mTLS
When control.tls is set, Conduit serves the control plane over TLS. If client_ca_path is also set, the server requires a client certificate signed by that CA (mutual TLS).
Configuring TLS
control:
listen_address: "0.0.0.0:5199"
tls:
cert_path: tls/server.pem
key_path: tls/server-key.pem
client_ca_path: tls/ca.pem # omit for TLS without client certs
Paths are config-relative unless absolute.
Clients
- Use
https://inCONDUIT_CONTROL/conduitctl --endpoint(or the client configendpoint) when the server uses TLS. - Trust the server with
--tls-ca/CONDUIT_TLS_CA/ client filetls.ca, or rely on the client’s normal trusted roots when the cert chains there. - For mTLS, present
--tls-certand--tls-key(or env / client filetls.cert/tls.key) matchingclient_ca_path. - Chain and hostname verification are on by default. Use
--tls-insecureonly as an explicit opt-out (for example a self-signed server cert without distributing a CA).
Full flag, env, and YAML client-file reference: gRPC and conduitctl — Connecting.
API keys (control.api_keys) apply independently: when keys are configured, callers still send Authorization: Bearer … even over mTLS.