helm (Go) fails TLS through Cortex proxy on macOS — CA not in System keychain
Maintainers usually reply within 1 day
@huang195 is already working on this.
Since Oct 10, 2026.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 18/100
Research direction
The payload names no source files, only install.sh and the agentop CLI, plus the ~/.cortex/ca/bundle.crt path the env vars point at. Start by reading how install.sh and agentop set HTTPS_PROXY and the CA variables, and reproduce with helm repo update behind the proxy. Done means a maintainer has chosen between the keychain change, a proxy bypass, or another supported CA path, and the chosen approach is implemented.
Written by the indexing model from the issue text.
Description
Summary
Go-based CLI tools (here: helm) fail TLS verification when their traffic is routed through the Cortex proxy on macOS, because they do not consult the *_CA_BUNDLE / SSL_CERT_FILE environment variables Cortex sets, and the Cortex bridge CA is not in the macOS System keychain that Go verifies against.
Filed as a blank issue per the Laptop-feedback template's guidance ("a Helm or platform problem — open a blank issue instead"). Raised with a Cortex maintainer, who suggested filing with details.
Where it fails
On the local machine, not the cluster. A Python CLI shells out to the local helm binary, which fetches public Helm chart repos (e.g. https://llm-d-incubation.github.io/llm-d-infra/) over the internet via the local Cortex proxy. The cluster API path (kubectl/oc) is unaffected.
Symptom
helm repo update llmDInfra
Get "https://llm-d-incubation.github.io/llm-d-infra/index.yaml":
tls: failed to verify certificate: x509: certificate signed by unknown authority
Reproduces both inside the CLI and when helm repo update is run standalone in the same shell.
Works vs. doesn't
curl -sSI https://llm-d-incubation.github.io/llm-d-infra/index.yaml→ HTTP/2 200 (curl honorsCURL_CA_BUNDLE).helm repo update→ TLS failure.
Root cause (hypothesis)
Cortex sets HTTPS_PROXY=http://127.0.0.1:47600 plus CURL_CA_BUNDLE / REQUESTS_CA_BUNDLE / SSL_CERT_FILE → ~/.cortex/ca/bundle.crt (valid, 129 certs). curl- and Python-based tools trust the bridge CA via those vars. Go-based tools (helm, and likely oc/kubectl plugins, gh in some builds) do not read *_CA_BUNDLE, and on macOS Go verifies against the System keychain rather than SSL_CERT_FILE — where the Cortex CA is absent. So any Go tool doing outbound TLS through the proxy fails.
Options considered (none applied)
- Add the Cortex CA to the macOS System keychain (
security add-trusted-cert -d -r trustRoot -k /Library/Keychains/System.keychain ~/.cortex/ca/bundle.crt) — fixes all Go tools, but is a sudo, machine-wide trust change. - Bypass the proxy for the helm step (
env -u HTTPS_PROXY ...) — loses Cortex token visibility for those calls.
Questions
- Is adding the bridge CA to the macOS System keychain the intended/supported fix for Go tools, and if so should
install.sh/agentopdo it (or offer it)? - Is there a supported way for Go/helm to pick up the CA without a system-wide keychain change?
- Is per-tool proxy bypass acceptable to Cortex's accounting model?
Environment
- OS:
Darwin arm64 - Cortex:
agentop v0.8.0 agentop service status: healthy; TLS bridge CA~/.cortex/ca/ca.crt(minted 2026-09-14), env vars point at~/.cortex/ca/bundle.crt- helm:
v4.2.3+g43e8b7f(Gogo1.25.1 darwin/arm64) - Agent: Claude Code, claude-opus-4-8
- Dominant language
- Go
- Stars
- 15
- Forks
- 41
- Avg merge
- 10h 43m
- Merged PRs (30d)
- 250
Getting set up
- No Dockerfile or Docker Compose file
- No pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from rossoctl/cortex
-
feedback laptop
Difficulty 1/5 Under an hour Newbie friendliness 78/100
Maintainers usually reply within 1 day
-
documentation question
Difficulty 1/5 Under an hour Newbie friendliness 68/100
rossoctl/cortex#1205 · 2 comments ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
rossoctl/cortex#1116 · 1 comment ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
Maintainers usually reply within 1 day
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
prime-radiant-inc/evener#4223 ·
Maintainers usually reply within 1 day
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
open-telemetry/opentelemetry-go-compile-instrumentation#1467 ·
Maintainers usually reply within 3 days
-
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
yetone/magpie#1490 · 1 comment ·
Maintainers usually reply within 1 day
-
bug
Difficulty 1/5 Under an hour Newbie friendliness 72/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
modelcontextprotocol/go-sdk#1367 · 1 comment ·
Maintainers usually reply within 1 day