influxdata/influxdb · error · Error

tls requires both a cert and a key file to be passed in to…

Error message

tls requires both a cert and a key file to be passed in to work

What it means

Error variant indicating TLS was enabled but the configuration is incomplete: serving TLS requires BOTH a certificate file and a private key file. The variant exists so `influxdb3 serve` fails fast with a clear message instead of an opaque TLS handshake error later.

Solutions

  1. Pass both --tls-cert <cert.pem> and --tls-key <key.pem> to the serve command.
  2. Check that both file paths exist and are readable by the influxdb3 process.
  3. Remove TLS flags entirely if plain HTTP was intended.

Example fix

# before
influxdb3 serve --tls-cert server.pem
# after
influxdb3 serve --tls-cert server.pem --tls-key server.key
Defensive patterns

Strategy: validation

Validate before calling

if tls_enabled && !(cert_path_set && key_path_set) {
    return Err("tls requires both a cert and a key file");
}

Type guard

fn tls_config_complete(cert: &Option<String>, key: &Option<String>) -> bool {
    cert.is_some() && key.is_some()
}

Prevention

When it happens

Trigger: Running `influxdb3 serve` with `--tls-cert` (cert file) or `--tls-key` (key file) set, but not both; or one of the two flags omitted/empty.

Common situations: Operators enable HTTPS but pass only the cert, forget the key flag, or use flag names from an older version where a single TLS option existed.

Understand the failure class

Background: "is required", "must be set", "missing required field": configuration validation errors across open-source libraries — this error's family across 36 libraries.

Related errors


AI-assisted analysis of influxdata/influxdb@06200ef96b (2026-09-19). Data as JSON: /api/errors/482030da91a01286. Report an issue: GitHub.

Appendix: source

Thrown at influxdb3/src/commands/serve.rs:162

    #[error("failed to initialize catalog: {0}")]
    InitializeCatalog(#[source] CatalogError),

    #[error("failed to initialize last cache: {0}")]
    InitializeLastCache(#[source] last_cache::Error),

    #[error("failed to initialize distinct cache: {0:#}")]
    InitializeDistinctCache(#[source] influxdb3_cache::distinct_cache::ProviderError),

    #[error("lost backend")]
    LostBackend,

    #[error("lost HTTP/gRPC service")]
    LostHttpGrpc,

    #[error("lost admin token recovery service")]
    LostAdminTokenRecovery,

    #[error("tls requires both a cert and a key file to be passed in to work")]
    NoCertOrKeyFile,

    #[error("table cache index initialization failed: {0}")]
    TableIndexCacheInitialization(
        #[source] influxdb3_write::table_index_cache::TableIndexCacheError,
    ),

    #[error(
        "environment variable {0} (named by --node-id-from-env / INFLUXDB3_NODE_ID_FROM_ENV) \
        must be set to a valid node id"
    )]
    NodeIdEnvVarMissing(String),

    #[error(
        "Python environment initialization failed: {0}\nPlease ensure Python and pip package manager is installed"
    )]
    PythonEnvironmentInitialization(
        #[source] influxdb3_processing_engine::environment::PluginEnvironmentError,

View on GitHub (pinned to 06200ef96b)