"""Verify TLS against this machine's own trust store as well as certifi's. `httpx` verifies against the `certifi` bundle, which carries the public web's certificate authorities and nothing else. A trusted-LAN inference host often has no public certificate: on a StartOS server, Ollama is served over HTTPS with a certificate from a local CA that the user installs on the machines they use it from. `curl` and the browser accepted such an endpoint; this application refused it: Connection failed: [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: self-signed certificate in certificate chain That is a wrong answer for the deployment this project targets (`planning/DECISIONS/002-ollama-only-v1.md`), because the user had already made the decision to trust that CA, at the level where such decisions belong. So the rule is the one a user already expects from everything else on their machine: **a CA installed on this host is trusted by this application.** This is not a relaxation of verification. Certificates are still verified, hostnames are still checked, and a certificate signed by nobody the machine trusts is still refused — `AIDND_ENDPOINT_INSECURE` and its like deliberately do not exist. The two stores are unioned rather than swapped. `ssl.create_default_context()` alone would be a behaviour *change* — it loads only the platform's default CA locations (`/etc/ssl/certs` on Debian and Ubuntu), and a stripped-down image whose system store is empty or stale would start failing on endpoints that used to work. Adding certifi on top makes this a strict superset of the old behaviour, so nothing that verified before can stop verifying now. Building a context parses every certificate in both stores, so it is done once and cached. The result is read-only afterwards and is shared safely across concurrent requests. """ import functools import ssl import certifi @functools.lru_cache(maxsize=1) def ssl_context() -> ssl.SSLContext: """The verification context every outbound HTTPS client should use.""" context = ssl.create_default_context() # the platform's CA store context.load_verify_locations(cafile=certifi.where()) # plus the public web's return context