---
title: Charmhub | Deploy Opensearch K8S using Charmhub - The Open Operator Collection
description: Deploy the latest version of Opensearch K8S as a Kubernetes Operator
  on any cloud.
url: https://charmhub.io/opensearch-k8s/docs/h-enable-tls
---

# Opensearch K8S

[Canonical](https://charmhub.io/publisher/data-platform "View all packages from Canonical")

* [Canonical](https://charmhub.io/publisher/data-platform "View all packages from Canonical")

Platform:

2/edge 22

```
juju deploy opensearch-k8s --channel 2/edge
```

[Learn to deploy on juju >](https://juju.is/docs/juju/manage-applications)

---

Share your thoughts on this charm with the community on discourse.

[Join the discussion](https://discourse.charmhub.io/)

# How to enable TLS encryption

This guide will show how to enable TLS using the [`self-signed-certificates` operator](https://github.com/canonical/self-signed-certificates-operator) as an example.

**[Self-signed certificates](https://en.wikipedia.org/wiki/Self-signed_certificate) are not recommended for a production environment.**

Check [this guide](https://discourse.charmhub.io/t/11664) for an overview of the signed and self-signed certificate charms available.

## [Summary](https://charmhub.io/opensearch-k8s/docs/h-enable-tls#p-32624-summary)

* [Enable TLS](https://charmhub.io/opensearch-k8s/docs/h-enable-tls#enable-tls)
* [Disable TLS](https://charmhub.io/opensearch-k8s/docs/h-enable-tls#disable-tls)
* [Manage certificates](https://charmhub.io/opensearch-k8s/docs/h-enable-tls#manage-certificates)
  + [Check certificates in use](https://charmhub.io/opensearch-k8s/docs/h-enable-tls#check-certificates-in-use)
  + [Update keys](https://charmhub.io/opensearch-k8s/docs/h-enable-tls#update-keys)

---

## [Enable TLS](https://charmhub.io/opensearch-k8s/docs/h-enable-tls#p-32624-enable-tls)

First, deploy the TLS charm and configure the name of the Certificate Authority:

```
juju deploy self-signed-certificates --config ca-common-name="My CA"
```

To enable TLS on Charmed OpenSearch, integrate the two applications:

```
juju integrate self-signed-certificates opensearch
```

After the deployment has settled, you can see the relation by running `juju status --relations` .

## [Disable TLS](https://charmhub.io/opensearch-k8s/docs/h-enable-tls#p-32624-disable-tls)

TLS is a requirement for Charmed OpenSearch, therefore TLS should not be disabled.

## [Manage certificates](https://charmhub.io/opensearch-k8s/docs/h-enable-tls#p-32624-manage-certificates)

### [Check certificates in use](https://charmhub.io/opensearch-k8s/docs/h-enable-tls#p-32624-check-certificates-in-use)

To check the certificates in use by OpenSearch, you can run:

```
openssl s_client -showcerts -connect leader_unit_IP:port < /dev/null | grep issuer
```

### [Update keys](https://charmhub.io/opensearch-k8s/docs/h-enable-tls#p-32624-update-keys)

Updates to private keys for certificate signing requests (CSR) can be made via the `set-tls-private-key` action. Charmed OpenSearch uses three types of certificates:

* `app-admin`: used for administrative actions on opensearch
* `unit-transport`: used for internal communication between opensearch nodes
* `unit-http`: used for external communication between opensearch and clients (users or applications)

The private key for `app-admin` can only be applied on the leader-unit.

Updates to each of these can be done with auto-generated keys:

```
juju run opensearch/leader set-tls-private-key category=app-admin
juju run opensearch/leader set-tls-private-key category=unit-transport
juju run opensearch/leader set-tls-private-key category=unit-http
```

It is also possible to use self-generated keys:

```
openssl genrsa -out unit-http.pem 3072
openssl genrsa -out unit-transport.pem 3072
openssl genrsa -out app-admin.pem 3072
```

Apply the private key for `app-admin` to the juju leader:

```
juju run opensearch/leader set-tls-private-key category=app-admin key="$(base64 -w0 app-admin.pem)"
```

Apply the private keys for `unit-transport` and `unit-http` to all units (including the leader):

```
juju run opensearch/leader set-tls-private-key category=unit-http key="$(base64 -w0 unit-http.pem)"
juju run opensearch/leader set-tls-private-key category=unit-transport key="$(base64 -w0 unit-transport.pem)"
```

---
