStore wrote and refreshes the bundle. The caller must be root. mkcert's own -uninstall keys on the filename mkcert chose, so it never reaches this one; without this the CA would stay trusted on the machine after lerd is gone. Idempotent, and every store is swept rather than only the first so nothing is left behind.
func WorktreeCertDomains ¶ added in v1.20.0
WorktreeCertDomains builds the full domain list for a certificate that covers the site's own domains plus all worktree domains. Each domain gets a wildcard entry via IssueCert, so worktree domains like branch.myapp.test produce *.branch.myapp.test SANs for deep subdomain coverage.
Types ¶
This section is empty.