Z
ZITADEL
Z
ZITADEL
Is anyone face this issue during install zitadel via helm chart?
Original message was deleted
ZITADEL
Join
ZITADEL - Identity infrastructure, simplified for you.
4,316
Members
View on Discord
F
FFO
β’
9/30/22, 2:04 PM
Hi there
, let me quickly check this
F
FFO
β’
9/30/22, 2:06 PM
Ok so you need to set TLS to false
E
.g
.
--set zitadel.configmapConfig.TLS.Enabled=false
--set zitadel.configmapConfig.TLS.Enabled=false
F
FFO
β’
9/30/22, 2:06 PM
Otherwise ZITADEL tries to load TLS keys while starting
F
FFO
β’
9/30/22, 2:11 PM
yes that makes sense
F
FFO
β’
9/30/22, 2:12 PM
ZITADEL by default does listen only to
l
o
c
a
l
h
o
s
t
:8080
F
FFO
β’
9/30/22, 2:13 PM
If you want zitadel to listen to other names you need to tell it this
.
https://docs.zitadel.com/docs/guides/manage/self-hosted/custom-domain
Custom Domain | ZITADEL Docs
This guide assumes you are already familiar with configuring ZITADEL
.
F
FFO
β’
10/1/22, 6:41 AM
Well zitadel needs to have the Hostname
otherwise it would not be feasible to run multiple instances in parallel
F
FFO
β’
10/1/22, 6:42 AM
We are open for ux changes in that regard
We did discuss if zitadel should accept all Hostnamen per default but this brings other challenges
(like from what domain should it send mails
, and more
)
F
FFO
β’
10/2/22, 3:46 PM
On what platform are you trying to deploy
? Docker compose
?
F
FFO
β’
10/2/22, 3:46 PM
Because in that case the docker
-compose
.yml already takes care of the cert to connect to the CRDB
F
FFO
β’
10/2/22, 3:47 PM
Ok
F
FFO
β’
10/2/22, 3:49 PM
I think you don
βt need to supply the certs if you deploy the whole chart directly
F
FFO
β’
10/2/22, 3:51 PM
Hm Strange we automated test the chart
F
FFO
β’
10/2/22, 3:52 PM
@Elio this one is for you
F
FFO
β’
10/2/22, 3:53 PM
I can look into this later as soon as I am on a pc
F
FFO
β’
10/2/22, 3:55 PM
Ok
F
FFO
β’
10/2/22, 4:46 PM
Ahh I see
F
FFO
β’
10/2/22, 4:47 PM
that has nothing to do with the database
. Instead it is the way zitadel should start
https://docs.zitadel.com/docs/guides/manage/self-hosted/tls_modes
TLS Modes | ZITADEL Docs
To allow ZITADEL to be run on any kind of infrastrucute it allows to configure on how tho handle TLS connections
.
F
FFO
β’
10/2/22, 4:49 PM
The TLS mode defines if ZITADEL should be connected from the outside world with TLS
, With TLS terminated at a proxy or without TLS eniterly
F
FFO
β’
10/2/22, 4:49 PM
This has nothing to do with the connection being made to the database with TLS
F
FFO
β’
10/2/22, 4:50 PM
So in your case if you run a proxy in front you should use tls
-mode external which disables the need for TLS certificates in ZITADEL
--set zitadel.configmapConfig.TLS.Enabled=false
--set zitadel.configmapConfig.TLS.Enabled=false