TLS and HTTP/2
Serve Arcane over HTTPS through a reverse proxy or your own TLS certificates.
Arcane can serve HTTPS in two ways: a reverse proxy in front of it handles the certificates, or Arcane serves HTTPS itself with a certificate you provide. For most installations, let the reverse proxy handle it.
Option A: HTTPS handled by a reverse proxy
Section titled “Option A: HTTPS handled by a reverse proxy”Set these values when Nginx, Caddy, Traefik, or another proxy handles HTTPS:
TLS_ENABLED=falseAPP_URL=https://your-domain.comPORT is optional and defaults to 3552.
Option B: Direct Arcane HTTPS and HTTP/2
Section titled “Option B: Direct Arcane HTTPS and HTTP/2”You need a domain name, a valid certificate and its private key, and access to Arcane’s .env or container settings.
- Set these values in your
.envfile or container environment:
TLS_ENABLED=trueTLS_CERT_FILE=/full/path/to/your/certificate.pemTLS_KEY_FILE=/full/path/to/your/private-key.pemAPP_URL=https://your-domain.com- Optionally set
PORT(default3552) andLISTEN. LeaveLISTENempty to bind on all interfaces. - Restart Arcane.
- Open your
https://URL and check that the browser reports a valid certificate.
With TLS_ENABLED=true, Arcane won’t start unless both TLS_CERT_FILE and TLS_KEY_FILE are set.
HTTP/2 without TLS
Section titled “HTTP/2 without TLS”When TLS_ENABLED=false, Arcane accepts HTTP/1.1 and h2c (HTTP/2 without encryption) on the same port. Proxies use h2c to forward gRPC traffic, such as the Edge Agent tunnel. Keep h2c on internal networks and use HTTPS for public access.