Skip to content

Add additive corporate-CA support: APM_EXTRA_CA_BUNDLE (npm NODE_EXTRA_CA_CERTS parity) #2034

Description

Context

Fast-follow from the #2005 / #2004 OS-trust-store work. A red-team review (enterprise-proxy + package-manager-precedent panels) flagged that APM has no additive CA path: REQUESTS_CA_BUNDLE / CURL_CA_BUNDLE replace the trust set (and skip truststore injection entirely). Many enterprises hand developers a single corporate-root PEM but do not permit OS trust-store edits, so they need "OS roots plus this one extra CA", not "only this CA".

This is the standard npm model (NODE_EXTRA_CA_CERTS, additive) and Node's --use-system-ca (system + bundled + extra). APM lacks the equivalent.

Proposal

Add an additive APM_EXTRA_CA_BUNDLE (and optionally APM_EXTRA_CA_DIR) that is layered on top of the OS trust store rather than replacing it:

  • Implement via a scoped SSLContext that first loads the OS/certifi defaults, then load_verify_locations(APM_EXTRA_CA_BUNDLE) — OS/certifi defaults remain intact.
  • Propagate to apm run child runtimes through the same build_child_tls_env() seam introduced in feat(tls): verify against the OS trust store by default (closes #2004) #2005 (export the extra bundle so Python and Node children both honor it, e.g. NODE_EXTRA_CA_CERTS for Node runtimes).
  • Precedence must be documented explicitly alongside the existing REQUESTS_CA_BUNDLE (replace) and APM_DISABLE_TRUSTSTORE (opt-out) knobs.

Acceptance

  • An enterprise PEM set via APM_EXTRA_CA_BUNDLE is trusted in addition to the OS store for both apm install and apm run.
  • e2e test: private-CA server trusted via APM_EXTRA_CA_BUNDLE while public HTTPS (OS/certifi roots) still verifies.

Deferred deliberately from #2005 to avoid half-shipping (Node-only) the additive path.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area/docs-sitedocs/src/content (Starlight), README, doc generation.area/enterpriseAir-gapped/GHE configurability, registry proxy, rulesets, adoption playbook.priority/highHuman-set high priority; not scope approval, a release commitment or a required milestone.status/acceptedHuman scope approval; verify the issue's approval record and review contact before work.theme/securitySecure by default. Content scanning, lockfile integrity, MCP trust boundaries.triage/recommendedAutomated advice completed; not human scope approval.type/featureNew capability, new flag, new primitive.

    Type

    No type

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions