Skip to content

feat(onboard): make setup work on networks that intercept TLS - #877

Merged
AmrikSD merged 1 commit into
mainfrom
onboard-tls
Oct 5, 2026
Merged

AmrikSD merged 1 commit into
mainfrom
onboard-tls

Conversation

@AmrikSD

@AmrikSD AmrikSD commented Oct 5, 2026

Copy link
Copy Markdown
Owner

On a company laptop whose network intercepts TLS, setup.sh fails at its first Bazel download: Bazel's JVM ignores SSL_CERT_FILE and rejects the proxy's certificate. That is the very first step on a new work machine, before any work-only config exists to fix it.

setup.sh now builds a Java truststore from SSL_CERT_FILE when it is set and points Bazel at it in ~/.bazelrc. It keys off the standard variable, so nothing company-specific is in this repo and a machine without it is untouched.

Tested the certificate split and import on a laptop with such a bundle (129 certificates in, 129 in the store) and that Bazel fetches with the resulting store. setup.sh as a whole has still not been run.

@AmrikSD
AmrikSD merged commit 31bb4a5 into main Oct 5, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant