The DDEV mkcert root needs to be trusted in each workspace after it starts. This is especially important for templates with an ephemeral system trust store: a workspace restart can leave https://<project>.ddev.site untrusted even though the mkcert CA itself persists.
Please have every template run mkcert -install as the workspace user during its startup path. The operation is idempotent, so it is safe to run on every start and does not need a DDEV project to exist yet.
Acceptance criteria:
- A fresh workspace trusts the DDEV local CA before its first
ddev start.
- After a workspace restart, the CA is trusted again without a manual terminal step.
- This applies consistently to every maintained template.
Related historical issues: #58 and #193.
The DDEV mkcert root needs to be trusted in each workspace after it starts. This is especially important for templates with an ephemeral system trust store: a workspace restart can leave
https://<project>.ddev.siteuntrusted even though the mkcert CA itself persists.Please have every template run
mkcert -installas the workspace user during its startup path. The operation is idempotent, so it is safe to run on every start and does not need a DDEV project to exist yet.Acceptance criteria:
ddev start.Related historical issues: #58 and #193.