Dstack-TEE / Dstack-TEE/dstack

gateway: no automatic CAA reconciliation loop

Open
#1,010 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Rust
Stars
544
Forks
96
Avg merge
17h 57m
Merged PRs (30d)
117

Description

Follow-up to #935.

Two paths currently rely on an operator manually rerunning `SetCaa` to converge:

1. **Partial rotation failure** — `RotateAcmeCredentials` publishes the new credentials first, then re-pins CAA best-effort per domain. Domains that fail stay pinned to the old account until `SetCaa` is rerun; issuance for them fails CAA while existing certs keep serving, so the breakage can stay invisible for up to ~90 days.
2. **Domain-list skew** — rotation and `SetCaa` iterate the local WaveKV snapshot. A ZT domain added on another node but not yet synced is silently skipped and stays pinned to the old account.

Certificate renewal has a periodic task that retries until it converges; CAA has no equivalent.

## Proposal

Add a periodic reconciliation pass (piggybacking on the existing renewal loop) that:

- reads the published credential's `accounturi`;
- for each ZT domain, checks whether the CAA `issue`/`issuewild` records pin that URI (DNS read only in the common case);
- re-pins divergent domains via the existing `set_caa` path, logging loudly.

This removes both manual steps, converges the concurrent-rotation aftermath (#1008), and also cleans up leftover `;` guard records from an interrupted `set_caa_records` run. Cost is N DNS reads per interval — quantify, but at renewal-loop frequency this is negligible.

Contributor guide

Open the contributing guide

Research direction

Trace RotateAcmeCredentials, SetCaa, set_caa, set_caa_records, and the existing certificate-renewal periodic task. Start by understanding how published accounturi values and ZT domains are obtained, then verify that reconciliation checks CAA records and retries divergent domains. Done means partial rotations, domain-list skew, and leftover guard records converge without manual SetCaa reruns, with the DNS-read cost quantified.

Written by the indexing model from the issue text.

Assessment

Tech stack
rust
Domain
backend, networking
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
48/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.