---
title: Charmhub | Deploy Temporal Server using Charmhub - The Open Operator Collection
description: Deploy the latest version of Temporal Server as a Kubernetes Operator
  on any cloud.
url: https://charmhub.io/temporal-k8s/docs/h-configure-frontend-tls
---

# Temporal Server

[Workflows Charmers](https://charmhub.io/publisher/workflows-charmers "View all packages from Workflows Charmers")

* [Workflows Charmers](https://charmhub.io/publisher/workflows-charmers "View all packages from Workflows Charmers")

Platform:

1.23/stable 60

```
juju deploy temporal-k8s --channel 1.23/stable
```

[Learn to deploy on juju >](https://juju.is/docs/juju/manage-applications)

---

#### Relevant links

* [Homepage](https://github.com/canonical/temporal-k8s-operator)

---

#### Contacts

##### Maintainers

+ [Commercial Systems](mailto:jaas-crew@lists.canonical.com)

* [Submit a bug](https://github.com/canonical/temporal-k8s-operator/issues)

---

Share your thoughts on this charm with the community on discourse.

[Join the discussion](https://discourse.charmhub.io/)

# Configure frontend TLS

This guide provides instructions for configuring frontend Transport Layer Security (TLS) termination in Charmed Temporal.

In the context of Temporal, frontend TLS refers to the use of TLS to secure network communication between Temporal clients (SDKs, CLI, or Web UI) and the Temporal Frontend Service. The Temporal Frontend Service acts as the API gateway for client requests to the Temporal Server.

See [TLS configuration reference](https://docs.temporal.io/references/configuration#tls) for more details.

There are two ways to handle TLS in your deployment:

* Frontend TLS – TLS termination is managed directly by the Temporal frontend.
* Ingress TLS Termination – TLS is terminated at the ingress level (e.g., with NGINX).

If you need TLS termination at the ingress, see [Configure Ingress with Nginx Ingress Integrator](https://charmhub.io/temporal-k8s/docs/h-deploy-ingress).

Important: While it’s technically possible to enable end-to-end encryption by letting Temporal handle TLS termination and having the ingress forward unencrypted traffic, this setup is not supported yet. You’ll need to choose one approach: either handle TLS at the frontend or at the ingress, but not both.

## [Requirements](https://charmhub.io/temporal-k8s/docs/h-configure-frontend-tls#p-38469-requirements)

* A Charmed Temporal deployment.
* The `temporal-k8s` charm to be configured with TLS must include `frontend` in its `service` configuration. You can check it as follows:

```
juju config temporal-k8s services

frontend
```

## [Enable frontend TLS](https://charmhub.io/temporal-k8s/docs/h-configure-frontend-tls#p-38469-enable-frontend-tls)

1. Integrate with a TLS certificate provider:

```
juju integrate temporal-k8s <tls-certificate-provider-charm>
```

1. If the certificate needs a specific Common Name (CN) and SANS (Subject Alternative NAmes) DNS, you can configure them as follows:

```
juju config temporal-k8s frontend-cert-common-name=<common_name>
juju config temporal-k8s frontend-cert-sans-dns=<sans_dns_comma_separated_list>
```

1. All requests from Temporal clients to the frontend must now trust the Certificate Authority (CA) that signed the Temporal frontend certificate. You can retrieve the CA certificate from the TLS certificate provider charms by running:

```
juju run <tls-cert-provider-charm> get-ca-certificate
```

---
