TLS and Certificates

The DataMind Installer does not terminate TLS and does not manage certificates. Nothing in its repository issues, stores, places, validates or renews a certificate. This page states exactly what the Installer does, and where the certificate for a DataMind OS deployment is actually handled.

What terminates TLS in a DataMind OS deployment

A DataMind OS deployment puts an edge web server, OpenResty, in front of the stack. It serves the UI and checks the browser's Origin header against the platform's allowed origins.

The Installer's code states this directly: a scheme-less PLATFORM_URL "propagates into NEST_ORIGINS (compared by openresty against the browser's Origin: header)". OpenResty is one of the DataMind OS services the Installer deploys, and its own comment in the Installer describes OpenResty as the component that "serves the UI and authorizes it".

So the certificate for the DataMind OS URL — the website layer that users reach — is the DataMind OS deployment's concern. The DataMind OS compose file that configures OpenResty is downloaded from blob storage at deploy time and is not part of the Installer repository.

Important

Certificate provisioning and renewal for a DataMind OS deployment are handled with the DataMind OS stack, not with the DataMind Installer. This repository does not contain OpenResty's TLS configuration, so no renewal command can be given here. Certbot, ACME clients, Traefik and Caddy do not appear anywhere in the Installer repository.

What the Installer does about certificates

Exactly one thing, and it only records paths:

During the Jenkins-migration flow, the configure dialog offers two optional fields — an SSL certificate path and an SSL key path. They are saved as DataMind OS configuration values with the codes SSL_CERT_PATH and SSL_KEY_PATH (through PATCH /api/configs/values). The Installer stores the path strings and writes them into the DataMind OS .env; it never reads, checks or renews the files they point to.

BehaviourReality
Collects SSL_CERT_PATH / SSL_KEY_PATHYes — optional, in the migration flow only
Places, validates or renews the certificate fileNo
Terminates TLS for the DataMind OS URLNo
Terminates TLS for its own URLNo

The Installer serves over plain HTTP

The Installer's own backend calls app.listen(port) with no TLS options, and its compose file publishes ports: '${NEST_PORT:-8000}:${NEST_PORT:-8000}'. In the default setup the Installer serves its packaged interface and its API on the same origin over plain HTTP, which is why the compose file notes that NEST_ORIGINS is irrelevant by default.

To reach the Installer's interface over HTTPS, a TLS-terminating reverse proxy is placed in front of it on the host. The repository ships no such proxy and documents none; that proxy's certificate is host infrastructure, not Installer configuration.

Useful facts for that decision:

How the platform URL's scheme is decided

The Installer normalises PLATFORM_URL before saving it. An explicitly typed scheme is always preserved; otherwise a scheme is inferred from the host:

HostInferred scheme
localhost, *.localhost, *.localhttp
Any IPv4 or IPv6 literalhttp — raw IPs almost never have a trusted TLS certificate
Any real domain namehttps

Only http:// and https:// are accepted; anything else is rejected with PLATFORM_URL must be an http:// or https:// address. This normalisation decides the string that reaches the DataMind OS .env; it does not create or check a certificate.

Legacy nginx.service

The bare-metal retirement script, scripts/migrate-host.sh, lists nginx.service among the legacy units it stops, disables and masks when a host moves onto Docker. That step retires the old platform's web server; it does not configure, migrate or manage any certificate.

Where to look instead

QuestionWhere the answer lives
Who holds the certificate for the DataMind OS URLThe DataMind OS deployment's edge (OpenResty), configured with the DataMind OS stack
How it is obtained or renewedWith the DataMind OS stack — not in this repository
Where the certificate path is recordedAs the SSL_CERT_PATH / SSL_KEY_PATH configuration values, written into the DataMind OS .env
How to secure the Installer's own URLA host reverse proxy in front of NEST_PORT, managed as host infrastructure