v1.9.5 — per-service TLS options for call_service
Added
- Per-service TLS options —
service_addnow acceptstls_insecureandca_bundle, andcall_servicehonours them via the existingnetguard.tls_verify()resolver (secure by default, #10 pattern — same asscan_add/webdav_add). This makes self-signed LAN services (e.g. a Crafty panel, which failed withSSL: CERTIFICATE_VERIFY_FAILED) reachable without weakening the default: verification stays ON unless an admin explicitly opts out,ca_bundle(pinned cert) takes precedence overtls_insecure, andservice_listvisibly flags such services with[TLS-INSECURE]. Merge-safe: updating other fields never resets a configured TLS opt-out. New tests:tests/test_service_tls.py.
Changed
netguard.tls_verifydocstring now listsservice_addamong the admin-only writers of TLS opt-out configs.
Deploy: docker compose pull aicortex && docker compose up -d aicortex — then ping = v1.9.5. A self-signed service is then reachable via service_add(name, base_url, tls_insecure=true) (admin-only).