The acme_zone reactor's first ACL branch iterates nodes that have letsencrypt/domains and reads their network/internal/ipv4. Until now that crashed for any node with letsencrypt but no internal LAN — the node had to either fake a network/internal/ipv4 or skip TLS. Add a `metadata.get(..., None)` guard to filter such nodes out of this branch. The wireguard branch below already covers them (any node with the wireguard bundle gets its wireguard/my_ip into the ACL), so ACME DNS-01 reachability still works for cross-Internet nodes that join the fleet via wireguard. Surfaced by ovh.left4me: dedicated server with no Hetzner/internal network, reachable from the bind-acme node only via wireguard. |
||
|---|---|---|
| .. | ||
| metadata.py | ||