# Install Flowfuse, setting up TLS for sslip.io

**URL:** <https://discourse.nodered.org/t/install-flowfuse-setting-up-tls-for-sslip-io/96512>\
**Category:** FlowFuse\
**Tags:** docker, flowfuse\
**Created:** [11 April 2025 03:13 UTC](https://discourse.nodered.org/t/install-flowfuse-setting-up-tls-for-sslip-io/96512 "2025-04-11T03:13:22Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![comet](https://avatars.discourse-cdn.com/v4/letter/c/a698b9/32.png) [@comet](https://discourse.nodered.org/u/comet)\
**Post date:** [11 April 2025 03:13 UTC](https://discourse.nodered.org/t/install-flowfuse-setting-up-tls-for-sslip-io/96512/1 "2025-04-11T03:13:22Z")

</div>

i use docker-compose.yaml file from github main branch `https://github.com/FlowFuse/docker-compose/`  
i use below command to start

[DOMAIN=192.100.0.101.sslip.io](http://DOMAIN=192.100.0.101.sslip.io) docker-compose -p flowfuse up  
in .env i set

```auto
TLS_ENABLED=true
TLS_CERTIFICATE= <self signed>
TLS_KEY=<self signed>

```

when i browse [https://forge.192.100.0.101.sslip.io](https://forge.192.100.0.101.sslip.io) , i get error `500 Internal Server Error, nginx/1.27.0` , http is no issue. may i know how to fix this? i'm ok to use self signed cert as my ip is not publicly accessible.

in docker logs for nginx

```auto
nginx-1 | nginx.1 | localhost 127.0.0.1 - - [11/Apr/2025:03:17:55 +0000] "HEAD / HTTP/1.1" 503 0 "-" "curl/7.88.1" "-"
nginx-1 | nginx.1 | forge.192.100.0.101.sslip.io 172.18.0.1 - - [11/Apr/2025:03:17:56 +0000] "GET / HTTP/2.0" 500 579 "-" "Mozilla/5.0 (<privacy hidden>) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36" "-"
nginx-1 | nginx.1 | forge.192.100.0.101.sslip.io 172.18.0.1 - - [11/Apr/2025:03:17:56 +0000] "GET /favicon.ico HTTP/2.0" 500 579 "https://forge.192.100.0.101.sslip.io/" "Mozilla/5.0 (<privacy hidden>) <privacy hidden>/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36" "-"

```

do i need to set env `DOCKER_DRIVER_PRIVATE_CA_PATH` when using self signed TLS ?

---

<div class="post-metadata">

**Author:** ![hardillb](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/hardillb/32/12373_2.png) [@hardillb](https://discourse.nodered.org/u/hardillb)\
**Post date:** [11 April 2025 08:07 UTC](https://discourse.nodered.org/t/install-flowfuse-setting-up-tls-for-sslip-io/96512/2 "2025-04-11T08:07:48Z")

</div>

Yes, if using self signed certs you will need to configure the `DOCKER_DRIVER_PRIVATE_CA_PATH` because the Node-RED instances need to know to trust the CA in order to complete Authentication.

You will need to suspend/restart any instances after making the change

---

<div class="post-metadata">

**Author:** ![hardillb](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/hardillb/32/12373_2.png) [@hardillb](https://discourse.nodered.org/u/hardillb)\
**Post date:** [11 April 2025 09:15 UTC](https://discourse.nodered.org/t/install-flowfuse-setting-up-tls-for-sslip-io/96512/3 "2025-04-11T09:15:47Z")

</div>

But the 500 error trying to access the forge application, does implie some other problems.

I would start by looking at the logs from other pods (specifically the forge app pod)

There was a problem with the very latest docker compose release from docker that means that the PostgreSQL database doesn't start properly, this was fixed in the release yesterday.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [10 July 2025 09:17 UTC](https://discourse.nodered.org/t/install-flowfuse-setting-up-tls-for-sslip-io/96512/4 "2025-07-10T09:17:52Z")

</div>

This topic was automatically closed 90 days after the last reply. New replies are no longer allowed.
