When the proxy asks whether a domain may get a certificate, a refusal is logged without the domain #107

Open
opened 2026-09-21 07:18:32 +00:00 by cgalo5758 · 0 comments
Owner

What a person cannot do today

Find out which domains the TLS proxy is asking about. Before issuing a certificate for a domain, the proxy sends the console an ask (a request the registry answers yes or no), and a wildcard DNS record draws a steady stream of asks from scanners, all refused. The request log records the path and never the query string, the authorizer logs a refusal only at debug level, and the fallback answerer (the legacy service consulted for domains the registry does not know) logs nothing. When the operator wants to know whether a burst is a scanner or one client stuck retrying a deleted site, nothing on the host can say without a packet capture.

What they should be able to do

See, on the Domains page, how many asks were refused in the last hour and for which domains, and read the same figures in the log when they are not zero.

Why it matters

Refused asks are the one signal of what the outside world expects the deployment to serve. They also show a member whose site is being asked for before its placement (the row that wires the domain to the site) exists.

Where

internal/domains, the ask handler; the Domains page.

Done when

A rolling per-domain counter of refused asks, shown on the Domains page as a count with the top domains, and written to the log once a minute when nonzero. Not a log line per request, which at scanner rates is noise.

Migrated from status/issues.md at b7a0e15

## What a person cannot do today Find out which domains the TLS proxy is asking about. Before issuing a certificate for a domain, the proxy sends the console an ask (a request the registry answers yes or no), and a wildcard DNS record draws a steady stream of asks from scanners, all refused. The request log records the path and never the query string, the authorizer logs a refusal only at debug level, and the fallback answerer (the legacy service consulted for domains the registry does not know) logs nothing. When the operator wants to know whether a burst is a scanner or one client stuck retrying a deleted site, nothing on the host can say without a packet capture. ## What they should be able to do See, on the Domains page, how many asks were refused in the last hour and for which domains, and read the same figures in the log when they are not zero. ## Why it matters Refused asks are the one signal of what the outside world expects the deployment to serve. They also show a member whose site is being asked for before its placement (the row that wires the domain to the site) exists. ## Where [`internal/domains`](https://git.coopcloud.tech/wiki-cafe/member-console/src/commit/b7a0e15/internal/domains), the ask handler; the Domains page. ## Done when A rolling per-domain counter of refused asks, shown on the Domains page as a count with the top domains, and written to the log once a minute when nonzero. Not a log line per request, which at scanner rates is noise. Migrated from status/issues.md at b7a0e15
cgalo5758 added the
kind
enhancement
area/domainsarea/ops
labels 2026-09-21 07:18:32 +00:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: wiki-cafe/member-console#107