Repository navigation
feat: the Let's Encrypt screen is driven by the instance description - #22
Merged
Merged
Conversation
marcos-mendez
force-pushed
the
feat/lets-encrypt-from-the-spec
branch
from
October 2, 2026 22:02
94387e2 to
0ffdf89
Compare
The domain boxes are prefilled from /etc/keel/instance.yaml: tls.acme.domains when it declares any, else instance.fqdn (the name the first boot records, Keel-Linux/inithooks#36), else from dehydrated's domains file as before, example.com on a fresh machine. Once the operator confirms the domains and the certificate is issued, the description gets tls.acme.domains and tls.acme.enabled: true, written as every Instance screen writes it (keelcli: staged, keel spec validate --no-secret-files, moved into place; a refusal is shown and the file left as it was). A request that fails writes nothing to it. dehydrated keeps reading its own domains file, written as before; HTTP-01 and DNS-01 are unchanged. The screen's text was eleven rows, too tall for a 24 row console with the five boxes under it; a test now holds it to the room that leaves.
marcos-mendez
force-pushed
the
feat/lets-encrypt-from-the-spec
branch
from
October 2, 2026 22:21
0ffdf89 to
0ca3508
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What. The domain boxes of Advanced > Let's Encrypt > Get certificate are prefilled from
/etc/keel/instance.yaml:tls.acme.domainswhen it declares any, elseinstance.fqdn(the name the first boot now records, Keel-Linux/inithooks#36), else from/etc/dehydrated/confconsole.domains.txtas before,example.comon a fresh machine. When the operator confirms the domains and the request succeeds, the description getstls.acme.domains(as confirmed, without blanks or aliases) andtls.acme.enabled: true;challengeandagree_tosare left as they were. When the request fails nothing is written to it. The domains file is still written and backed up as before, since dehydrated reads it; HTTP-01 and DNS-01 are unchanged.Why. The maintainer wants confconsole driven by the spec: the screen offered example.com whatever the machine was named, and a certificate it obtained was unknown to
keel spec apply --systemandkeel diff.How the spec is written. With confconsole's own writer,
keelcli(stage_spec→keel spec validate --no-secret-files→commit_spec), the same path the Database mode and Keel Cloud screens use; keel has no writer of its own, so there is no keel version to depend on. A description keel refuses, or a machine without keel, is shown on the screen ("the certificate was issued, but ... was NOT changed") and the file is left as it was.Decisions to note. The screen's description text was eleven rows, which with the five boxes does not fit a 24 row console; it is shorter now, says where the boxes come from, and a test holds it to
keelbanner.available(24, 80). A success still returns to the menu silently, as before.Tested.
tests/test_lets_encrypt.py(31) loads the plugin the way confconsole does, with the fake console; requests, dehydrated-wrapper and keel are replaced.keelcli.pystays at 100 percent in the gate (860 passed);get_certificate.pymeasured alone is 61 percent, every line added here covered, the rest the DNS-01 flow (COVERAGE.md).