Skip to main content
Put a load balancer, ingress or service mesh in front of Quivr to serve HTTPS. Configure outgoing TLS separately for each dependency in your engine configuration.

Prerequisites

You need operator access to your platform and the engine configuration, plus TLS endpoints for your dependencies. For a private certificate authority (CA), mount its PEM certificate bundle where the API, worker and quivr migrate process can read it. For Temporal, Weaviate, PostgreSQL or S3 client authentication, also mount a matching PEM certificate and private key for those processes.

Steps

  1. Configure your platform to terminate HTTPS and forward traffic to Quivr’s listen address over HTTP. Restrict that address to the platform’s network. Keep both API and worker probe_listen addresses private: their readiness and metrics endpoints have no authentication. Quivr serves plain HTTP on these addresses.
  2. Set public_url to the public HTTPS address if your connector plugins receive source webhooks. If your platform forwards source addresses, configure only its trusted network ranges in connector_push.trusted_proxy_cidrs.
  3. Set https:// URLs for Weaviate, S3 and plugins. Set tls.temporal.enabled to true; Temporal uses a host:port address. Set tls.postgres.enabled to true, or use sslmode=verify-full in database_url. See Outbound TLS for defaults and all fields.
  4. Add ca_file for a private CA. Omit it to use system roots. Add server_name only when the certificate names a different host from the connection address. Configure cert_file and key_file together when the dependency requires a client certificate; plugin client certificates are not supported.
  5. Apply the same settings to the API and worker, then restart both. Rerun quivr migrate with those settings when preparing a deployment.
For example, this unrun configuration excerpt enables Temporal client authentication with mounted certificates. Replace the paths and name with those issued for your deployment:
The files must exist inside each engine container, at the configured paths. Changing certificate files requires restarting the processes to load them again. Clients using S3 upload or download URLs also need to trust the S3 endpoint and supply client certificates if it requires them.

Check it worked

Check that your public API address presents your platform’s certificate and forwards API requests. Check GET /readyz on the API and on the private worker probe address; 204 means ready and 503 means unavailable: the API checks its database schema and search warm-up, and the worker also checks Temporal, S3 and Weaviate. A plugin’s availability is checked when Quivr calls it; an unavailable plugin does not prevent startup.

Troubleshooting

Next