Prerequisites
You need operator access to your platform and the engine configuration, plus TLS endpoints for your dependencies. For a private certificate authority (CA), mount its PEM certificate bundle where the API, worker andquivr migrate process can read it. For Temporal, Weaviate, PostgreSQL or S3 client authentication, also mount a matching PEM certificate and private key for those processes.
Steps
- Configure your platform to terminate HTTPS and forward traffic to Quivr’s
listenaddress over HTTP. Restrict that address to the platform’s network. Keep both API and workerprobe_listenaddresses private: their readiness and metrics endpoints have no authentication. Quivr serves plain HTTP on these addresses. - Set
public_urlto the public HTTPS address if your connector plugins receive source webhooks. If your platform forwards source addresses, configure only its trusted network ranges inconnector_push.trusted_proxy_cidrs. - Set
https://URLs for Weaviate, S3 and plugins. Settls.temporal.enabledtotrue; Temporal uses ahost:portaddress. Settls.postgres.enabledtotrue, or usesslmode=verify-fullindatabase_url. See Outbound TLS for defaults and all fields. - Add
ca_filefor a private CA. Omit it to use system roots. Addserver_nameonly when the certificate names a different host from the connection address. Configurecert_fileandkey_filetogether when the dependency requires a client certificate; plugin client certificates are not supported. - Apply the same settings to the API and worker, then restart both. Rerun
quivr migratewith those settings when preparing a deployment.
Check it worked
Check that your public API address presents your platform’s certificate and forwards API requests. CheckGET /readyz on the API and on the private worker probe address; 204 means ready and 503 means unavailable: the API checks its database schema and search warm-up, and the worker also checks Temporal, S3 and Weaviate. A plugin’s availability is checked when Quivr calls it; an unavailable plugin does not prevent startup.
Troubleshooting
Next
- Configuration reference for the exact TLS settings.
- Operate a Quivr deployment for other operator tasks.