Page MenuHomeSoftware Heritage

Move Web UI TLS termination out of Apache
Closed, MigratedEdits Locked

Description

As varnish is a http-only cache, it only supports connecting to backends unencrypted.

This means we need to move the TLS configuration out of Apache and into another tool. The standard to put in front of varnish seems to be hitch, so we'll go with that.

Event Timeline

olasd closed subtask T930: Create puppet manifest for hitch as Resolved.

The web UI (and deposit) TLS termination is now done inside hitch.