Two addresses need certificates. Your reverse proxy holds the one for the DataMind Installer. The DataMind OS gateway holds its own.
The Installer serves HTTP on port 8000. Terminate TLS in your reverse proxy or load balancer, then
allow only the proxy through, as Restrict the port
shows.
| Your proxy must | Because |
|---|---|
Send X-Forwarded-Proto: https | The Installer marks its session cookies Secure only on HTTPS requests or with this header set to https |
Pass the browser's original Host header | The Installer derives the cookie domain from Host. See Sign-in loops behind a proxy |
Rate-limit POST / | Protects the sign-in endpoint against password guessing |
| Turn response buffering off | Job and service logs stream as server-sent events. With buffering they arrive in bursts |
With NEST_NODE_ENV=prod, when the browser's Origin host differs from the Host the Installer
sees, or is missing, it sets the cookie domain to the last two labels of Host:
Host the Installer sees | Cookie domain | Result |
|---|---|---|
installer. | . | Works |
installer. | . | Rejected by the browser: a public suffix |
10. | . | Rejected by the browser |
A rejected cookie means the password is accepted and you land back on the sign-in screen. Pass the
original Host through, so Origin and Host match and no domain is set.
Check it worked. Sign in through the proxy and open the browser's developer tools. Both session cookies show Secure and HttpOnly, and no domain other than the host you typed.
The DataMind OS gateway (OpenResty) picks its mode when its container starts:
| The gateway finds | It serves | Its log line |
|---|---|---|
Non-empty cert. and key. in / | HTTPS | [openresty] SSL certs detected - HTTPS enabled |
| Either file missing or empty | HTTP | [openresty] No SSL certs - HTTP only |
Set SSL_CERT_PATH and SSL_KEY_PATH on Configuration to the
absolute paths of the certificate and key files on the host, then click Apply changes.
Check it worked.
docker ps --format '{{.Names}}' | grep -i openresty
docker logs <gateway-container> 2>&1 | grep '\[openresty\]'[openresty] SSL certs detected - HTTPS enabled
Then open the platform address in a browser and check the certificate's issuer and expiry date.
After you renew the certificate files, restart the gateway so it reads them again: on Status, open the gateway service and click its restart button.
The Installer builds every link to DataMind OS from PLATFORM_URL, and normalises it on save:
| You type | The Installer saves |
|---|---|
An address with http:/ or https:/ | It as typed, without trailing slashes |
A domain name without a scheme, such as data. | https:/ |
localhost, a *. or *. name, or an IP address, without a scheme | http:/ plus the address |
Any other scheme, such as ftp:/ | Nothing. It answers PLATFORM_URL must be an http:/ |
| An empty value | Nothing. It answers PLATFORM_URL cannot be empty |
| A value that is not an address | Nothing. It answers PLATFORM_URL is not a valid address: "<value>" |
To serve DataMind OS over HTTPS on an IP address, type https:/ yourself.
The gateway did not find both files. It logs [openresty] No SSL certs - HTTP only. Correct
SSL_CERT_PATH and SSL_KEY_PATH in Configuration, then click Apply changes. If only the files
changed, restart the gateway.
The browser rejected the session cookie. Your proxy rewrites Host, so the Installer sets a
domain such as .. Pass the original Host header.