influxdata/influxdb · error · Error

tls config error

Error message

tls config error: {0}

What it means

A server-specific error raised when TLS configuration supplied to the InfluxDB3 server is invalid. Unlike the Rustls variant (which wraps library-level rustls::Error), TlsConfig(String) carries a free-form message describing configuration problems detected while assembling the TLS setup, such as incomplete or mutually inconsistent TLS options.

Solutions

  1. Read the embedded message to see exactly which TLS setting is invalid
  2. Ensure both certificate and private key paths are provided, non-empty, and point to valid PEM files
  3. Verify the private key matches the certificate (compare moduli/hashes)
  4. Check that TLS-related environment variables or config files use the exact expected option names
  5. Start without TLS to confirm the rest of the server works, then re-add TLS incrementally

Example fix

// before: incomplete TLS options
influxdb3 serve --tls-cert /etc/ssl/influxdb.crt
// after: provide matching cert and key
influxdb3 serve --tls-cert /etc/ssl/influxdb.crt --tls-key /etc/ssl/influxdb.key
Defensive patterns

Strategy: validation

Validate before calling

fn validate_tls_config(cert: Option<&str>, key: Option<&str>) -> Result<(), String> {
    match (cert, key) {
        (Some(c), Some(k)) if !c.trim().is_empty() && !k.trim().is_empty() => Ok(()),
        (None, None) => Ok(()), // TLS disabled is fine
        _ => Err("both --tls-cert and --tls-key must be set and non-empty".into()),
    }
}

Try / catch

match server_result {
    Err(influxdb3_server::Error::TlsConfig(msg)) => eprintln!("fix TLS config: {msg}"),
    Err(e) => eprintln!("server error: {e}"),
    Ok(v) => handle(v),
}

Prevention

When it happens

Trigger: Starting the server with TLS enabled but providing only one of cert/key; supplying an empty or blank cert/key path; specifying TLS options that conflict or are incomplete in serve commands that build a TlsConfig.

Common situations: Setting --tls-cert without --tls-key (or vice versa); typos in environment variables controlling TLS; copying a config from another service with different option names; enabling TLS in a container without mounting the certificate files.

Understand the failure class

Background: "Invalid value" and "allowed values are" config errors: what your library rejected and how to fix it — this error's family across 41 libraries.

Related errors


AI-assisted analysis of influxdata/influxdb@06200ef96b (2026-09-19). Data as JSON: /api/errors/6a6bfe7f128fb842. Report an issue: GitHub.

Appendix: source

Thrown at influxdb3_server/src/lib.rs:84

    #[error("http error: {0}")]
    Http(#[from] Box<http::Error>),

    #[error("database not found {db_name}")]
    DatabaseNotFound { db_name: String },

    #[error("datafusion error: {0}")]
    DataFusion(#[from] datafusion::error::DataFusionError),

    #[error("influxdb3_write error: {0}")]
    InfluxDB3Write(#[from] influxdb3_write::Error),

    #[error("from hex error: {0}")]
    FromHex(#[from] hex::FromHexError),

    #[error("io error: {0}")]
    Io(#[from] std::io::Error),

    #[error("tls config error: {0}")]
    TlsConfig(String),

    #[error("rustls error: {0}")]
    Rustls(#[from] rustls::Error),
}

pub type Result<T, E = Error> = std::result::Result<T, E>;

#[derive(Debug, Clone)]
pub struct CommonServerState {
    catalog: Arc<Catalog>,
    metrics: Arc<metric::Registry>,
    trace_exporter: Option<Arc<trace_exporters::export::AsyncExporter>>,
    trace_header_parser: TraceHeaderParser,
    telemetry_store: Arc<TelemetryStore>,
}

impl CommonServerState {

View on GitHub (pinned to 06200ef96b)