Documentation
¶
Overview ¶
Package originca holds the node side of Cloudflare Origin CA certificates for managed kombify.me origins (ADR-0047).
The node generates the key pair and hands out only a CSR. Techstack has the certificate issued and delivers the signed certificate, which is public. The private key is written to owner custody and never leaves the node: no result, log or receipt in this package carries it.
Index ¶
- Constants
- func Covers(workspace, host string) bool
- func CustodyDir(workspace string) string
- func LiveDir(workspace string) string
- func NormalizeHosts(hosts []string) ([]string, error)
- func RootPEM() []byte
- func RootPool() *x509.CertPool
- func Serves(workspace, host string, now time.Time) bool
- type InstallResult
- type Installer
- type RequestResult
Constants ¶
const ( SchemaVersion = "stackkit.origin-certificate/v1" // ManagedZone is the only zone the Origin CA certificate covers. ManagedZone = "kombify.me" PhaseRequest = "request" PhaseInstall = "install" // ContainerDir is where the router sees the live directory. ContainerDir = "/origin-tls" )
Variables ¶
This section is empty.
Functions ¶
func Covers ¶
Covers reports whether an installed origin certificate, expired or not, covers host. Route rendering uses it: a managed route stays on the origin certificate path after expiry and never falls back to an ACME order.
func CustodyDir ¶
CustodyDir is the owner-custody directory of the origin certificate.
func NormalizeHosts ¶
NormalizeHosts validates and sorts the managed hostnames.
Types ¶
type InstallResult ¶
type InstallResult struct {
SchemaVersion string `json:"schemaVersion"`
Phase string `json:"phase"`
Hosts []string `json:"hosts"`
SerialHex string `json:"serialHex"`
NotBefore string `json:"notBefore"`
NotAfter string `json:"notAfter"`
CertificateSHA256 string `json:"certificateSha256"`
}
InstallResult is the public result of the install phase. It carries the certificate identity only, never key material.
type Installer ¶
Installer binds the node operations to one workspace and a trust pool.
type RequestResult ¶
type RequestResult struct {
SchemaVersion string `json:"schemaVersion"`
Phase string `json:"phase"`
Hosts []string `json:"hosts"`
KeyAlgorithm string `json:"keyAlgorithm"`
CSRPEM string `json:"csrPem"`
CSRSHA256 string `json:"csrSha256"`
}
RequestResult is the public result of the request phase.