Skip to content

feat: the Let's Encrypt screen is driven by the instance description - #22

Merged
marcos-mendez merged 1 commit into
masterfrom
feat/lets-encrypt-from-the-spec
Oct 2, 2026
Merged

marcos-mendez merged 1 commit into
masterfrom
feat/lets-encrypt-from-the-spec

Conversation

@marcos-mendez

Copy link
Copy Markdown
Collaborator

What. The domain boxes of Advanced > Let's Encrypt > Get certificate are prefilled from /etc/keel/instance.yaml: tls.acme.domains when it declares any, else instance.fqdn (the name the first boot now records, Keel-Linux/inithooks#36), else from /etc/dehydrated/confconsole.domains.txt as before, example.com on a fresh machine. When the operator confirms the domains and the request succeeds, the description gets tls.acme.domains (as confirmed, without blanks or aliases) and tls.acme.enabled: true; challenge and agree_tos are left as they were. When the request fails nothing is written to it. The domains file is still written and backed up as before, since dehydrated reads it; HTTP-01 and DNS-01 are unchanged.

Why. The maintainer wants confconsole driven by the spec: the screen offered example.com whatever the machine was named, and a certificate it obtained was unknown to keel spec apply --system and keel diff.

How the spec is written. With confconsole's own writer, keelcli (stage_spec → keel spec validate --no-secret-files → commit_spec), the same path the Database mode and Keel Cloud screens use; keel has no writer of its own, so there is no keel version to depend on. A description keel refuses, or a machine without keel, is shown on the screen ("the certificate was issued, but ... was NOT changed") and the file is left as it was.

Decisions to note. The screen's description text was eleven rows, which with the five boxes does not fit a 24 row console; it is shorter now, says where the boxes come from, and a test holds it to keelbanner.available(24, 80). A success still returns to the menu silently, as before.

Tested. tests/test_lets_encrypt.py (31) loads the plugin the way confconsole does, with the fake console; requests, dehydrated-wrapper and keel are replaced. keelcli.py stays at 100 percent in the gate (860 passed); get_certificate.py measured alone is 61 percent, every line added here covered, the rest the DNS-01 flow (COVERAGE.md).

The domain boxes are prefilled from /etc/keel/instance.yaml:
tls.acme.domains when it declares any, else instance.fqdn (the name the
first boot records, Keel-Linux/inithooks#36), else from dehydrated's
domains file as before, example.com on a fresh machine. Once the
operator confirms the domains and the certificate is issued, the
description gets tls.acme.domains and tls.acme.enabled: true, written
as every Instance screen writes it (keelcli: staged, keel spec validate
--no-secret-files, moved into place; a refusal is shown and the file
left as it was). A request that fails writes nothing to it. dehydrated
keeps reading its own domains file, written as before; HTTP-01 and
DNS-01 are unchanged.

The screen's text was eleven rows, too tall for a 24 row console with
the five boxes under it; a test now holds it to the room that leaves.
@marcos-mendez
marcos-mendez force-pushed the feat/lets-encrypt-from-the-spec branch from 0ffdf89 to 0ca3508 Compare October 2, 2026 22:21
@marcos-mendez
marcos-mendez merged commit e96ca9a into master Oct 2, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant