> For the complete documentation index, see [llms.txt](https://docs.e6data.com/query-engine/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.e6data.com/query-engine/guides/security/authentication/tls-certificates.md).

# TLS certificates

How TLS certificates work for e6data endpoints - Serverless (managed by e6data) vs In-VPC (managed by you).

All e6data endpoints are TLS-protected. How the certificate is managed depends on your deployment model.

## Serverless

For Serverless workspaces, e6data manages TLS certificates automatically:

* Certificates are issued by a public CA and rotated before expiry
* No action is required from you
* The certificate covers the workspace endpoint provisioned by e6data

If you want a custom hostname (e.g., `analytics.acme.com`) instead of the default e6data-provided hostname, contact your e6data CSM - this is supported as a paid add-on.

## In Your VPC

For In-VPC deployments, you manage the certificate. The certificate covers your custom endpoint hostname (e.g., `e6data.acme.com`).

### Initial certificate

During [workspace deployment](/query-engine/guides/deployment/azure-in-vpc/deploy-workspace-and-e6data.md), you create a Kubernetes TLS secret with your certificate:

```bash
kubectl create secret tls envoy-tls \
  -n <WORKSPACE_NAME> \
  --cert=fullchain.pem \
  --key=privkey.pem
```

A single certificate covering the workspace's specific hostname is sufficient. No wildcard required.

### Using Let's Encrypt with cert-manager

cert-manager is installed as part of the [base cluster setup](/query-engine/guides/deployment/azure-in-vpc/configure-registry-kubernetes-networking.md). To use Let's Encrypt:

1. Create a `ClusterIssuer` pointing to Let's Encrypt's production server
2. Create a `Certificate` resource targeting your workspace's hostname
3. cert-manager fetches and renews the certificate automatically

See the [cert-manager documentation](https://cert-manager.io/docs/) for the exact resource specs.

The `Certificate` resource must produce a secret named `envoy-tls` - the name the QueryRouter references in `spec.auth.tls.secretName`.

### Using your own CA

If your organization runs an internal CA:

1. Generate a CSR for your workspace's hostname
2. Submit to your CA
3. Receive the certificate and chain
4. Create the Kubernetes TLS secret as shown above

Certificate rotation is on you - set up a reminder to renew before expiry, or automate with cert-manager pointing at your internal CA's ACME endpoint (if supported).

### Certificate rotation

To rotate the certificate:

1. Generate or fetch a new certificate
2. Update the TLS secret:

   ```bash
   kubectl create secret tls envoy-tls \
     -n <WORKSPACE_NAME> \
     --cert=new-fullchain.pem \
     --key=new-privkey.pem \
     --dry-run=client -o yaml | kubectl apply -f -
   ```
3. Envoy automatically picks up the new certificate - typically within a minute, depending on how quickly kubelet syncs the updated secret to the pod; no pod restart needed

If you're using cert-manager, rotation happens automatically.

### Monitoring certificate expiry

Set up alerting in your observability stack on certificate expiry:

* Most observability platforms have a built-in TLS-expiry check
* For self-monitoring, query `kubectl get secret envoy-tls -o jsonpath='{.data.tls\.crt}' | base64 -d | openssl x509 -enddate -noout`

Aim to rotate at least 14 days before expiry.

## Verifying your endpoint

Check the certificate served by your workspace endpoint:

```bash
openssl s_client -connect <workspace-endpoint>:443 -servername <workspace-endpoint> </dev/null 2>/dev/null | \
  openssl x509 -noout -subject -issuer -dates
```

Should show your hostname as the subject and a valid date range.

## See also

* [Deploy a workspace](/query-engine/guides/deployment/azure-in-vpc/deploy-workspace-and-e6data.md)
* [Base cluster setup](/query-engine/guides/deployment/azure-in-vpc/configure-registry-kubernetes-networking.md) - installs cert-manager
* [Connection info](/query-engine/guides/clusters/create-and-manage-clusters.md)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.e6data.com/query-engine/guides/security/authentication/tls-certificates.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
