- Task
- Create
Configure TLS certificates for Liquibase Secure server
Last updated: September 29, 2026
By default, liquibase-platform install generates a self-signed TLS certificate, and browsers show a security warning when your team opens the web app. Use this guide to serve the deployment with a certificate issued by your organization's certificate authority instead.
Procedure
Obtain a PEM-encoded certificate and private key
Request a certificate for the hostname your team will use to reach the server. Common sources are:
Active Directory Certificate Services (Windows PKI)
HashiCorp Vault PKI secrets engine
An internal OpenSSL certificate authority
Certbot with Let's Encrypt, which requires public DNS and internet access
Both files must be PEM-encoded. If your certificate authority provides a certificate chain, concatenate the leaf and intermediate certificates into a single file.
Install the certificates
New installation: Pass both certificate flags to the install command. The flags must be provided together, and the files are copied into the deployment's certs/ directory.
Be sure to:
Replace
your_registry_urlwith the container registry URL provided by Liquibase. For example,registry.liquibase.comReplace
path/to/server.crtandpath/to/server.keywith the paths to your certificate and private key files
Running deployment: Copy the new certificate and key over the existing files in the certs/ directory, then restart the stack.
Verify the certificate
Open the web app URL in a browser and confirm that no certificate warning appears. To inspect the certificate the server presents, run:
Be sure to:
Replace
your_server_hostwith the hostname of your deployment. For example,liquibase.internal.example.com
Troubleshooting
TLS certificate generation fails during install
If the install command cannot generate a self-signed certificate, place your own certificate and key at certs/server.crt and certs/server.key, then run the install again.