Page MenuHomeVyOS Platform

pki: dependent conf_mode scripts run against a stale config cache within the same commit, causing ACME-imported CA chains to go missing
Closed, ResolvedPublicBUG

Description

When pki.py issues an ACME cert, it discovers the intermediate CA and injects it into the CLI via add_cli_node() as pki ca AUTOCHAIN_<cert>. This mutates the config backend directly, not the in-memory config tree already held by the current Config object. pki.py then triggers dependent scripts (HAProxy, HTTPS) through call_dependents(), reusing that same Config instance. Its cache was populated before the import, so dependents see a pre-import snapshot and their CA-chain logic finds nothing. Separately, certbot renewals skipped the import step entirely, so a broken cert could never self-correct.

system_login.py has the identical mutate-then call_dependents() shape and carries the same risk for its dependents.

Implement an automatic reload of the configuration object after mutation.

Details

Version
1.5.1
Is it a breaking change?
Perfectly compatible
Issue type
Bug (incorrect behavior)