diff options
| author | Yuriy Andamasov <yuriy@vyos.io> | 2026-05-06 22:08:17 +0300 |
|---|---|---|
| committer | GitHub <noreply@github.com> | 2026-05-06 22:08:17 +0300 |
| commit | c1ad0a2b289ac3b1a17c8adadfce49b1eca3c741 (patch) | |
| tree | 6ffa092a021096834532d5ce5ca4e674f412c076 /docs/configuration/service/rst-https.rst | |
| parent | ab5359702db9ba94fa27d770af440a20cf95a41b (diff) | |
| parent | 50a82c126037023d029eaa4ff2d2144c44ae039b (diff) | |
| download | vyos-documentation-c1ad0a2b289ac3b1a17c8adadfce49b1eca3c741.tar.gz vyos-documentation-c1ad0a2b289ac3b1a17c8adadfce49b1eca3c741.zip | |
Merge pull request #1901 from vyos/feat/myst-as-primary-sagitta
feat: flip swap mechanism on sagitta — MD as primary, RST as override (mirrors #1899/#1900)
Diffstat (limited to 'docs/configuration/service/rst-https.rst')
| -rw-r--r-- | docs/configuration/service/rst-https.rst | 83 |
1 files changed, 83 insertions, 0 deletions
diff --git a/docs/configuration/service/rst-https.rst b/docs/configuration/service/rst-https.rst new file mode 100644 index 00000000..973c5355 --- /dev/null +++ b/docs/configuration/service/rst-https.rst @@ -0,0 +1,83 @@ +.. _http-api: + +######## +HTTP API +######## + +VyOS provide an HTTP API. You can use it to execute op-mode commands, +update VyOS, set or delete config. + +Please take a look at the :ref:`vyosapi` page for an detailed how-to. + +************* +Configuration +************* + +.. cfgcmd:: set service https allow-client address <address> + + Only allow certain IP addresses or prefixes to access the https + webserver. + +.. cfgcmd:: set service https certificates ca-certificate <name> + + Use CA certificate from PKI subsystem + +.. cfgcmd:: set service https certificates certificate <name> + + Use certificate from PKI subsystem + +.. cfgcmd:: set service https certificates dh-params <name> + + Use :abbr:`DH (Diffie–Hellman)` parameters from PKI subsystem. + Must be at least 2048 bits in length. + +.. cfgcmd:: set service https listen-address <address> + + Webserver should only listen on specified IP address + +.. cfgcmd:: set service https port <number> + + Webserver should listen on specified port. + + Default: 443 + +.. cfgcmd:: set service https enable-http-redirect + + Enable automatic redirect from http to https. + +.. cfgcmd:: set service https tls-version <1.2 | 1.3> + + Select TLS version used. + + This defaults to both 1.2 and 1.3. + +.. cfgcmd:: set service https vrf <name> + + Start Webserver in given VRF. + +API +=== + +.. cfgcmd:: set service https api keys id <name> key <apikey> + + Set a named api key. Every key has the same, full permissions + on the system. + +.. cfgcmd:: set service https api debug + + To enable debug messages. Available via :opcmd:`show log` or + :opcmd:`monitor log` + +.. cfgcmd:: set service https api strict + + Enforce strict path checking + +********************* +Example Configuration +********************* + +Set an API-KEY is the minimal configuration to get a working API Endpoint. + +.. code-block:: none + + set service https api keys id MY-HTTPS-API-ID key MY-HTTPS-API-PLAINTEXT-KEY |
