Skip to content

Configure HTTPS

By default, TestGen serves its web UI, API, and MCP server over HTTP. To serve them over HTTPS, provide an SSL certificate and private key. When both are configured, TestGen serves the UI, API, and MCP server over TLS.

Prerequisites

Tip

When installing with dk-installer, you can enable HTTPS during installation instead of afterward by passing the --ssl-cert-file and --ssl-key-file options. See Installation options.

Configure SSL

  1. Navigate to the directory that contains the docker-compose.yml file for TestGen.

    • If the instance was installed using dk-installer.exe, the file can be located under "AppData\Local\DataKitchenApps".
    • If the instance was installed using dk-installer, the file can be located in the folder from which the Python installer was executed.
  2. Add the certificate and key as bind mounts on the engine service.

    services:
      engine:
        volumes:
          - type: bind
            source: <path to certificate file>
            target: /dk/ssl/cert.crt
          - type: bind
            source: <path to key file>
            target: /dk/ssl/cert.key
    
  3. Add the following lines under the x-common-variables section.

    x-common-variables: &common-variables
     SSL_CERT_FILE: /dk/ssl/cert.crt
     SSL_KEY_FILE: /dk/ssl/cert.key
    
  4. Map the host's HTTPS port to the UI in the engine service's ports section, for example, to serve the UI on port 443.

    services:
      engine:
        ports:
          - 443:8501
          - 8530:8530
    
  5. Update TG_UI_BASE_URL and TG_BASE_URL to use the https scheme, the host name on your certificate, and the host ports from the previous step.

    x-common-variables: &common-variables
     TG_UI_BASE_URL: https://<host>
     TG_BASE_URL: https://<host>:8530
    
  6. Restart the application.

    docker compose up -d --wait
    

Note

If you terminate TLS at a reverse proxy (for example, NGINX) in front of TestGen, configure the certificate on the proxy instead and leave SSL_CERT_FILE and SSL_KEY_FILE unset. Set TG_UI_BASE_URL and TG_BASE_URL to the URLs that the proxy serves.

  1. Open the ~/.testgen/config.env file in a text editor.

  2. Add the paths to your certificate and key files (one variable per line, no quotes).

    SSL_CERT_FILE=<path to certificate file>
    SSL_KEY_FILE=<path to key file>
    
  3. Update TG_UI_BASE_URL and TG_BASE_URL to use the https scheme and the host name on your certificate.

    TG_UI_BASE_URL=https://<host>:8501
    TG_BASE_URL=https://<host>:8530
    
  4. Restart the application. Stop the running TestGen process with Ctrl+C in the terminal where it is running, then start it again.

    python3 dk-installer.py tg start
    

Note

If you terminate TLS at a reverse proxy (for example, NGINX) in front of TestGen, configure the certificate on the proxy instead and leave SSL_CERT_FILE and SSL_KEY_FILE unset. Set TG_UI_BASE_URL and TG_BASE_URL to the URLs that the proxy serves.

TLS terminates at the ingress, which holds the certificate. Configure it in the ingress section of values-tg-app.yaml, as outlined in Install on Kubernetes.