• Sources: jakesaunders.dev post, HN discussion
  • Summary: The post describes a sandboxed pipeline running on the author's own hardware that carries a single prompt through to a deployed application. The certificate handling is the transferable part: an ACME DNS-01 challenge driven through the registrar API issues a valid certificate for a hostname that has no public A record, so a service reachable only on the author's tailnet still serves HTTPS. The author states the hostname is still disclosed in certificate transparency logs.
  • Why it matters: A DNS-01 challenge through the registrar API issues a valid certificate without publishing an A record, so a tailnet-only service gets HTTPS, and the author states the hostname still appears in certificate transparency logs.

send feedback on this story