• Task
  • Create

Configure TLS certificates for Liquibase Secure server

Last updated: September 29, 2026

By default, liquibase-platform install generates a self-signed TLS certificate, and browsers show a security warning when your team opens the web app. Use this guide to serve the deployment with a certificate issued by your organization's certificate authority instead.

Procedure

1

Obtain a PEM-encoded certificate and private key

Request a certificate for the hostname your team will use to reach the server. Common sources are:

  • Active Directory Certificate Services (Windows PKI)

  • HashiCorp Vault PKI secrets engine

  • An internal OpenSSL certificate authority

  • Certbot with Let's Encrypt, which requires public DNS and internet access

Both files must be PEM-encoded. If your certificate authority provides a certificate chain, concatenate the leaf and intermediate certificates into a single file.

2

Install the certificates

New installation: Pass both certificate flags to the install command. The flags must be provided together, and the files are copied into the deployment's certs/ directory.

Be sure to:

  • Replace your_registry_url with the container registry URL provided by Liquibase. For example, registry.liquibase.com

  • Replace path/to/server.crt and path/to/server.key with the paths to your certificate and private key files

loading

Running deployment: Copy the new certificate and key over the existing files in the certs/ directory, then restart the stack.

loading
3

Verify the certificate

Open the web app URL in a browser and confirm that no certificate warning appears. To inspect the certificate the server presents, run:

Be sure to:

  • Replace your_server_host with the hostname of your deployment. For example, liquibase.internal.example.com

loading

Troubleshooting

TLS certificate generation fails during install

If the install command cannot generate a self-signed certificate, place your own certificate and key at certs/server.crt and certs/server.key, then run the install again.