Enabling HTTPS Connections

This guide will walk you through how to generate your own self-signed certificates for use by the Chainlink node. You can also substitute self-signed certificates with certificates of your own, like those created by Let's Encrypt.

Create a directory tls/ within your local Chainlink directory:

mkdir ~/.chainlink-sepolia/tls

Run this command to create a server.crt and server.key file in the previously created directory:

openssl req -x509 -out  ~/.chainlink-sepolia/tls/server.crt  -keyout ~/.chainlink-sepolia/tls/server.key \
  -newkey rsa:2048 -nodes -sha256 -days 365 \
  -subj '/CN=localhost' -extensions EXT -config <( \
   printf "[dn]\nCN=localhost\n[req]\ndistinguished_name = dn\n[EXT]\nsubjectAltName=DNS:localhost\nkeyUsage=digitalSignature\nextendedKeyUsage=serverAuth")

Next, add the certificate and key paths to the [WebServer.TLS] section of your config.toml file. Set SecureCookies to true and HTTPSPort to the HTTPS port:

[WebServer]
SecureCookies = true

[WebServer.TLS]
CertPath = '/chainlink/tls/server.crt'
KeyPath = '/chainlink/tls/server.key'
HTTPSPort = 6689

Finally, update your run command to forward port 6689 to the container instead of 6688:

cd ~/.chainlink-sepolia && docker run -p 6689:6689 -v ~/.chainlink-sepolia:/chainlink -it smartcontract/chainlink:2.66.0 node -config /chainlink/config.toml -secrets /chainlink/secrets.toml start

Now when running the node, you can access it by navigating to https://localhost:6689 if running on the same machine or with a ssh tunnel.

What's next

Get the latest Chainlink content straight to your inbox.