TLS
Via supports manual TLS termination for HTTP/1.1:
listen: ":443"
tls:
cert: /etc/via/cert.pem
key: /etc/via/key.pem
proxy_pass: http://localhost:8000
The certificate file may contain a certificate chain. The private key must match the leaf certificate. Via validates that both paths are readable and asks OpenSSL to validate their contents before starting or reloading.
Requests accepted by a TLS listener are sent upstream with:
X-Forwarded-Proto: https
The upstream itself may use either HTTP or HTTPS independently of downstream TLS termination.
Certificate reload
Changing tls.cert or tls.key triggers the normal debounced configuration
reload. Via creates a complete replacement OpenSSL server context before
publishing the configuration.
Each newly accepted connection snapshots the current context:
- existing TLS connections continue with their established session;
- new connections use the replacement certificate;
- a certificate or key loading error keeps the previous context in production;
- debug mode enters diagnostic state after a reload error.
Enabling or disabling TLS changes the listener transport and therefore
requires restarting Via. Changing listen also requires a restart.
Current scope
Via currently supports one certificate context for the listener. SNI-based multiple certificates and ACME automation are intentionally outside this milestone.
OpenSSL development libraries are required for a normal build. Use
make release-http only when TLS support and HTTPS upstreams are not needed.