Skip to content

latest

Pre-release
Pre-release

Choose a tag to compare

@fourdollars fourdollars released this 29 Apr 14:54
· 13 commits to main since this release
proxy: point NODE_EXTRA_CA_CERTS to system CA bundle

OpenClaw gateway systemd service sets NODE_EXTRA_CA_CERTS to
/etc/ssl/certs/ca-certificates.crt (the system CA bundle). Since
update-ca-certificates merges our cert into this bundle, pointing
profile.d to the same path is sufficient.

Remove all extra system modifications (/etc/environment, npm cafile,
NODE_OPTIONS). The only things cella injects are:
1. CA cert file
2. update-ca-certificates (merges into system bundle)
3. /etc/profile.d script (for login shells)

For LXD: environment.NODE_EXTRA_CA_CERTS via LXD API (already existed)
ensures the container env has it for all processes.

For Docker: profile.d covers login shells; OpenClaw gateway should be
started via openclaw gateway start (which creates a systemd service
with NODE_EXTRA_CA_CERTS) or with the env var explicitly set.