influxdata/influxdb · error · Error
tls config error
Error message
tls config error: {0} What it means
A server-specific error raised when TLS configuration supplied to the InfluxDB3 server is invalid. Unlike the Rustls variant (which wraps library-level rustls::Error), TlsConfig(String) carries a free-form message describing configuration problems detected while assembling the TLS setup, such as incomplete or mutually inconsistent TLS options.
Solutions
- Read the embedded message to see exactly which TLS setting is invalid
- Ensure both certificate and private key paths are provided, non-empty, and point to valid PEM files
- Verify the private key matches the certificate (compare moduli/hashes)
- Check that TLS-related environment variables or config files use the exact expected option names
- Start without TLS to confirm the rest of the server works, then re-add TLS incrementally
Example fix
// before: incomplete TLS options influxdb3 serve --tls-cert /etc/ssl/influxdb.crt // after: provide matching cert and key influxdb3 serve --tls-cert /etc/ssl/influxdb.crt --tls-key /etc/ssl/influxdb.key
Defensive patterns
Strategy: validation
Validate before calling
fn validate_tls_config(cert: Option<&str>, key: Option<&str>) -> Result<(), String> {
match (cert, key) {
(Some(c), Some(k)) if !c.trim().is_empty() && !k.trim().is_empty() => Ok(()),
(None, None) => Ok(()), // TLS disabled is fine
_ => Err("both --tls-cert and --tls-key must be set and non-empty".into()),
}
} Try / catch
match server_result {
Err(influxdb3_server::Error::TlsConfig(msg)) => eprintln!("fix TLS config: {msg}"),
Err(e) => eprintln!("server error: {e}"),
Ok(v) => handle(v),
} Prevention
- Always supply cert and key as a matched, non-empty pair
- Confirm cert/key are valid PEM and correspond to each other
- Keep TLS options in one reviewed config source to avoid name mismatches
- Smoke-test TLS startup in CI before deploying
When it happens
Trigger: Starting the server with TLS enabled but providing only one of cert/key; supplying an empty or blank cert/key path; specifying TLS options that conflict or are incomplete in serve commands that build a TlsConfig.
Common situations: Setting --tls-cert without --tls-key (or vice versa); typos in environment variables controlling TLS; copying a config from another service with different option names; enabling TLS in a container without mounting the certificate files.
Understand the failure class
Background: "Invalid value" and "allowed values are" config errors: what your library rejected and how to fix it — this error's family across 41 libraries.
- SSL/TLS and certificate errors — how TLS handshakes and certificate validation fail.
Related errors
- failed to build an http client
- tls requires both a cert and a key file to be passed in to…
- failed to initialize write buffer
- lost admin token recovery service
- rustls error
AI-assisted analysis of influxdata/influxdb@06200ef96b (2026-09-19).
Data as JSON: /api/errors/6a6bfe7f128fb842.
Report an issue: GitHub.
Appendix: source
Thrown at influxdb3_server/src/lib.rs:84
#[error("http error: {0}")]
Http(#[from] Box<http::Error>),
#[error("database not found {db_name}")]
DatabaseNotFound { db_name: String },
#[error("datafusion error: {0}")]
DataFusion(#[from] datafusion::error::DataFusionError),
#[error("influxdb3_write error: {0}")]
InfluxDB3Write(#[from] influxdb3_write::Error),
#[error("from hex error: {0}")]
FromHex(#[from] hex::FromHexError),
#[error("io error: {0}")]
Io(#[from] std::io::Error),
#[error("tls config error: {0}")]
TlsConfig(String),
#[error("rustls error: {0}")]
Rustls(#[from] rustls::Error),
}
pub type Result<T, E = Error> = std::result::Result<T, E>;
#[derive(Debug, Clone)]
pub struct CommonServerState {
catalog: Arc<Catalog>,
metrics: Arc<metric::Registry>,
trace_exporter: Option<Arc<trace_exporters::export::AsyncExporter>>,
trace_header_parser: TraceHeaderParser,
telemetry_store: Arc<TelemetryStore>,
}
impl CommonServerState {View on GitHub (pinned to 06200ef96b)