summaryrefslogtreecommitdiff
path: root/docs/configuration/service/rst-https.rst
diff options
context:
space:
mode:
authorYuriy Andamasov <yuriy@vyos.io>2026-05-06 21:50:08 +0300
committerYuriy Andamasov <yuriy@vyos.io>2026-05-06 21:50:08 +0300
commitb8b3044d3c3515d91de0f44785bfd965174867df (patch)
tree788923f3da1387b498b94fe58a00157458e59ab9 /docs/configuration/service/rst-https.rst
parentab5359702db9ba94fa27d770af440a20cf95a41b (diff)
downloadvyos-documentation-b8b3044d3c3515d91de0f44785bfd965174867df.tar.gz
vyos-documentation-b8b3044d3c3515d91de0f44785bfd965174867df.zip
feat: flip swap mechanism on sagitta — MD as primary, RST as override
Mirror of #1899 (current) and #1900 (circinus) for sagitta. Same logic, same scripts, per-branch file set. Changes: - Rename docs/**/md-<stem>.md to docs/**/<stem>.md (drop md- prefix) for all 210 stems previously listed in docs/_swap.txt - Rename docs/**/<stem>.rst to docs/**/rst-<stem>.rst (add rst- prefix) for the same 210 stems - Repurpose docs/_swap.txt as docs/_rst_overrides.txt; initially empty - conf.py exclude_patterns flipped: rst-*.rst excluded by default - conf.py runtime-artifact references updated to _rst_override_state.json and _md_exclude.txt - scripts/swap_sources.py imported from current (post-#1899 rewrite, with inverted rename direction) - scripts/import_myst.py and tests/test_import_myst.py deleted (obsolete) - tests/test_swap_sources.py imported from current (post-#1899 rewrite) Side-effect: fixes the same 404 on /en/1.4/ View page source links that #1899 fixed for /en/rolling/ and #1900 fixed for /en/1.5/. Per-branch differences vs #1899: - sagitta has 210 stems vs current's 254 (sagitta has no vpp pages and fewer current-only features; cli + installation/cloud/aws are still RST-only on sagitta pending the title-level fix follow-up) - otherwise the script/conf.py/test changes are byte-identical with current Generated by robots https://vyos.io
Diffstat (limited to 'docs/configuration/service/rst-https.rst')
-rw-r--r--docs/configuration/service/rst-https.rst83
1 files changed, 83 insertions, 0 deletions
diff --git a/docs/configuration/service/rst-https.rst b/docs/configuration/service/rst-https.rst
new file mode 100644
index 00000000..973c5355
--- /dev/null
+++ b/docs/configuration/service/rst-https.rst
@@ -0,0 +1,83 @@
+.. _http-api:
+
+########
+HTTP API
+########
+
+VyOS provide an HTTP API. You can use it to execute op-mode commands,
+update VyOS, set or delete config.
+
+Please take a look at the :ref:`vyosapi` page for an detailed how-to.
+
+*************
+Configuration
+*************
+
+.. cfgcmd:: set service https allow-client address <address>
+
+ Only allow certain IP addresses or prefixes to access the https
+ webserver.
+
+.. cfgcmd:: set service https certificates ca-certificate <name>
+
+ Use CA certificate from PKI subsystem
+
+.. cfgcmd:: set service https certificates certificate <name>
+
+ Use certificate from PKI subsystem
+
+.. cfgcmd:: set service https certificates dh-params <name>
+
+ Use :abbr:`DH (Diffie–Hellman)` parameters from PKI subsystem.
+ Must be at least 2048 bits in length.
+
+.. cfgcmd:: set service https listen-address <address>
+
+ Webserver should only listen on specified IP address
+
+.. cfgcmd:: set service https port <number>
+
+ Webserver should listen on specified port.
+
+ Default: 443
+
+.. cfgcmd:: set service https enable-http-redirect
+
+ Enable automatic redirect from http to https.
+
+.. cfgcmd:: set service https tls-version <1.2 | 1.3>
+
+ Select TLS version used.
+
+ This defaults to both 1.2 and 1.3.
+
+.. cfgcmd:: set service https vrf <name>
+
+ Start Webserver in given VRF.
+
+API
+===
+
+.. cfgcmd:: set service https api keys id <name> key <apikey>
+
+ Set a named api key. Every key has the same, full permissions
+ on the system.
+
+.. cfgcmd:: set service https api debug
+
+ To enable debug messages. Available via :opcmd:`show log` or
+ :opcmd:`monitor log`
+
+.. cfgcmd:: set service https api strict
+
+ Enforce strict path checking
+
+*********************
+Example Configuration
+*********************
+
+Set an API-KEY is the minimal configuration to get a working API Endpoint.
+
+.. code-block:: none
+
+ set service https api keys id MY-HTTPS-API-ID key MY-HTTPS-API-PLAINTEXT-KEY