summaryrefslogtreecommitdiff
path: root/frontends/Rexfile
diff options
context:
space:
mode:
authorPaul Buetow <paul@buetow.org>2026-08-03 10:27:49 +0300
committerPaul Buetow <paul@buetow.org>2026-08-03 10:27:49 +0300
commita7d859681f5508a829115376d9dd993f3f137321 (patch)
tree272a080c3a21a2345e916a961b035b3fe8b46627 /frontends/Rexfile
parent7785a4281d6fc2b33eae2face2505cd892d733d4 (diff)
frontends: give f3s hosts a standby.<host> SAN instead of a separate cert
f3s hosts don't get a distinct standby certificate/keypair; alias the primary cert's files under the standby name (relayd selects a keypair by SNI, so it needs matching filenames) and add standby.<host> as a SAN on the primary cert. Every host now also gets www.<host> as a SAN unconditionally, since public DNS publishes www for all of them. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Diffstat (limited to 'frontends/Rexfile')
-rw-r--r--frontends/Rexfile12
1 files changed, 10 insertions, 2 deletions
diff --git a/frontends/Rexfile b/frontends/Rexfile
index 21c2f58..3dd3c43 100644
--- a/frontends/Rexfile
+++ b/frontends/Rexfile
@@ -296,13 +296,21 @@ task 'acme',
group => 'frontends',
sub {
file '/etc/acme-client.conf',
- content => template( './etc/acme-client.conf.tpl', acme_hosts => \@acme_hosts ),
+ content => template(
+ './etc/acme-client.conf.tpl',
+ acme_hosts => \@acme_hosts,
+ f3s_hosts => \@f3s_hosts
+ ),
owner => 'root',
group => 'wheel',
mode => '644';
file '/usr/local/bin/acme.sh',
- content => template( './scripts/acme.sh.tpl', acme_hosts => \@acme_hosts ),
+ content => template(
+ './scripts/acme.sh.tpl',
+ acme_hosts => \@acme_hosts,
+ f3s_hosts => \@f3s_hosts
+ ),
owner => 'root',
group => 'wheel',
mode => '744';