caddytls: Avoid default issuers for implicit tailscale policies (#7577)

This commit is contained in:
Tao 2026-03-21 01:36:03 +10:00 committed by GitHub
parent df65455b1f
commit 5d189aff40
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
2 changed files with 61 additions and 1 deletions

View file

@ -235,7 +235,7 @@ func (ap *AutomationPolicy) Provision(tlsApp *TLS) error {
}
issuers := ap.Issuers
if len(issuers) == 0 {
if len(issuers) == 0 && !ap.implicitTailscaleManagersOnly() {
var err error
issuers, err = DefaultIssuersProvisioned(tlsApp.ctx)
if err != nil {
@ -429,6 +429,29 @@ func (ap *AutomationPolicy) AllInternalSubjects() bool {
})
}
// implicitTailscaleManagersOnly returns true if this policy is configured to
// serve only Tailscale names from the Tailscale manager at handshake-time.
func (ap *AutomationPolicy) implicitTailscaleManagersOnly() bool {
if len(ap.subjects) == 0 {
return false
}
for _, subject := range ap.subjects {
if !strings.HasSuffix(strings.ToLower(subject), tailscaleDomainAliasEnding) {
return false
}
}
for _, manager := range ap.Managers {
switch manager.(type) {
case Tailscale, *Tailscale:
return true
}
}
return false
}
func (ap *AutomationPolicy) onlyInternalIssuer() bool {
if len(ap.Issuers) != 1 {
return false

View file

@ -0,0 +1,37 @@
package caddytls
import (
"testing"
"github.com/caddyserver/certmagic"
"go.uber.org/zap"
)
func TestAutomationPolicyMakeCertMagicConfigImplicitTailscaleManagersOnly(t *testing.T) {
ap := AutomationPolicy{
Managers: []certmagic.Manager{Tailscale{}},
subjects: []string{"test-node.example.ts.net"},
}
cfg, err := ap.makeCertMagicConfig(&TLS{
logger: zap.NewNop(),
}, nil, &certmagic.FileStorage{Path: t.TempDir()})
if err != nil {
t.Fatalf("making certmagic config: %v", err)
}
if cfg.OnDemand == nil {
t.Fatal("expected on-demand config to be set")
}
if len(cfg.Issuers) != 0 {
t.Fatalf("expected no issuers for tailscale-managed ts.net policy, got %d", len(cfg.Issuers))
}
}
func TestAutomationPolicyImplicitTailscaleManagersOnlyCatchAll(t *testing.T) {
ap := AutomationPolicy{
Managers: []certmagic.Manager{Tailscale{}},
}
if ap.implicitTailscaleManagersOnly() {
t.Fatal("expected catch-all manager policy to remain outside tailscale-only special case")
}
}