{"record":{"id":"6a6bfe7f128fb842","repo":"influxdata/influxdb","slug":"tls-config-error-0","errorCode":null,"errorMessage":"tls config error: {0}","messagePattern":"tls config error: (.+?)","errorType":"error_code","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"influxdb3_server/src/lib.rs","lineNumber":84,"sourceCode":"    #[error(\"http error: {0}\")]\n    Http(#[from] Box<http::Error>),\n\n    #[error(\"database not found {db_name}\")]\n    DatabaseNotFound { db_name: String },\n\n    #[error(\"datafusion error: {0}\")]\n    DataFusion(#[from] datafusion::error::DataFusionError),\n\n    #[error(\"influxdb3_write error: {0}\")]\n    InfluxDB3Write(#[from] influxdb3_write::Error),\n\n    #[error(\"from hex error: {0}\")]\n    FromHex(#[from] hex::FromHexError),\n\n    #[error(\"io error: {0}\")]\n    Io(#[from] std::io::Error),\n\n    #[error(\"tls config error: {0}\")]\n    TlsConfig(String),\n\n    #[error(\"rustls error: {0}\")]\n    Rustls(#[from] rustls::Error),\n}\n\npub type Result<T, E = Error> = std::result::Result<T, E>;\n\n#[derive(Debug, Clone)]\npub struct CommonServerState {\n    catalog: Arc<Catalog>,\n    metrics: Arc<metric::Registry>,\n    trace_exporter: Option<Arc<trace_exporters::export::AsyncExporter>>,\n    trace_header_parser: TraceHeaderParser,\n    telemetry_store: Arc<TelemetryStore>,\n}\n\nimpl CommonServerState {","sourceCodeStart":66,"sourceCodeEnd":102,"githubUrl":"https://github.com/influxdata/influxdb/blob/06200ef96ba82c5f6727e5038a83af8e722c6875/influxdb3_server/src/lib.rs#L66-L102","documentation":"A server-specific error raised when TLS configuration supplied to the InfluxDB3 server is invalid. Unlike the Rustls variant (which wraps library-level rustls::Error), TlsConfig(String) carries a free-form message describing configuration problems detected while assembling the TLS setup, such as incomplete or mutually inconsistent TLS options.","triggerScenarios":"Starting the server with TLS enabled but providing only one of cert/key; supplying an empty or blank cert/key path; specifying TLS options that conflict or are incomplete in serve commands that build a TlsConfig.","commonSituations":"Setting --tls-cert without --tls-key (or vice versa); typos in environment variables controlling TLS; copying a config from another service with different option names; enabling TLS in a container without mounting the certificate files.","solutions":["Read the embedded message to see exactly which TLS setting is invalid","Ensure both certificate and private key paths are provided, non-empty, and point to valid PEM files","Verify the private key matches the certificate (compare moduli/hashes)","Check that TLS-related environment variables or config files use the exact expected option names","Start without TLS to confirm the rest of the server works, then re-add TLS incrementally"],"exampleFix":"// before: incomplete TLS options\ninfluxdb3 serve --tls-cert /etc/ssl/influxdb.crt\n// after: provide matching cert and key\ninfluxdb3 serve --tls-cert /etc/ssl/influxdb.crt --tls-key /etc/ssl/influxdb.key","handlingStrategy":"validation","validationCode":"fn validate_tls_config(cert: Option<&str>, key: Option<&str>) -> Result<(), String> {\n    match (cert, key) {\n        (Some(c), Some(k)) if !c.trim().is_empty() && !k.trim().is_empty() => Ok(()),\n        (None, None) => Ok(()), // TLS disabled is fine\n        _ => Err(\"both --tls-cert and --tls-key must be set and non-empty\".into()),\n    }\n}","typeGuard":null,"tryCatchPattern":"match server_result {\n    Err(influxdb3_server::Error::TlsConfig(msg)) => eprintln!(\"fix TLS config: {msg}\"),\n    Err(e) => eprintln!(\"server error: {e}\"),\n    Ok(v) => handle(v),\n}","preventionTips":["Always supply cert and key as a matched, non-empty pair","Confirm cert/key are valid PEM and correspond to each other","Keep TLS options in one reviewed config source to avoid name mismatches","Smoke-test TLS startup in CI before deploying"],"tags":["influxdb3","tls","configuration","startup"],"backgroundTag":"invalid-config-value","analyzedSha":"06200ef96ba82c5f6727e5038a83af8e722c6875","analyzedAt":"2026-09-19T12:55:30.003Z","contentChangedAt":"2026-09-19T12:55:30.003Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}