Expand description
The path check: which request paths a rule applies to.
Matched against the profile-stripped path, so /directory — not
/profile/default/directory — is the value to list, and one check covers
every endpoint.
§What it replaces, and the trap it exists for
This is the successor to filter.exempt_paths, and the reason it is a check
rather than a list is that a path is rarely the whole answer. As a rule it
composes: public-paths or mgmt-net opens a path to everyone or an
address to everything, and not public-paths and mgmt-net restricts a
sensitive path to one network. The old list could only say “skip the
connection stage entirely for this exact string”.
The concrete reason an operator needs it: /crl is served by the profile
router, so it sits behind the policy like every other ACME resource. Turn
on an address-based check without exempting it and every relying party
outside the allowlist silently loses revocation checking — and relying
parties are precisely not the ACME clients that were allowlisted. A
public-paths check listing /crl is the companion to any address policy.
Server-level routes (GET /health, /, the http-01 responder) are served
by the root router, which no profile’s policy ever sees, so they need no
entry here.
§Globs
* matches one or more characters other than / — one path segment, the
same “one component” reading * has in the name checks. So
/renewalInfo/* covers every certificate id and nothing deeper, which the
exact-match list it replaces could not express at all.