Add troubleshooting section for https (#754)

* Add troubleshooting section for https

Co-Authored-By: Luke Kysow <1034429+lkysow@users.noreply.github.com>
This commit is contained in:
Julien Bisconti
2019-08-22 13:58:37 +02:00
committed by Luke Kysow
parent 3851df8c84
commit 6451ff60ba
2 changed files with 34 additions and 0 deletions

View File

@@ -0,0 +1,27 @@
# HTTPS, SSL, TLS
When using a self-signed certificate for Atlantis (with flags `--ssl-cert-file` and `--ssl-key-file`),
there are a few considerations.
Atlantis uses the web server from the standard Go library,
the method name is [ListenAndServeTLS](https://golang.org/pkg/net/http/#ListenAndServeTLS).
`ListenAndServeTLS` acts identically to [ListenAndServe](https://golang.org/pkg/net/http/#ListenAndServe),
except that it expects HTTPS connections.
Additionally, files containing a certificate and matching private key for the server must be provided.
If the certificate is signed by a certificate authority,
the file passed to `--ssl-cert-file` should be the concatenation of the server's certificate, any intermediates, and the CA's certificate.
If you have this error when specifying a TLS cert with a key:
```
[EROR] server.go:413 server: Tls: private key does not match public key
```
Check that the locally signed certificate authority is prepended to the self signed certificate.
A good example is shown at [Seth Vargo terraform implementation of atlantis-on-gke](https://github.com/sethvargo/atlantis-on-gke/blob/master/terraform/tls.tf#L64)
For Go specific TLS resources have a look at the repository by [denji called golang-tls](https://github.com/denji/golang-tls).
For a complete explanation on PKI, read this [article](https://smallstep.com/blog/everything-pki.html).