Feature: ACME DNS-01 challenge delegation (CNAME alias) for least-privilege DNS tokens
Ninguém assumiu esta issue ainda.
Avaliação
- Dificuldade
- 5/5
- Tempo estimado
- Mais de uma semana
- Facilidade para iniciantes
- 45/100
Direção de pesquisa
Comece por entrypoint.sh e pela abstração dns_providers existente; rastreie a invocação atual de ACME, o tratamento de TXT e o caminho de falha de CAA. Revise o fluxo proposto de ACME_CHALLENGE_ALIAS e os manual auth/cleanup hooks do certbot. Considera-se concluído quando a delegação de TXT da alias-zone funcionar sem acesso à production-zone e o CAA exato de accounturi for impresso e verificado, ou sua ausência for reportada claramente.
Escrita pelo modelo de indexação a partir do texto da issue.
Descrição
Problem
dstack-ingress issues certs via ACME DNS-01, which requires a DNS provider API token that can edit the served domain's own zone (to write the _acme-challenge TXT, and — per entrypoint.sh — to set the A record and CAA).
In our deployment the served name (e.g. svc.example.com) lives under a shared production zone (example.com) that holds many unrelated production records. Handing the enclave a token for that zone is too broad:
- Cloudflare API tokens scope only to zone level — there is no way to restrict a token to a single subdomain/record.
- Managing the subdomain as its own Cloudflare zone requires an Enterprise plan.
So today we'd have to give the enclave a token that can edit our entire example.com zone, which we can't accept.
Proposed feature: DNS-01 challenge delegation (CNAME alias)
Let the operator delegate only the _acme-challenge to a separate zone they fully control, so the enclave's token never touches the production zone:
- Operator adds one static record in the production zone:
_acme-challenge.svc.example.com CNAME <label>.<delegation-zone> - dstack-ingress writes the challenge TXT into
<delegation-zone>(its token scoped only to that zone). Let's Encrypt follows the CNAME during validation.
This is a standard least-privilege ACME pattern (acme.sh --challenge-alias, lego, cert-manager, and Cloudflare's own "Delegated DCV" all support it), and it fits dstack's zero-trust ethos.
Design sketch (opt-in, non-breaking)
- New env
ACME_CHALLENGE_ALIAS=<delegation-zone>; unset ⇒ current behavior, unchanged. - When set, run certbot with
--manual --preferred-challenges=dns+ auth/cleanup hooks that reuse the existingdns_providersabstraction to write the TXT under the alias zone instead of_acme-challenge.<domain>.
Important: CAA handling (needs an explicit decision)
entrypoint.sh currently auto-sets the accounturi CAA
(letsencrypt.org;validationmethods=dns-01;accounturi=$ACCOUNT_URI) on the served domain, using the same token. In delegation mode the token cannot touch the served domain's zone, so this auto-set won't work — and the current code treats a CAA-set failure as not critical, which would silently drop the accounturi lock (the forge-prevention against a non-TEE account issuing a cert for the domain).
To avoid silently weakening security, in delegation mode the feature should:
- print the exact CAA record the operator must set statically in the served zone (including the account URI), and
- verify the CAA is present / warn loudly if absent, instead of silently continuing.
This keeps the "only the TEE's ACME account can issue" guarantee explicit, rather than silently lost.
- Linguagem predominante
- Python
- Estrelas
- 27
- Forks
- 26
- Merge médio
- 2d 3h
- PRs com merge (30d)
- 7
Preparar o ambiente
- Sem Dockerfile nem arquivo Docker Compose
- Sem modelo de pull request
- Ler o guia de contribuição
Primeiros passos
- Leia a issue inteira e depois o guia de contribuição do projeto.
- Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
- Faça um fork do repositório e trabalhe em uma branch.
- Abra um pull request que referencie o número da issue.
Mais de Dstack-TEE/dstack-examples
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 76/100
Dstack-TEE/dstack-examples#87 · 2 comentários ·
-
Dificuldade 5/5 Mais de uma semana Facilidade para iniciantes 28/100
Dstack-TEE/dstack-examples#106 · 3 comentários ·
-
Dificuldade 3/5 1-2 dias Facilidade para iniciantes 45/100
-
enhancement help wanted
Dificuldade 5/5 Mais de uma semana Facilidade para iniciantes 25/100
-
Oracle exampleAbertaapp-idea
Dificuldade 5/5 Mais de uma semana Facilidade para iniciantes 25/100
Todas as issues de Dstack-TEE/dstack-examples
Issues semelhantes
-
dependencies feature github_actions good first issue
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 62/100
wemake-services/wemake-django-template#3149 ·
Mantenedores costumam responder em até 1 dia
-
[request] vsg/1.1.16Abertaupstream update
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 65/100
conan-io/conan-center-index#31142 ·
Mantenedores costumam responder em até 1 dia
-
area:core bug
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 78/100
Mantenedores costumam responder em até 1 dia
-
request-theme
Dificuldade 2/5 Menos de uma hora Facilidade para iniciantes 70/100
LizardByte/ThemerrDB#8877 · 1 comentário ·
Mantenedores costumam responder em até 1 dia
-
area/install-update comp/gateway P0 sweeper:risk-compatibility type/bug
Dificuldade 2/5 Menos de uma hora Facilidade para iniciantes 72/100
NousResearch/hermes-agent#135997 · 3 comentários ·
Mantenedores costumam responder em até 1 dia