- Sources: jakesaunders.dev post, HN discussion
- Summary: The post describes a sandboxed pipeline running on the author's own hardware that carries a single prompt through to a deployed application. The certificate handling is the transferable part: an ACME DNS-01 challenge driven through the registrar API issues a valid certificate for a hostname that has no public A record, so a service reachable only on the author's tailnet still serves HTTPS. The author states the hostname is still disclosed in certificate transparency logs.
- Why it matters: A DNS-01 challenge through the registrar API issues a valid certificate without publishing an A record, so a tailnet-only service gets HTTPS, and the author states the hostname still appears in certificate transparency logs.
send feedback on this story