Skip to main content

Module path

Module path 

Source
Expand description

The path check: which request paths a rule applies to.

Matched against the profile-stripped path, so /directory — not /profile/default/directory — is the value to list, and one check covers every endpoint.

§What it replaces, and the trap it exists for

This is the successor to filter.exempt_paths, and the reason it is a check rather than a list is that a path is rarely the whole answer. As a rule it composes: public-paths or mgmt-net opens a path to everyone or an address to everything, and not public-paths and mgmt-net restricts a sensitive path to one network. The old list could only say “skip the connection stage entirely for this exact string”.

The concrete reason an operator needs it: /crl is served by the profile router, so it sits behind the policy like every other ACME resource. Turn on an address-based check without exempting it and every relying party outside the allowlist silently loses revocation checking — and relying parties are precisely not the ACME clients that were allowlisted. A public-paths check listing /crl is the companion to any address policy.

Server-level routes (GET /health, /, the http-01 responder) are served by the root router, which no profile’s policy ever sees, so they need no entry here.

§Globs

* matches one or more characters other than / — one path segment, the same “one component” reading * has in the name checks. So /renewalInfo/* covers every certificate id and nothing deeper, which the exact-match list it replaces could not express at all.

Structs§

PathList
Accepts or refuses a request by the path it asks for.
Settings
Resolved [filter.check.<name>] settings for type = "path".