abiosoft / abiosoft/colima

Certs placed in /etc/ssl/certs/certs.d and system bundle not updated

Aperta
#1,632 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub
Lingua principale
Go
Stelle
30.8k
Fork
613
Metriche di merge delle PR
Nessuna PR unita negli ultimi 30g

Descrizione

### Description

I'm running colima in an environment where custom CA certificates are needed for TLS connections. After recent changes to colima, the certs in my `~/.docker/certs.d` were not being placed directly into `/etc/ssl/certs` on the VM, but rather the `certs.d` directory itself was being copied there. A provisioning script workaround to move the certs to `/etc/ssl/certs` and to run `update-ca-certificates` gets TLS to work, but it is awkward, because the certs are copied to the VM after the provisioning script runs, so I have to reboot once for the provisioning script to be effective.

### Version

```
colima version 0.10.3
git commit: 00f6c297e92a82c04a4ab507db0a61435650d7e8

runtime: docker
arch: aarch64
client: v29.7.2
server: v29.5.2
limactl version 2.2.0
qemu-img version 11.0.3
Copyright (c) 2003-2026 Fabrice Bellard and the QEMU Project developers
```

### Operating System

- [ ] macOS Intel <= 13 (Ventura)
- [ ] macOS Intel >= 14 (Sonoma)
- [ ] Apple Silicon <= 13 (Ventura)
- [x] Apple Silicon >= 14 (Sonoma)
- [ ] Linux

### Output of `colima status`

```
time="2026-09-08T20:18:02-05:00" level=info msg="colima is running using macOS Virtualization.Framework"
time="2026-09-08T20:18:02-05:00" level=info msg="arch: aarch64"
time="2026-09-08T20:18:02-05:00" level=info msg="runtime: docker"
time="2026-09-08T20:18:02-05:00" level=info msg="mountType: sshfs"
time="2026-09-08T20:18:02-05:00" level=info msg="docker socket: unix:///Users/japitn/.colima/default/docker.sock"
time="2026-09-08T20:18:02-05:00" level=info msg="containerd socket: unix:///Users/japitn/.colima/default/containerd.sock"
```

### Reproduction Steps

1. Have some `.crt` CA certificate files in `~/.docker/certs.d`
2. Create a new colima VM
3. Using `colima ssh`, observe that the certificates are placed in `/etc/ssl/certs/certs.d`

### Expected behaviour

The certs probably should be placed in `/usr/local/share/ca-certificates`, and then `update-ca-certificates` should be run to update the system CA bundle.

### Additional context

I have four custom CA certificates to install in my environment. They are not specific to any particular Docker repository server.

Guida per i contributori

Nessuna guida per i contributori indicizzata per questo repository

Valutazione

Questa issue non è ancora stata valutata.

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.