The DataMind Installer does not terminate TLS and does not manage certificates. Nothing in its repository issues, stores, places, validates or renews a certificate. This page states exactly what the Installer does, and where the certificate for a DataMind OS deployment is actually handled.
A DataMind OS deployment puts an edge web server, OpenResty, in front of the stack. It serves
the UI and checks the browser's Origin header against the platform's allowed origins.
The Installer's code states this directly: a scheme-less PLATFORM_URL "propagates into
NEST_ORIGINS (compared by openresty against the browser's Origin: header)". OpenResty is one of
the DataMind OS services the Installer deploys, and its own comment in the Installer describes
OpenResty as the component that "serves the UI and authorizes it".
So the certificate for the DataMind OS URL — the website layer that users reach — is the DataMind OS deployment's concern. The DataMind OS compose file that configures OpenResty is downloaded from blob storage at deploy time and is not part of the Installer repository.
Certificate provisioning and renewal for a DataMind OS deployment are handled with the DataMind OS stack, not with the DataMind Installer. This repository does not contain OpenResty's TLS configuration, so no renewal command can be given here. Certbot, ACME clients, Traefik and Caddy do not appear anywhere in the Installer repository.
Exactly one thing, and it only records paths:
During the Jenkins-migration flow, the configure dialog offers two optional fields — an SSL
certificate path and an SSL key path. They are saved as DataMind OS configuration values with the
codes SSL_CERT_PATH and SSL_KEY_PATH (through PATCH /api/configs/values). The Installer stores
the path strings and writes them into the DataMind OS .env; it never reads, checks or renews the
files they point to.
| Behaviour | Reality |
|---|---|
Collects SSL_CERT_PATH / SSL_KEY_PATH | Yes — optional, in the migration flow only |
| Places, validates or renews the certificate file | No |
| Terminates TLS for the DataMind OS URL | No |
| Terminates TLS for its own URL | No |
The Installer's own backend calls app.listen(port) with no TLS options, and its compose file
publishes ports: '${NEST_PORT:-8000}:${NEST_PORT:-8000}'. In the default setup the Installer
serves its packaged interface and its API on the same origin over plain HTTP, which is why the
compose file notes that NEST_ORIGINS is irrelevant by default.
To reach the Installer's interface over HTTPS, a TLS-terminating reverse proxy is placed in front of it on the host. The repository ships no such proxy and documents none; that proxy's certificate is host infrastructure, not Installer configuration.
Useful facts for that decision:
NEST_PORT defaults to 8000 and is the only port the Installer publishes.NEST_ORIGINS is the CORS allowlist, consulted only when the interface is served from a different
origin.The Installer normalises PLATFORM_URL before saving it. An explicitly typed scheme is always
preserved; otherwise a scheme is inferred from the host:
| Host | Inferred scheme |
|---|---|
localhost, *.localhost, *.local | http |
| Any IPv4 or IPv6 literal | http — raw IPs almost never have a trusted TLS certificate |
| Any real domain name | https |
Only http:// and https:// are accepted; anything else is rejected with
PLATFORM_URL must be an http:// or https:// address. This normalisation decides the string that
reaches the DataMind OS .env; it does not create or check a certificate.
nginx.serviceThe bare-metal retirement script, scripts/migrate-host.sh, lists nginx.service among the legacy
units it stops, disables and masks when a host moves onto Docker. That step retires the old
platform's web server; it does not configure, migrate or manage any certificate.
| Question | Where the answer lives |
|---|---|
| Who holds the certificate for the DataMind OS URL | The DataMind OS deployment's edge (OpenResty), configured with the DataMind OS stack |
| How it is obtained or renewed | With the DataMind OS stack — not in this repository |
| Where the certificate path is recorded | As the SSL_CERT_PATH / SSL_KEY_PATH configuration values, written into the DataMind OS .env |
| How to secure the Installer's own URL | A host reverse proxy in front of NEST_PORT, managed as host infrastructure |