Repository navigation
Add additive corporate-CA support: APM_EXTRA_CA_BUNDLE (npm NODE_EXTRA_CA_CERTS parity) #2034
Copy link
Copy link
Open
Labels
area/docs-sitedocs/src/content (Starlight), README, doc generation.docs/src/content (Starlight), README, doc generation.area/enterpriseAir-gapped/GHE configurability, registry proxy, rulesets, adoption playbook.Air-gapped/GHE configurability, registry proxy, rulesets, adoption playbook.priority/highHuman-set high priority; not scope approval, a release commitment or a required milestone.Human-set high priority; not scope approval, a release commitment or a required milestone.status/acceptedHuman scope approval; verify the issue's approval record and review contact before work.Human scope approval; verify the issue's approval record and review contact before work.theme/securitySecure by default. Content scanning, lockfile integrity, MCP trust boundaries.Secure by default. Content scanning, lockfile integrity, MCP trust boundaries.triage/recommendedAutomated advice completed; not human scope approval.Automated advice completed; not human scope approval.type/featureNew capability, new flag, new primitive.New capability, new flag, new primitive.
Description
Activity
Metadata
Metadata
Assignees
Labels
area/docs-sitedocs/src/content (Starlight), README, doc generation.docs/src/content (Starlight), README, doc generation.area/enterpriseAir-gapped/GHE configurability, registry proxy, rulesets, adoption playbook.Air-gapped/GHE configurability, registry proxy, rulesets, adoption playbook.priority/highHuman-set high priority; not scope approval, a release commitment or a required milestone.Human-set high priority; not scope approval, a release commitment or a required milestone.status/acceptedHuman scope approval; verify the issue's approval record and review contact before work.Human scope approval; verify the issue's approval record and review contact before work.theme/securitySecure by default. Content scanning, lockfile integrity, MCP trust boundaries.Secure by default. Content scanning, lockfile integrity, MCP trust boundaries.triage/recommendedAutomated advice completed; not human scope approval.Automated advice completed; not human scope approval.type/featureNew capability, new flag, new primitive.New capability, new flag, new primitive.
Type
Projects
- StatusShow more project fieldsTodo
Context
Fast-follow from the #2005 / #2004 OS-trust-store work. A red-team review (enterprise-proxy + package-manager-precedent panels) flagged that APM has no additive CA path:
REQUESTS_CA_BUNDLE/CURL_CA_BUNDLEreplace the trust set (and skip truststore injection entirely). Many enterprises hand developers a single corporate-root PEM but do not permit OS trust-store edits, so they need "OS roots plus this one extra CA", not "only this CA".This is the standard npm model (
NODE_EXTRA_CA_CERTS, additive) and Node's--use-system-ca(system + bundled + extra). APM lacks the equivalent.Proposal
Add an additive
APM_EXTRA_CA_BUNDLE(and optionallyAPM_EXTRA_CA_DIR) that is layered on top of the OS trust store rather than replacing it:SSLContextthat first loads the OS/certifi defaults, thenload_verify_locations(APM_EXTRA_CA_BUNDLE)— OS/certifi defaults remain intact.apm runchild runtimes through the samebuild_child_tls_env()seam introduced in feat(tls): verify against the OS trust store by default (closes #2004) #2005 (export the extra bundle so Python and Node children both honor it, e.g.NODE_EXTRA_CA_CERTSfor Node runtimes).REQUESTS_CA_BUNDLE(replace) andAPM_DISABLE_TRUSTSTORE(opt-out) knobs.Acceptance
APM_EXTRA_CA_BUNDLEis trusted in addition to the OS store for bothapm installandapm run.APM_EXTRA_CA_BUNDLEwhile public HTTPS (OS/certifi roots) still verifies.Deferred deliberately from #2005 to avoid half-shipping (Node-only) the additive path.