Skip to content

TLS and HTTP/2

Serve Arcane over HTTPS through a reverse proxy or your own TLS certificates.

Arcane can serve HTTPS in two ways: a reverse proxy in front of it handles the certificates, or Arcane serves HTTPS itself with a certificate you provide. For most installations, let the reverse proxy handle it.

Option A: HTTPS handled by a reverse proxy

Section titled “Option A: HTTPS handled by a reverse proxy”

Set these values when Nginx, Caddy, Traefik, or another proxy handles HTTPS:

Terminal window
TLS_ENABLED=false
Terminal window
APP_URL=https://your-domain.com

PORT is optional and defaults to 3552.

You need a domain name, a valid certificate and its private key, and access to Arcane’s .env or container settings.

  1. Set these values in your .env file or container environment:
Terminal window
TLS_ENABLED=true
Terminal window
TLS_CERT_FILE=/full/path/to/your/certificate.pem
Terminal window
TLS_KEY_FILE=/full/path/to/your/private-key.pem
Terminal window
APP_URL=https://your-domain.com
  1. Optionally set PORT (default 3552) and LISTEN. Leave LISTEN empty to bind on all interfaces.
  2. Restart Arcane.
  3. Open your https:// URL and check that the browser reports a valid certificate.

With TLS_ENABLED=true, Arcane won’t start unless both TLS_CERT_FILE and TLS_KEY_FILE are set.

When TLS_ENABLED=false, Arcane accepts HTTP/1.1 and h2c (HTTP/2 without encryption) on the same port. Proxies use h2c to forward gRPC traffic, such as the Edge Agent tunnel. Keep h2c on internal networks and use HTTPS for public access.