How to Configure SSL/HTTPS for Production Deployments of AnythingLLM
AnythingLLM supports HTTPS through native Node.js TLS termination—enabled via the ENABLE_HTTPS environment variable—or by terminating TLS at an external reverse proxy such as Nginx, with reverse-proxy deployment recommended for production environments.
To secure your self-hosted AI workspace, you must configure SSL/HTTPS for production deployments of AnythingLLM. The open-source application (maintained by Mintplex-Labs) offers flexible TLS deployment options—either native HTTPS support within the Node.js server or delegation to a reverse proxy—allowing administrators to align security implementation with their infrastructure standards.
Native HTTPS Configuration in AnythingLLM
AnythingLLM can terminate TLS directly within its Node.js server when provided with valid certificate files, eliminating the need for external proxy layers in simpler deployments.
Enabling Built-in TLS
According to the source code in server/index.js (lines 59-61), the application evaluates process.env.ENABLE_HTTPS to determine whether to invoke the secure boot path. When ENABLE_HTTPS is set to "true", the server imports bootSSL from server/utils/boot/index.js (lines 19-31), which creates an HTTPS server using the certificate and private key specified by the environment variables HTTPS_CERT_PATH and HTTPS_KEY_PATH.
The bootSSL function also configures WebSocket support via express-ws (lines 44-45 in server/utils/boot/index.js) to ensure real-time agent streams function over secure WebSocket (wss://) connections. If certificate loading fails, the implementation gracefully falls back to plain HTTP and logs the specific error for troubleshooting (lines 46-56), preventing application crashes while alerting administrators to configuration issues.
Required Environment Variables
Configure these variables in your server/.env file, following the template in server/.env.example (lines 49-53):
ENABLE_HTTPS="true"
HTTPS_CERT_PATH="/app/server/ssl/fullchain.pem"
HTTPS_KEY_PATH="/app/server/ssl/privkey.pem"
Docker Deployment with TLS Certificates
When running AnythingLLM via Docker, bind-mount your certificate directory as a read-only volume and pass the environment variables through docker-compose.yml:
services:
anything-llm:
build:
context: ../.
dockerfile: ./docker/Dockerfile
ports:
- "3001:3001"
volumes:
- "./.env:/app/server/.env"
- "/opt/anything-llm/ssl:/app/server/ssl:ro"
- "../server/storage:/app/server/storage"
- "../collector/hotdir/:/app/collector/hotdir"
- "../collector/outputs/:/app/collector/outputs"
environment:
- ENABLE_HTTPS=true
- HTTPS_CERT_PATH=/app/server/ssl/fullchain.pem
- HTTPS_KEY_PATH=/app/server/ssl/privkey.pem
Reverse Proxy TLS Termination (Recommended)
For production deployments, terminating TLS at a reverse proxy provides centralized certificate management, automated Let's Encrypt integration, and additional security hardening through HTTP/2 and HSTS enforcement.
Nginx Configuration Example
The official bare-metal documentation in BARE_METAL.md (lines 15-28) provides an Nginx configuration that proxies both HTTP API routes and WebSocket connections. This approach allows the upstream Node process to run on plain HTTP internally while presenting HTTPS externally:
server {
listen 443 ssl;
server_name chat.example.com;
ssl_certificate /etc/ssl/certs/fullchain.pem;
ssl_certificate_key /etc/ssl/private/privkey.pem;
ssl_protocols TLSv1.2 TLSv1.3;
location / {
proxy_pass http://localhost:3001;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}
# WebSocket support for agent streams
location ~* ^/api/agent-invocation/(.*) {
proxy_pass http://localhost:3001;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "Upgrade";
}
proxy_connect_timeout 600s;
proxy_send_timeout 600s;
proxy_read_timeout 600s;
}
Generating Self-Signed Certificates for Testing
For internal testing before deploying production certificates from a trusted CA:
mkdir -p sslcert
openssl req -newkey rsa:2048 -nodes -keyout sslcert/key.pem \
-x509 -days 365 -out sslcert/cert.pem -subj "/CN=anything.local"
Self-signed certificates are suitable for development environments; production deployments should use certificates from a trusted certificate authority.
Summary
- Native TLS termination: Set
ENABLE_HTTPS=truewith validHTTPS_CERT_PATHandHTTPS_KEY_PATHvalues to enable direct HTTPS serving via thebootSSLfunction inserver/utils/boot/index.js, with automatic WebSocket (wss://) support. - Reverse proxy deployment: Deploy Nginx, Traefik, or similar in front of AnythingLLM to handle TLS termination and certificate rotation, allowing the application to run on plain HTTP internally while presenting HTTPS externally.
- Certificate fallback behavior: If native HTTPS is enabled but certificate files are missing or invalid, the server falls back to HTTP (as implemented in lines 46-56 of
server/utils/boot/index.js) and logs the error rather than crashing. - WebSocket compatibility: Ensure proxy configurations include
UpgradeandConnectionheaders for/api/agent-invocation/routes to maintain real-time agent functionality over TLS.
Frequently Asked Questions
Can AnythingLLM automatically redirect HTTP to HTTPS?
No, the current implementation in server/utils/boot/index.js starts either an HTTPS server or an HTTP server based on the ENABLE_HTTPS flag, but does not include a redirect mechanism. To enforce HTTPS, deploy a reverse proxy that handles 301 redirects from port 80 to 443, or configure the HTTP instance solely for redirection while the HTTPS instance serves the application on a separate port.
What happens if the SSL certificate files are missing or invalid?
If the bootSSL function cannot load the certificate or key files specified in HTTPS_CERT_PATH or HTTPS_KEY_PATH, the server logs the specific filesystem error and falls back to running on plain HTTP (lines 46-56 in server/utils/boot/index.js). This prevents the application from crashing but leaves the deployment insecure, so verify file paths, permissions, and certificate validity before production deployment.
Does AnythingLLM support Let's Encrypt or automated certificate rotation?
Not natively within the application code. For automated certificate management, use a reverse proxy such as Nginx with Certbot, or Traefik with built-in ACME support. These tools handle Let's Encrypt challenges, automatic renewal, and configuration reloading without requiring changes to the ENABLE_HTTPS configuration or container restarts.
How do I secure WebSocket connections for agent features?
When using native HTTPS, the bootSSL function automatically configures express-ws to serve WebSocket connections over wss:// (secure WebSocket) as shown in lines 44-45 of server/utils/boot/index.js. When using a reverse proxy, include the Upgrade $http_upgrade and Connection "Upgrade" headers in your proxy configuration for routes matching /api/agent-invocation/ to ensure agent streams and real-time features function correctly over TLS.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →