influxdata/influxdb · error · Error
tls requires both a cert and a key file to be passed in to…
Error message
tls requires both a cert and a key file to be passed in to work
What it means
Error variant indicating TLS was enabled but the configuration is incomplete: serving TLS requires BOTH a certificate file and a private key file. The variant exists so `influxdb3 serve` fails fast with a clear message instead of an opaque TLS handshake error later.
Solutions
- Pass both --tls-cert <cert.pem> and --tls-key <key.pem> to the serve command.
- Check that both file paths exist and are readable by the influxdb3 process.
- Remove TLS flags entirely if plain HTTP was intended.
Example fix
# before influxdb3 serve --tls-cert server.pem # after influxdb3 serve --tls-cert server.pem --tls-key server.key
Defensive patterns
Strategy: validation
Validate before calling
if tls_enabled && !(cert_path_set && key_path_set) {
return Err("tls requires both a cert and a key file");
} Type guard
fn tls_config_complete(cert: &Option<String>, key: &Option<String>) -> bool {
cert.is_some() && key.is_some()
} Prevention
- Always pass --tls-cert and --tls-key together.
- Verify both file paths exist before starting the server.
- Script startup configs to validate TLS pairs in CI.
When it happens
Trigger: Running `influxdb3 serve` with `--tls-cert` (cert file) or `--tls-key` (key file) set, but not both; or one of the two flags omitted/empty.
Common situations: Operators enable HTTPS but pass only the cert, forget the key flag, or use flag names from an older version where a single TLS option existed.
Understand the failure class
Background: "is required", "must be set", "missing required field": configuration validation errors across open-source libraries — this error's family across 36 libraries.
- SSL/TLS and certificate errors — how TLS handshakes and certificate validation fail.
Related errors
- tls config error
- Cannot parse object store config
- Could not find user's home directory
- environment variable
- failed to build an http client
AI-assisted analysis of influxdata/influxdb@06200ef96b (2026-09-19).
Data as JSON: /api/errors/482030da91a01286.
Report an issue: GitHub.
Appendix: source
Thrown at influxdb3/src/commands/serve.rs:162
#[error("failed to initialize catalog: {0}")]
InitializeCatalog(#[source] CatalogError),
#[error("failed to initialize last cache: {0}")]
InitializeLastCache(#[source] last_cache::Error),
#[error("failed to initialize distinct cache: {0:#}")]
InitializeDistinctCache(#[source] influxdb3_cache::distinct_cache::ProviderError),
#[error("lost backend")]
LostBackend,
#[error("lost HTTP/gRPC service")]
LostHttpGrpc,
#[error("lost admin token recovery service")]
LostAdminTokenRecovery,
#[error("tls requires both a cert and a key file to be passed in to work")]
NoCertOrKeyFile,
#[error("table cache index initialization failed: {0}")]
TableIndexCacheInitialization(
#[source] influxdb3_write::table_index_cache::TableIndexCacheError,
),
#[error(
"environment variable {0} (named by --node-id-from-env / INFLUXDB3_NODE_ID_FROM_ENV) \
must be set to a valid node id"
)]
NodeIdEnvVarMissing(String),
#[error(
"Python environment initialization failed: {0}\nPlease ensure Python and pip package manager is installed"
)]
PythonEnvironmentInitialization(
#[source] influxdb3_processing_engine::environment::PluginEnvironmentError,View on GitHub (pinned to 06200ef96b)