Update runbook docs for web01 reverse proxy and per-host ACME keys
Reflect web01 in the machines table and monitoring scrape list, note Grafana is now also published publicly via web01's reverse proxy, add the CNX Uptime dashboard, and document the dedicated acme_mx1/acme_web01 DNS-01 keys.
This commit is contained in:
+18
-6
@@ -61,13 +61,25 @@ requires re-submitting the DS.
|
||||
|
||||
## ACME DNS-01
|
||||
|
||||
A dedicated TSIG key (`acme_ddns`), scoped by `acl_acme` to `TXT` updates at or
|
||||
under `_acme-challenge.<zone>` on `ns1` only. Knot signs the record and transfers
|
||||
it to `ns2`, which never needs this key. Retrieve the client config with:
|
||||
Certificates are issued by `_acme-challenge` TXT updates that `ns1` accepts over
|
||||
TSIG, signs, and transfers to `ns2` (which never needs these keys). Each consumer
|
||||
gets its **own** key, scoped by an ACL to exactly the owner names it needs and
|
||||
attached only to the zone it lives in — so a leaked key can write nothing but its
|
||||
own challenges.
|
||||
|
||||
```
|
||||
clan vars get ns1 dns-acme-tsig/acme.conf
|
||||
```
|
||||
- **`acme_ddns`** (`acl_acme`) — the general key, scoped to `TXT` at or under
|
||||
`_acme-challenge.<zone>` and attached to every zone. Client config:
|
||||
```
|
||||
clan vars get ns1 dns-acme-tsig/acme.conf
|
||||
```
|
||||
- **`acme_mx1`** (`acl_acme_mx1`) — held only by `mx1`, scoped to
|
||||
`_acme-challenge.{mx1,mta-sts,mail}` and attached only to `cnx.email` (the mail
|
||||
cert plus its MTA-STS and client-alias SANs). Secret shared via the
|
||||
`dns-acme-mx1-secret` generator.
|
||||
- **`acme_web01`** (`acl_acme_web01`) — held only by `web01`, scoped to
|
||||
`_acme-challenge` and attached only to `cnx.network` (where the wildcard
|
||||
`*.cnx.network` challenge lands, at the apex). Secret shared via the
|
||||
`dns-acme-web01-secret` generator.
|
||||
|
||||
## Runbook: stale secondary
|
||||
|
||||
|
||||
Reference in New Issue
Block a user