Remove server-side TLS; terminate at the reverse proxy #165
Labels
No labels
actions
bug
cli
duplicate
enhancement
fork
forum
git storage
help wanted
insights
invalid
issues
moderation
oidc
ownership transfer
packages
pr/merge protection rules
projects
pull requests
question
releases
sponsorships
tags
webhooks
wiki
wontfix
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
crueber/walhub#165
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Remove server-side TLS: TLS termination belongs on the reverse proxy
Decision
The server should not itself be a TLS server and should not deal with SSL certs. TLS termination belongs on the reverse proxy in front of it.
Verification that no cert is needed (checked 2026-09-05)
cmd/walhub/serve.go).git clone https://during import) validates against system root CAs — it never usesserver.tls.cert/key.server.tls.mode = off|files|self_signed(TLSStruct,tlsConfigFor,TLSServerConfig,checkTLS) — all of this becomes dead surface after removal.Scope
files/self_signedmodes, cert/key loading, and TLS listener wrapping; server listens plain HTTP (h2c retained).server.tlscert settings — decide in the change, fail closed.docs/go/06_server_http.md,10-series/config docs, README/compose TLS references,DEVIATIONS.mdif the removal deviates from the Rust spec) with a Decisions entry (law 12); deployment docs gain a reverse-proxy snippet/pointer (caddy/nginx minimal example).X-Forwarded-Protowhen building absolute URLs (e.g. clone URLs) behind a proxy — file separately if out of scope.Acceptance criteria
go vet/coverage gates hold on touched packages.make cover/make testgreen for touched packages; e2e over plain HTTP green.Fixed by PR #167 (#167) — branch fix/issue-165, awaiting review (not merged).
What landed: server-side TLS removed end to end (modes, cert/key loading, self-signed generation, listener wrap, ca.pem route, setup.json ca_url/trust, install.sh CA step, TLS setup fields). Plain HTTP + h2c; x/crypto (SSH) and x/net (h2c) retained.
Two judgment calls worth flagging:
Verification: vet clean; -race green (config/server/api/cmd); cover 95.5% on config/server/api; node --test 325/325; e2e green; live smoke confirmed plain-HTTP serve, https clone URLs under X-Forwarded-Proto, ca.pem 404, and zero server.tls keys in the setup schema.
Review of PR #167 (fix/issue-165, remove server-side TLS) — verified in scratch worktree /tmp/pr167 at
6b33a47(c61c4e9+ 1 review fixup).VERDICT: ready to merge (after the 1-line fixup already pushed).
DANGLING REFS (all clear, grepped myself):
TRUST BOUNDARY (X-Forwarded-Proto):
DEPENDENCY BUDGET: x/crypto still imported (sshd.go, command.go, sshkeys.go — SSH transport only); x/net still imported (listener.go h2c/h2c handler). No new modules. DEVIATIONS D-DEP-3 updated (I removed a duplicated Rationale: line left by the edit — pushed as
6b33a47).COMPAT / FAIL-CLOSED:
COVERAGE / TESTS (all in scratch worktree):
DOCS: 01_overview, 06_server_http (§2.2/§3/§9.1-9.3/§10.4/§11 + Decisions), 11_config_cli (keys table, example, validation renumber 8/9/10, env-exception note), 12_web_ui (#124 follow-up marked resolved), 16_packaging (standalone/S3 shapes, new §3.4 Caddy+nginx snippets with the load-bearing X-Forwarded-Proto line; §4.2 reworded). Proxy snippets accurate. Nested decision recorded in same change per law 12.
FIX APPLIED DIRECTLY: DEVIATIONS.md D-DEP-3 duplicated Rationale line removed (commit
6b33a47, pushed to origin/fix/issue-165).RECOMMENDATION: ready to merge.
Fixed by PR #167 incl. review doc fixup (TLS modes/certs removed, proxy snippets, X-Forwarded-Proto honored display-only; all gates green), merged. Closing.