Route and inspect outbound HTTPS traffic through a MITM proxy
For the complete documentation index, see llms.txt. For a full content snapshot, see llms-full.txt. Append.mdto anykestra.io/docs/*URL for plain Markdown.
Route and inspect Kestra’s outbound HTTP/S traffic through an MITM proxy. In secured or restricted environments this is used for auditing, inspection, or policy enforcement. Kestra must trust the proxy’s CA certificate, route outbound traffic through the proxy, and configure the JVM and any auxiliary daemons (such as the Docker daemon) to use the proxy and truststore.
Security note: An MITM proxy intercepts TLS traffic. Only enable this in controlled environments and with appropriate approvals.
Prerequisites
1. Create a Java truststore with the MITM CA certificate
Import the MITM CA certificate into a Java keystore so the JVM trusts intercepted TLS connections:
keytool -importcert -alias mitmproxy-ca -storepass changeit -keystore truststore.jks -trustcacerts -file mitmproxy-ca.crt -nopromptTip: prefer a strong password instead of changeit in production. You can also use PKCS12 by setting -deststoretype PKCS12.
2. (Kubernetes) Create a Secret containing the truststore
Create a Kubernetes secret from the truststore.jks:
kubectl create secret generic kestra-ssl --from-file=truststore.jks -n kestraThis secret will be mounted into Kestra pods.
Configuring Kestra to use the MITM proxy
The Observability and Networking configuration must include proxy settings, and the truststore must be available inside the container. The following covers both Kubernetes (Helm) and Docker Compose deployments.
1. Micronaut / Kestra configuration
Add proxy settings and truststore configuration to your Observability and Networking configuration (merged via Helm configurations.application or a config file):
## values.yamlconfigurations: application: micronaut: http: client: proxy-address: "your.proxy.net:8000" proxy-type: HTTP server: ssl: clientAuthentication: want trustStore: path: "file:/app/ssl/truststore.jks" password: "changeit" type: "JKS"2. Mount the truststore inside the container
Kubernetes (Helm values.yaml)
common: extraVolumeMounts: - name: ssl-secret mountPath: "/app/ssl" readOnly: true extraVolumes: - name: ssl-secret secret: secretName: kestra-sslDocker Compose
services: kestra: volumes: - kestra-data:/app/storage - /var/run/docker.sock:/var/run/docker.sock - tmp-kestra:/tmp/kestra-wd - ./ssl:/app/ssl # ensure ./ssl/truststore.jks exists on host3. JVM environment variables (JAVA_OPTS)
Kubernetes (values.yaml)
common: extraEnv: - name: JAVA_OPTS value: >- -Djavax.net.ssl.trustStore=/app/ssl/truststore.jks -Djavax.net.ssl.trustStorePassword=changeit -Djavax.net.ssl.trustStoreType=JKS -Dhttp.proxyHost=your.proxy.net -Dhttp.proxyPort=8000 -Dhttps.proxyHost=your.proxy.net -Dhttps.proxyPort=8000 -Dhttp.nonProxyHosts=localhost|127.0.0.1|kubernetes.default.svc|.svc|.cluster.local|your.nexus.domain.com|kestra-minioDocker Compose
services: kestra: environment: - JAVA_OPTS=-Djavax.net.ssl.trustStore=/app/ssl/truststore.jks -Djavax.net.ssl.trustStorePassword=changeit -Djavax.net.ssl.trustStoreType=JKS -Dhttp.proxyHost=your.proxy.net -Dhttp.proxyPort=8000 -Dhttps.proxyHost=your.proxy.net -Dhttps.proxyPort=8000 -Dhttp.nonProxyHosts=localhost|127.0.0.1|your.nexus.domain.comTroubleshooting
-
TLS handshake errors Verify
truststore.jkscontains the correct CA (keytool -list -keystore truststore.jks). -
Requests not reaching the proxy Confirm
http.proxyHost/https.proxyHostandhttp.nonProxyHostsare correct. -
Docker image pull failures Add the MITM CA to Docker daemon certs (
/etc/docker/certs.d/.../ca.crt). -
Debugging TLS Temporarily enable:
-Djavax.net.debug=ssl,handshake.
Was this page helpful?