Feat v0.6.7 native mtls #42

Merged
xcaliber merged 1 commits from feat/v0.6.7-native-mtls into main 2026-03-31 18:36:13 +00:00
Owner
No description provided.
xcaliber added 1 commit 2026-03-31 18:32:51 +00:00
Feat v0.6.7 native mTLS (#42)
All checks were successful
CI/CD / detect-changes (pull_request) Successful in 4s
CI/CD / test-frontend (pull_request) Successful in 6s
CI/CD / test-go-pg (pull_request) Successful in 2m44s
CI/CD / test-sqlite (pull_request) Successful in 2m50s
CI/CD / build-and-deploy (pull_request) Successful in 1m4s
1b095d50be
End-to-end mutual TLS without a reverse proxy. Go binary terminates
TLS itself via ListenAndServeTLS. TLS_MODE config (none/server/mtls)
is independent of AUTH_MODE.

- MTLSNativeProvider reads PeerCertificates directly (no header trust)
- Shared helpers extracted to mtls_helpers.go (ParseDN, FingerprintCert)
- MTLSProvider renamed to MTLSProxyProvider for clarity
- BuildPeerTLSConfig for future node-to-node mTLS
- switchboard-ca.sh: CA init, issue-node, issue-user (ECDSA P-256)
- 12 new tests (unit + TLS integration)

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
xcaliber merged commit fb5284f667 into main 2026-03-31 18:36:13 +00:00
xcaliber deleted branch feat/v0.6.7-native-mtls 2026-03-31 18:36:13 +00:00
This repo is archived. You cannot comment on pull requests.
No Reviewers
No Label
1 Participants
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: switchboard/core#42