Skip to content

fix(gateway): keep ACME issuance off the startup path and bound ACME requests - #1262

Merged
kvinwang merged 4 commits into
nextfrom
fix/gateway-startup-and-config
Sep 24, 2026
Merged

kvinwang merged 4 commits into
nextfrom
fix/gateway-startup-and-config

Conversation

@kvinwang

@kvinwang kvinwang commented Sep 20, 2026 •

Copy link
Copy Markdown
Collaborator

Two ways ACME work could block or hang the gateway.

  1. ProxyInner::new called certbot.init_all() before proxy::start bound any listener. It does ACME/DNS I/O per domain, and request_new_cert slept a hard-coded 30s when another node held the cert lock. It is redundant: certificates already in the KV store are loaded into the resolver just above it, and start_certbot_task spawns a full renew_cert(None, false) pass that issues for domains without a certificate. Removed init_all, init_domain and request_new_cert (single-caller each).
  2. ReqwestHttpClient uses reqwest's async client, which has no default timeout. ensure_acme_account / rotate_acme_credentials run under the cluster ACME lock with no outer bound, so a silent ACME directory held the lock until it expired. Each request now has a 30s timeout.

Split out: peer HTTPS timeout (#1374), dead external_port key (#1375).

Verification: cargo test -p dstack-gateway -p certbot passes; fmt and clippy clean.

@kvinwang
kvinwang force-pushed the fix/gateway-startup-and-config branch from 8577bf8 to 960dcfc Compare September 24, 2026 08:42
@kvinwang kvinwang changed the title fix(gateway): ACME issuance blocks startup, peer HTTPS has no timeout, and external_port is dead config fix(gateway): keep ACME issuance off the startup path and bound ACME directory requests Sep 24, 2026
@kvinwang kvinwang changed the title fix(gateway): keep ACME issuance off the startup path and bound ACME directory requests fix(gateway): keep ACME issuance off the startup path and bound ACME requests Sep 24, 2026
…nd-config

# Conflicts:
#	dstack/gateway/src/distributed_certbot.rs
@kvinwang
kvinwang merged commit 40ae882 into next Sep 24, 2026
15 checks passed
@kvinwang
kvinwang deleted the fix/gateway-startup-and-config branch September 24, 2026 14:24
kvinwang added a commit that referenced this pull request Sep 25, 2026
…in spelling

PR #1262 removed certificate issuance from the startup path; the
certificate-bootstrap cases now restart a node against a silent ACME
directory with an uncertified domain configured and require it to listen.
PR #1356 normalizes the domain in ForceReleaseCertLock and
ListCertAttestations; tc-gw-certificat-002 releases a crashed node's lock
with a non-normalized spelling and tc-gw-certificat-007 lists history
under one.

Signed-off-by: Kevin Wang <wy721@qq.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant