summaryrefslogtreecommitdiff
path: root/docs/configuration/service/rst-https.rst
diff options
context:
space:
mode:
authorYuriy Andamasov <yuriy@vyos.io>2026-05-06 22:08:17 +0300
committerGitHub <noreply@github.com>2026-05-06 22:08:17 +0300
commitc1ad0a2b289ac3b1a17c8adadfce49b1eca3c741 (patch)
tree6ffa092a021096834532d5ce5ca4e674f412c076 /docs/configuration/service/rst-https.rst
parentab5359702db9ba94fa27d770af440a20cf95a41b (diff)
parent50a82c126037023d029eaa4ff2d2144c44ae039b (diff)
downloadvyos-documentation-c1ad0a2b289ac3b1a17c8adadfce49b1eca3c741.tar.gz
vyos-documentation-c1ad0a2b289ac3b1a17c8adadfce49b1eca3c741.zip
Merge pull request #1901 from vyos/feat/myst-as-primary-sagitta
feat: flip swap mechanism on sagitta — MD as primary, RST as override (mirrors #1899/#1900)
Diffstat (limited to 'docs/configuration/service/rst-https.rst')
-rw-r--r--docs/configuration/service/rst-https.rst83
1 files changed, 83 insertions, 0 deletions
diff --git a/docs/configuration/service/rst-https.rst b/docs/configuration/service/rst-https.rst
new file mode 100644
index 00000000..973c5355
--- /dev/null
+++ b/docs/configuration/service/rst-https.rst
@@ -0,0 +1,83 @@
+.. _http-api:
+
+########
+HTTP API
+########
+
+VyOS provide an HTTP API. You can use it to execute op-mode commands,
+update VyOS, set or delete config.
+
+Please take a look at the :ref:`vyosapi` page for an detailed how-to.
+
+*************
+Configuration
+*************
+
+.. cfgcmd:: set service https allow-client address <address>
+
+ Only allow certain IP addresses or prefixes to access the https
+ webserver.
+
+.. cfgcmd:: set service https certificates ca-certificate <name>
+
+ Use CA certificate from PKI subsystem
+
+.. cfgcmd:: set service https certificates certificate <name>
+
+ Use certificate from PKI subsystem
+
+.. cfgcmd:: set service https certificates dh-params <name>
+
+ Use :abbr:`DH (Diffie–Hellman)` parameters from PKI subsystem.
+ Must be at least 2048 bits in length.
+
+.. cfgcmd:: set service https listen-address <address>
+
+ Webserver should only listen on specified IP address
+
+.. cfgcmd:: set service https port <number>
+
+ Webserver should listen on specified port.
+
+ Default: 443
+
+.. cfgcmd:: set service https enable-http-redirect
+
+ Enable automatic redirect from http to https.
+
+.. cfgcmd:: set service https tls-version <1.2 | 1.3>
+
+ Select TLS version used.
+
+ This defaults to both 1.2 and 1.3.
+
+.. cfgcmd:: set service https vrf <name>
+
+ Start Webserver in given VRF.
+
+API
+===
+
+.. cfgcmd:: set service https api keys id <name> key <apikey>
+
+ Set a named api key. Every key has the same, full permissions
+ on the system.
+
+.. cfgcmd:: set service https api debug
+
+ To enable debug messages. Available via :opcmd:`show log` or
+ :opcmd:`monitor log`
+
+.. cfgcmd:: set service https api strict
+
+ Enforce strict path checking
+
+*********************
+Example Configuration
+*********************
+
+Set an API-KEY is the minimal configuration to get a working API Endpoint.
+
+.. code-block:: none
+
+ set service https api keys id MY-HTTPS-API-ID key MY-HTTPS-API-PLAINTEXT-KEY