summaryrefslogtreecommitdiff
path: root/docs/configuration/service/https.rst
diff options
context:
space:
mode:
authorYuriy Andamasov <yuriy@vyos.io>2026-05-06 21:08:17 +0300
committerYuriy Andamasov <yuriy@vyos.io>2026-05-06 21:08:17 +0300
commit3edf063d4d27d6132c67024b9560c0075fe7a48e (patch)
treeed97f8268b0e3a57d22d7969fbca00e8b8f005ae /docs/configuration/service/https.rst
parent3315a4cf73ff66d2ccb12916e9befbdb132bf0d0 (diff)
downloadvyos-documentation-3edf063d4d27d6132c67024b9560c0075fe7a48e.tar.gz
vyos-documentation-3edf063d4d27d6132c67024b9560c0075fe7a48e.zip
feat: flip swap mechanism on circinus — MD as primary, RST as override
Mirror of #1899 for circinus. Same logic, same scripts, per-branch file set. Changes: - Rename docs/**/md-<stem>.md to docs/**/<stem>.md (drop md- prefix) for all 253 stems previously listed in docs/_swap.txt - Rename docs/**/<stem>.rst to docs/**/rst-<stem>.rst (add rst- prefix) for the same 253 stems - Repurpose docs/_swap.txt as docs/_rst_overrides.txt; initially empty - conf.py exclude_patterns flipped: rst-*.rst excluded by default - conf.py runtime-artifact references updated to _rst_override_state.json and _md_exclude.txt - scripts/swap_sources.py rewritten with inverted rename direction (rst-<stem>.rst → <stem>.rst when applying overrides; <stem>.md excluded via _md_exclude.txt) - scripts/import_myst.py and tests/test_import_myst.py deleted (obsolete) - tests/test_swap_sources.py rewritten for new semantics Identical change set to #1899 (current). Per-branch differences: - circinus has 253 stems vs current's 254 (suricata is current-only) - otherwise the script/conf.py/test changes are byte-identical with current Generated by robots https://vyos.io
Diffstat (limited to 'docs/configuration/service/https.rst')
-rw-r--r--docs/configuration/service/https.rst124
1 files changed, 0 insertions, 124 deletions
diff --git a/docs/configuration/service/https.rst b/docs/configuration/service/https.rst
deleted file mode 100644
index e72e8e8b..00000000
--- a/docs/configuration/service/https.rst
+++ /dev/null
@@ -1,124 +0,0 @@
-.. _http-api:
-
-########
-HTTP API
-########
-
-VyOS provide an HTTP API. You can use it to execute op-mode commands,
-update VyOS, set or delete config.
-
-Please take a look at the :ref:`vyosapi` page for an detailed how-to.
-
-*************
-Configuration
-*************
-
-.. cfgcmd:: set service https allow-client address <address>
-
- Only allow certain IP addresses or prefixes to access the https
- webserver.
-
-.. cfgcmd:: set service https certificates ca-certificate <name>
-
- Use CA certificate from PKI subsystem
-
-.. cfgcmd:: set service https certificates certificate <name>
-
- Use certificate from PKI subsystem
-
-.. cfgcmd:: set service https certificates dh-params <name>
-
- Use :abbr:`DH (Diffie–Hellman)` parameters from PKI subsystem.
- Must be at least 2048 bits in length.
-
-.. cfgcmd:: set service https listen-address <address>
-
- Webserver should only listen on specified IP address
-
-.. cfgcmd:: set service https port <number>
-
- Webserver should listen on specified port.
-
- Default: 443
-
-.. cfgcmd:: set service https enable-http-redirect
-
- Enable automatic redirect from http to https.
-
-.. cfgcmd:: set service https tls-version <1.2 | 1.3>
-
- Select TLS version used.
-
- This defaults to both 1.2 and 1.3.
-
-.. cfgcmd:: set service https vrf <name>
-
- Start Webserver in given VRF.
-
-.. cfgcmd:: set service https request-body-size-limit <size>
-
- Set the maximum request body size in megabytes. Default is 1MB.
-
-API
-===
-
-.. cfgcmd:: set service https api keys id <name> key <apikey>
-
- Set a named api key. Every key has the same, full permissions
- on the system.
-
-REST
-====
-
-.. cfgcmd:: set service https api rest
-
- Enable REST API
-
-.. cfgcmd:: set service https api rest debug
-
- To enable debug messages. Available via :opcmd:`show log` or
- :opcmd:`monitor log`
-
-.. cfgcmd:: set service https api rest strict
-
- Enforce strict path checking.
-
-GraphQL
-=======
-
-.. cfgcmd:: set service https api graphql introspection
-
- Enable GraphQL Schema introspection.
-
-.. note:: Do not leave introspection enabled in production, it is a security risk.
-
-.. cfgcmd:: set service https api graphql authentication type <key | token>
-
- Set the authentication type for GraphQL, default option is key. Available options are:
-
- * ``key`` use API keys configured in ``service https api keys``
-
- * ``token`` use JWT tokens.
-
-.. cfgcmd:: set service https api graphql authentication expiration
-
- Set the lifetime for JWT tokens in seconds. Default is 3600 seconds.
-
-.. cfgcmd:: set service https api graphql authentication secret-length
-
- Set the byte length of the JWT secret. Default is 32.
-
-.. cfgcmd:: set service https api graphql cors allow-origin <origin>
-
- Allow cross-origin requests from `<origin>`.
-
-*********************
-Example Configuration
-*********************
-
-Setting REST API and an API-KEY is the minimal configuration to get a working API Endpoint.
-
-.. code-block:: none
-
- set service https api keys id MY-HTTPS-API-ID key MY-HTTPS-API-PLAINTEXT-KEY
- set service https api rest