{"record":{"id":"482030da91a01286","repo":"influxdata/influxdb","slug":"tls-requires-both-a-cert-and-a-key-file-to-be-passed-in-to","errorCode":null,"errorMessage":"tls requires both a cert and a key file to be passed in to work","messagePattern":"tls requires both a cert and a key file to be passed in to work","errorType":"validation","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"influxdb3/src/commands/serve.rs","lineNumber":162,"sourceCode":"    #[error(\"failed to initialize catalog: {0}\")]\n    InitializeCatalog(#[source] CatalogError),\n\n    #[error(\"failed to initialize last cache: {0}\")]\n    InitializeLastCache(#[source] last_cache::Error),\n\n    #[error(\"failed to initialize distinct cache: {0:#}\")]\n    InitializeDistinctCache(#[source] influxdb3_cache::distinct_cache::ProviderError),\n\n    #[error(\"lost backend\")]\n    LostBackend,\n\n    #[error(\"lost HTTP/gRPC service\")]\n    LostHttpGrpc,\n\n    #[error(\"lost admin token recovery service\")]\n    LostAdminTokenRecovery,\n\n    #[error(\"tls requires both a cert and a key file to be passed in to work\")]\n    NoCertOrKeyFile,\n\n    #[error(\"table cache index initialization failed: {0}\")]\n    TableIndexCacheInitialization(\n        #[source] influxdb3_write::table_index_cache::TableIndexCacheError,\n    ),\n\n    #[error(\n        \"environment variable {0} (named by --node-id-from-env / INFLUXDB3_NODE_ID_FROM_ENV) \\\n        must be set to a valid node id\"\n    )]\n    NodeIdEnvVarMissing(String),\n\n    #[error(\n        \"Python environment initialization failed: {0}\\nPlease ensure Python and pip package manager is installed\"\n    )]\n    PythonEnvironmentInitialization(\n        #[source] influxdb3_processing_engine::environment::PluginEnvironmentError,","sourceCodeStart":144,"sourceCodeEnd":180,"githubUrl":"https://github.com/influxdata/influxdb/blob/06200ef96ba82c5f6727e5038a83af8e722c6875/influxdb3/src/commands/serve.rs#L144-L180","documentation":"Error variant indicating TLS was enabled but the configuration is incomplete: serving TLS requires BOTH a certificate file and a private key file. The variant exists so `influxdb3 serve` fails fast with a clear message instead of an opaque TLS handshake error later.","triggerScenarios":"Running `influxdb3 serve` with `--tls-cert` (cert file) or `--tls-key` (key file) set, but not both; or one of the two flags omitted/empty.","commonSituations":"Operators enable HTTPS but pass only the cert, forget the key flag, or use flag names from an older version where a single TLS option existed.","solutions":["Pass both --tls-cert <cert.pem> and --tls-key <key.pem> to the serve command.","Check that both file paths exist and are readable by the influxdb3 process.","Remove TLS flags entirely if plain HTTP was intended."],"exampleFix":"# before\ninfluxdb3 serve --tls-cert server.pem\n# after\ninfluxdb3 serve --tls-cert server.pem --tls-key server.key","handlingStrategy":"validation","validationCode":"if tls_enabled && !(cert_path_set && key_path_set) {\n    return Err(\"tls requires both a cert and a key file\");\n}","typeGuard":"fn tls_config_complete(cert: &Option<String>, key: &Option<String>) -> bool {\n    cert.is_some() && key.is_some()\n}","tryCatchPattern":null,"preventionTips":["Always pass --tls-cert and --tls-key together.","Verify both file paths exist before starting the server.","Script startup configs to validate TLS pairs in CI."],"tags":["tls","configuration","cli","startup"],"backgroundTag":"missing-required-config-field","analyzedSha":"06200ef96ba82c5f6727e5038a83af8e722c6875","analyzedAt":"2026-09-19T12:55:30.003Z","contentChangedAt":"2026-09-19T12:55:30.003Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}