latest
Pre-release
Pre-release
proxy: point NODE_EXTRA_CA_CERTS to system CA bundle OpenClaw gateway systemd service sets NODE_EXTRA_CA_CERTS to /etc/ssl/certs/ca-certificates.crt (the system CA bundle). Since update-ca-certificates merges our cert into this bundle, pointing profile.d to the same path is sufficient. Remove all extra system modifications (/etc/environment, npm cafile, NODE_OPTIONS). The only things cella injects are: 1. CA cert file 2. update-ca-certificates (merges into system bundle) 3. /etc/profile.d script (for login shells) For LXD: environment.NODE_EXTRA_CA_CERTS via LXD API (already existed) ensures the container env has it for all processes. For Docker: profile.d covers login shells; OpenClaw gateway should be started via openclaw gateway start (which creates a systemd service with NODE_EXTRA_CA_CERTS) or with the env var explicitly set.