HUMMIX On-Premises supports Transport Layer Security (TLS) 1.2+ for incoming and outgoing traffic. To automatically switch the application to work over the secure HTTPS protocol, enable TLS encryption support.
Enabling TLS for the HUMMIX application consists of three stages:
- Prepare a secret with a certificate for working via HTTPS.
- Make changes to the configuration file.
- Apply TLS parameters for HUMMIX On-Premises.
Step 1: Prepare a secret with a certificate for working via HTTPS
To work over the HTTPS protocol, create a secret with a certificate. Next, configure trust support if it is required by the certificate or set of CA certificates you are using. Read more about these actions in Create a secret with a certificate for HTTPS operation.
Step 2: Make changes to the configuration file values-hummix.yaml
Attention
Before editing the values-hummix.yaml file, make a backup copy of it, as incorrect parameter settings may cause HUMMIX application malfunction.
- Fill put the configuration file
values-hummix.yamlto enable TLS.
To enable encryption support, specify true in the parameter global.ingress.onpremiseTls.enabled. In this parameter, specify the name of the certificate for working via https, for example, hummix-onpremise-tls. The certificate must be issued for the domain name FQDN in the parameter global.host, through which the system will be accessible, for example example.com.
global:
## Domain (FQDN) or ip address where the system is available
host: 'example.com'
ingress:
## Enable host in ingress (value taken from host)
## For installed s3 minio via hummix-dbs charts, specify in the minio block
## the value in the hosts parameter in the values-dbs.yaml file
hostEnabled: false
onpremiseTls:
## enable HTTPS
enabled: true
## name of the secret with certificates for HTTPS
secret: "hummix-onpremise-tls"
Attention
Before applying TLS parameters for the HUMMIX application, ensure that the S3 file storage operates over the HTTPS protocol (uses TLS encryption).
- Specify in the connection parameters that the S3 storage server uses TLS encryption. To do this, set
truein thedb.s3.ssl.enabledparameter.
...
db:
...
## connections settings for S3 file storage
s3:
method: PUT
accesskeyid: PZSF73JG72Ksd955JKU1HIA
secretaccesskey: aFDkj28Jbs2JKbnvJH678MNwiz88zKjsuNBHHs
bucket: s3hummix
backend:
address: example.com
region: us-east-1
ssl:
enabled: "true"
...
Step 3: Apply TLS parameters for HUMMIX On-Premises
You can update parameters for HUMMIX On-Premises in two ways: online and offline.
Update parameters online
- Determine the chart version with which the HUMMIX application was installed or updated:
helm show chart hummix/hummix
Example of command execution:

After the command execution, you see the chart version information in the APP VERSION string. Save this value for the next step.
- Update the parameters using the
values-hummix.yamlconfiguration file. To do this, execute the following command specifying the installed chart version for the--versionflag instead of<hummix-chart-version>:
helm upgrade --install hummix hummix/hummix -f values-hummix.yaml --version <hummix-chart-version> --timeout=30m --wait [-n namespace]
Update parameters offline
Navigate to the directory with the downloaded HUMMIX chart and execute the command:
helm upgrade --install hummix ./hummix -f values-hummix.yaml --timeout=30m --wait [-n namespace]
It takes about 10-30 minutes to update the parameters. Wait for it to complete.