Records completed staging/production issuance, ACME ownership of the live certificate files, and the remaining gateway passthrough observation.
Why
A later orchestrator session needs the accurate renewal state and security boundary without consulting certificate or service logs.
Evidence
Direct TLS to cc-ci presents the new Let’s Encrypt production certificate, valid through 2026-11-29.
acme-dns UDP/TCP authority, localhost-only API, disabled registration, and active renewal timer were verified.
The public gateway TCP endpoint currently closes TLS before forwarding; it is documented as operator-owned external infrastructure.
## What changed
Records completed staging/production issuance, ACME ownership of the live certificate files, and the remaining gateway passthrough observation.
## Why
A later orchestrator session needs the accurate renewal state and security boundary without consulting certificate or service logs.
## Evidence
- Direct TLS to cc-ci presents the new Let’s Encrypt production certificate, valid through 2026-11-29.
- acme-dns UDP/TCP authority, localhost-only API, disabled registration, and active renewal timer were verified.
- The public gateway TCP endpoint currently closes TLS before forwarding; it is documented as operator-owned external infrastructure.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
What changed
Records completed staging/production issuance, ACME ownership of the live certificate files, and the remaining gateway passthrough observation.
Why
A later orchestrator session needs the accurate renewal state and security boundary without consulting certificate or service logs.
Evidence