What this test proves
This lane calls the peer doctor route over mTLS, then checks unauthenticated rejection before HTTP and DNS-based routing. The negative cases make the admission boundary observable.
Evidence layout
The runner writes immutable evidence for smoke-crosshost-curl-tls beneath site/reports/. The JSON payload is the source for case or worker outcomes; the rendered report and envelope provide the public navigation entry.
Changes
The revision sections below are the retained runner-history backfill. Each section records the source revision and its own ordered procedure description.
Flow
Steps
| step | action | observable | evidence |
|---|---|---|---|
| 1 | Execute `doctor` | The named check reports PASS or FAIL at revision `8043ce64` | `smoke-crosshost-curl-tls.json` cases |