Commit Graph
1 Commits
  • fix(dns_oci): read ~/.oci/config before cached account.conf values (#7124)
    The OCI DNS plugin cached the tenancy, user, region and signing key into
    acme.sh's account.conf at issuance and then, on subsequent runs, read those
    cached values before consulting ~/.oci/config. A value cached at issuance
    therefore permanently shadowed the config file, so editing ~/.oci/config
    afterwards (most visibly rotating the API signing key) had no effect and
    renewals kept using stale credentials, failing authentication.
    
    Resolve each field in the order: explicit environment variable, then
    ~/.oci/config when it exists, then the cached account.conf value as a
    fallback for env-only installs that have no config file. The signing key
    likewise prefers the key_file resolved from the environment or ~/.oci/config
    over any cached key.
    
    Signed-off-by: Avi Miller <me@dje.li>