summaryrefslogtreecommitdiff
path: root/docs/configuration/service/rst-https.rst
diff options
context:
space:
mode:
authorYuriy Andamasov <yuriy@vyos.io>2026-05-07 10:10:21 +0300
committerYuriy Andamasov <yuriy@vyos.io>2026-05-07 10:10:21 +0300
commit672b331fdaaa91e5a0c23c4abb9609c6f4c6a359 (patch)
tree82f67edd0bd5cc9730014e6e5f5a829a379ea81f /docs/configuration/service/rst-https.rst
parent0dbd2b071c0fc36796ae00a814586a39aabcc616 (diff)
parentcda6de295f85bc33d4ad60b0cbed48ea54aaedf8 (diff)
downloadvyos-documentation-672b331fdaaa91e5a0c23c4abb9609c6f4c6a359.tar.gz
vyos-documentation-672b331fdaaa91e5a0c23c4abb9609c6f4c6a359.zip
Merge remote-tracking branch 'origin/sagitta' into fix/docs-html-title-sagitta
# Conflicts: # docs/conf.py
Diffstat (limited to 'docs/configuration/service/rst-https.rst')
-rw-r--r--docs/configuration/service/rst-https.rst83
1 files changed, 83 insertions, 0 deletions
diff --git a/docs/configuration/service/rst-https.rst b/docs/configuration/service/rst-https.rst
new file mode 100644
index 00000000..973c5355
--- /dev/null
+++ b/docs/configuration/service/rst-https.rst
@@ -0,0 +1,83 @@
+.. _http-api:
+
+########
+HTTP API
+########
+
+VyOS provide an HTTP API. You can use it to execute op-mode commands,
+update VyOS, set or delete config.
+
+Please take a look at the :ref:`vyosapi` page for an detailed how-to.
+
+*************
+Configuration
+*************
+
+.. cfgcmd:: set service https allow-client address <address>
+
+ Only allow certain IP addresses or prefixes to access the https
+ webserver.
+
+.. cfgcmd:: set service https certificates ca-certificate <name>
+
+ Use CA certificate from PKI subsystem
+
+.. cfgcmd:: set service https certificates certificate <name>
+
+ Use certificate from PKI subsystem
+
+.. cfgcmd:: set service https certificates dh-params <name>
+
+ Use :abbr:`DH (Diffie–Hellman)` parameters from PKI subsystem.
+ Must be at least 2048 bits in length.
+
+.. cfgcmd:: set service https listen-address <address>
+
+ Webserver should only listen on specified IP address
+
+.. cfgcmd:: set service https port <number>
+
+ Webserver should listen on specified port.
+
+ Default: 443
+
+.. cfgcmd:: set service https enable-http-redirect
+
+ Enable automatic redirect from http to https.
+
+.. cfgcmd:: set service https tls-version <1.2 | 1.3>
+
+ Select TLS version used.
+
+ This defaults to both 1.2 and 1.3.
+
+.. cfgcmd:: set service https vrf <name>
+
+ Start Webserver in given VRF.
+
+API
+===
+
+.. cfgcmd:: set service https api keys id <name> key <apikey>
+
+ Set a named api key. Every key has the same, full permissions
+ on the system.
+
+.. cfgcmd:: set service https api debug
+
+ To enable debug messages. Available via :opcmd:`show log` or
+ :opcmd:`monitor log`
+
+.. cfgcmd:: set service https api strict
+
+ Enforce strict path checking
+
+*********************
+Example Configuration
+*********************
+
+Set an API-KEY is the minimal configuration to get a working API Endpoint.
+
+.. code-block:: none
+
+ set service https api keys id MY-HTTPS-API-ID key MY-HTTPS-API-PLAINTEXT-KEY