originca

package
v0.51.8 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 4, 2026 License: Apache-2.0 Imports: 18 Imported by: 0

Documentation

Overview

Package originca holds the node side of Cloudflare Origin CA certificates for managed kombify.me origins (ADR-0047).

The node generates the key pair and hands out only a CSR. Techstack has the certificate issued and delivers the signed certificate, which is public. The private key is written to owner custody and never leaves the node: no result, log or receipt in this package carries it.

Index

Constants

View Source
const (
	SchemaVersion = "stackkit.origin-certificate/v1"
	// ManagedZone is the only zone the Origin CA certificate covers.
	ManagedZone = "kombify.me"

	PhaseRequest = "request"
	PhaseInstall = "install"

	// ContainerDir is where the router sees the live directory.
	ContainerDir = "/origin-tls"
)

Variables

This section is empty.

Functions

func Covers

func Covers(workspace, host string) bool

Covers reports whether an installed origin certificate, expired or not, covers host. Route rendering uses it: a managed route stays on the origin certificate path after expiry and never falls back to an ACME order.

func CustodyDir

func CustodyDir(workspace string) string

CustodyDir is the owner-custody directory of the origin certificate.

func LiveDir

func LiveDir(workspace string) string

LiveDir is the directory the router mounts read-only.

func NormalizeHosts

func NormalizeHosts(hosts []string) ([]string, error)

NormalizeHosts validates and sorts the managed hostnames.

func RootPEM

func RootPEM() []byte

RootPEM returns the concatenated root certificates.

func RootPool

func RootPool() *x509.CertPool

RootPool returns the Cloudflare Origin CA roots published at developers.cloudflare.com/ssl/static. Origin CA certificates are not browser trust; callers use this pool for node-vantage probes of managed routes instead of system trust.

func Serves

func Serves(workspace, host string, now time.Time) bool

Serves reports whether an unexpired installed origin certificate covers host.

Types

type InstallResult

type InstallResult struct {
	SchemaVersion     string   `json:"schemaVersion"`
	Phase             string   `json:"phase"`
	Hosts             []string `json:"hosts"`
	SerialHex         string   `json:"serialHex"`
	NotBefore         string   `json:"notBefore"`
	NotAfter          string   `json:"notAfter"`
	CertificateSHA256 string   `json:"certificateSha256"`
}

InstallResult is the public result of the install phase. It carries the certificate identity only, never key material.

type Installer

type Installer struct {
	Workspace string
	Roots     *x509.CertPool
	Now       func() time.Time
}

Installer binds the node operations to one workspace and a trust pool.

func (Installer) Install

func (i Installer) Install(certificatePEM []byte) (InstallResult, error)

Install verifies the delivered certificate against the pending key, the requested hostnames and the Origin CA roots, then publishes it atomically to the router's live directory.

func (Installer) Request

func (i Installer) Request(hosts []string) (RequestResult, error)

Request generates a fresh ECDSA P-256 key pair in custody and returns the CSR. A repeated request replaces the pending key; the live certificate keeps serving until Install swaps it.

type RequestResult

type RequestResult struct {
	SchemaVersion string   `json:"schemaVersion"`
	Phase         string   `json:"phase"`
	Hosts         []string `json:"hosts"`
	KeyAlgorithm  string   `json:"keyAlgorithm"`
	CSRPEM        string   `json:"csrPem"`
	CSRSHA256     string   `json:"csrSha256"`
}

RequestResult is the public result of the request phase.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL