public inbox for pbs-devel@lists.proxmox.com
 help / color / mirror / Atom feed
From: Samuel Rufinatscha <s.rufinatscha@proxmox.com>
To: pbs-devel@lists.proxmox.com
Subject: [PATCH proxmox 2/2] acme-api: support HTTP proxies
Date: Thu,  8 Oct 2026 17:33:20 +0200	[thread overview]
Message-ID: <20261008153323.293158-3-s.rufinatscha@proxmox.com> (raw)
In-Reply-To: <20261008153323.293158-1-s.rufinatscha@proxmox.com>

Accept an optional proxy configuration for operations that contact
the ACME server and pass it to each new client.

Signed-off-by: Samuel Rufinatscha <s.rufinatscha@proxmox.com>
---
 proxmox-acme-api/Cargo.toml                 |  2 ++
 proxmox-acme-api/src/account_api_impl.rs    | 27 +++++++++++++++------
 proxmox-acme-api/src/account_config.rs      |  5 ++--
 proxmox-acme-api/src/certificate_helpers.rs | 12 ++++++---
 4 files changed, 34 insertions(+), 12 deletions(-)

diff --git a/proxmox-acme-api/Cargo.toml b/proxmox-acme-api/Cargo.toml
index 4bb1720b..9229d4ea 100644
--- a/proxmox-acme-api/Cargo.toml
+++ b/proxmox-acme-api/Cargo.toml
@@ -30,6 +30,7 @@ openssl = { workspace = true, optional = true }
 proxmox-acme = { workspace = true, features = ["api-types"] }
 proxmox-base64 = { workspace = true, optional = true }
 proxmox-config-digest = { workspace = true, optional = true }
+proxmox-http = { workspace = true, optional = true }
 proxmox-log = { workspace = true, optional = true }
 proxmox-product-config = { workspace = true, optional = true }
 proxmox-rest-server = { workspace = true, optional = true }
@@ -57,6 +58,7 @@ impl = [
 
     "dep:proxmox-base64",
     "dep:proxmox-config-digest",
+    "dep:proxmox-http",
     "dep:proxmox-log",
     "dep:proxmox-product-config",
     "dep:proxmox-rest-server",
diff --git a/proxmox-acme-api/src/account_api_impl.rs b/proxmox-acme-api/src/account_api_impl.rs
index ef195908..d42a475f 100644
--- a/proxmox-acme-api/src/account_api_impl.rs
+++ b/proxmox-acme-api/src/account_api_impl.rs
@@ -7,6 +7,7 @@ use serde_json::json;
 
 use proxmox_acme::async_client::AcmeClient;
 use proxmox_acme::types::AccountData as AcmeAccountData;
+use proxmox_http::ProxyConfig;
 use proxmox_log::warn;
 
 use crate::account_config::AccountData;
@@ -41,9 +42,12 @@ pub async fn get_account(account_name: AcmeAccountName) -> Result<AccountInfo, E
     })
 }
 
-pub async fn get_tos(directory: Option<String>) -> Result<Option<String>, Error> {
+pub async fn get_tos(
+    directory: Option<String>,
+    proxy_config: Option<ProxyConfig>,
+) -> Result<Option<String>, Error> {
     let directory = directory.unwrap_or_else(|| DEFAULT_ACME_DIRECTORY_ENTRY.url.to_string());
-    Ok(AcmeClient::new(directory)
+    Ok(AcmeClient::with_proxy(directory, proxy_config)
         .terms_of_service_url()
         .await?
         .map(str::to_owned))
@@ -55,11 +59,12 @@ pub async fn register_account(
     tos_url: Option<String>,
     directory_url: Option<String>,
     eab_creds: Option<(String, String)>,
+    proxy_config: Option<ProxyConfig>,
 ) -> Result<String, Error> {
     let directory_url =
         directory_url.unwrap_or_else(|| DEFAULT_ACME_DIRECTORY_ENTRY.url.to_string());
 
-    let mut client = AcmeClient::new(directory_url.clone());
+    let mut client = AcmeClient::with_proxy(directory_url.clone(), proxy_config);
 
     let contact = account_contact_from_string(&contact);
     let account = client
@@ -73,9 +78,13 @@ pub async fn register_account(
     Ok(account.location)
 }
 
-pub async fn deactivate_account(name: &AcmeAccountName, force: bool) -> Result<(), Error> {
+pub async fn deactivate_account(
+    name: &AcmeAccountName,
+    force: bool,
+    proxy_config: Option<ProxyConfig>,
+) -> Result<(), Error> {
     let mut account_data = super::account_config::load_account_config(name).await?;
-    let mut client = account_data.client();
+    let mut client = account_data.client(proxy_config);
 
     match client
         .update_account(&json!({"status": "deactivated"}))
@@ -99,9 +108,13 @@ pub async fn deactivate_account(name: &AcmeAccountName, force: bool) -> Result<(
     Ok(())
 }
 
-pub async fn update_account(name: &AcmeAccountName, contact: Option<String>) -> Result<(), Error> {
+pub async fn update_account(
+    name: &AcmeAccountName,
+    contact: Option<String>,
+    proxy_config: Option<ProxyConfig>,
+) -> Result<(), Error> {
     let mut account_data = super::account_config::load_account_config(name).await?;
-    let mut client = account_data.client();
+    let mut client = account_data.client(proxy_config);
 
     let data = match contact {
         Some(contact) => json!({
diff --git a/proxmox-acme-api/src/account_config.rs b/proxmox-acme-api/src/account_config.rs
index ce128c45..387f002c 100644
--- a/proxmox-acme-api/src/account_config.rs
+++ b/proxmox-acme-api/src/account_config.rs
@@ -8,6 +8,7 @@ use std::path::{Path, PathBuf};
 use anyhow::{Error, bail, format_err};
 use serde::{Deserialize, Serialize};
 
+use proxmox_http::ProxyConfig;
 use proxmox_product_config::replace_secret_config;
 use proxmox_sys::error::SysError;
 
@@ -68,8 +69,8 @@ impl AccountData {
         }
     }
 
-    pub fn client(&self) -> AcmeClient {
-        let mut client = AcmeClient::new(self.directory_url.clone());
+    pub fn client(&self, proxy_config: Option<ProxyConfig>) -> AcmeClient {
+        let mut client = AcmeClient::with_proxy(self.directory_url.clone(), proxy_config);
         client.set_account(Account {
             location: self.location.clone(),
             private_key: self.key.clone(),
diff --git a/proxmox-acme-api/src/certificate_helpers.rs b/proxmox-acme-api/src/certificate_helpers.rs
index 323f4b4a..d43e8f62 100644
--- a/proxmox-acme-api/src/certificate_helpers.rs
+++ b/proxmox-acme-api/src/certificate_helpers.rs
@@ -10,6 +10,7 @@ use openssl::rsa::Rsa;
 use openssl::x509::{X509, X509Builder};
 
 use proxmox_acme::async_client::AcmeClient;
+use proxmox_http::ProxyConfig;
 use proxmox_log::{info, warn};
 use proxmox_rest_server::WorkerTask;
 
@@ -18,10 +19,14 @@ use crate::types::{AcmeConfig, AcmeDomain};
 
 const ACME_POLL_TIMEOUT: Duration = Duration::from_secs(5 * 60);
 
-pub async fn revoke_certificate(acme_config: &AcmeConfig, certificate: &[u8]) -> Result<(), Error> {
+pub async fn revoke_certificate(
+    acme_config: &AcmeConfig,
+    certificate: &[u8],
+    proxy_config: Option<ProxyConfig>,
+) -> Result<(), Error> {
     let mut acme = super::account_config::load_account_config(&acme_config.account)
         .await?
-        .client();
+        .client(proxy_config);
 
     acme.revoke_certificate(certificate, None).await?;
 
@@ -37,6 +42,7 @@ pub async fn order_certificate(
     worker: Arc<WorkerTask>,
     acme_config: &AcmeConfig,
     domains: &[AcmeDomain],
+    proxy_config: Option<ProxyConfig>,
 ) -> Result<Option<OrderedCertificate>, Error> {
     use proxmox_acme::authorization::Status;
     use proxmox_acme::order::Identifier;
@@ -55,7 +61,7 @@ pub async fn order_certificate(
 
     let mut acme = super::account_config::load_account_config(&acme_config.account)
         .await?
-        .client();
+        .client(proxy_config);
 
     let (plugins, _) = super::plugin_config::plugin_config()?;
 
-- 
2.47.3





  parent reply	other threads:[~2026-10-08 15:33 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-08 15:33 [PATCH proxmox{,-backup,-datacenter-manager} 0/4] fix #6173: acme: use the configured HTTP proxy Samuel Rufinatscha
2026-10-08 15:33 ` [PATCH proxmox 1/2] acme: async_client: support HTTP proxies Samuel Rufinatscha
2026-10-08 15:33 ` Samuel Rufinatscha [this message]
2026-10-08 15:33 ` [PATCH proxmox-backup 1/1] fix #6173: acme: use the configured HTTP proxy Samuel Rufinatscha
2026-10-08 15:33 ` [PATCH proxmox-datacenter-manager " Samuel Rufinatscha

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261008153323.293158-3-s.rufinatscha@proxmox.com \
    --to=s.rufinatscha@proxmox.com \
    --cc=pbs-devel@lists.proxmox.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
Service provided by Proxmox Server Solutions GmbH | Privacy | Legal