Skip to content

docs: require well-known CA-signed TLS certs for enterprise install#466

Merged
ak684 merged 2 commits into
mainfrom
docs/well-known-ca-certs
Apr 21, 2026
Merged

docs: require well-known CA-signed TLS certs for enterprise install#466
ak684 merged 2 commits into
mainfrom
docs/well-known-ca-certs

Conversation

@ak684
Copy link
Copy Markdown
Contributor

@ak684 ak684 commented Apr 21, 2026

Summary

  • Updates the Enterprise Quick Start TLS guidance to explicitly require a certificate signed by a well-known certificate authority, and notes that self-signed certs are not supported for the OpenHands application.
  • Scoped change: the existing warning about the Replicated Admin Console's hardcoded self-signed cert is left untouched since that behavior is outside our control and is factually accurate.

Context

From a recent discussion with the field team (JM, Rajiv, Joe): since Enterprise trials are explicitly the self-hosted path, customers' network/IT teams are unlikely to issue self-signed certs, and we should steer POCs toward well-known CA-signed certs rather than leaving the door open to self-signed.

Test plan

  • Mintlify preview renders the updated TLS Setup section correctly
  • Wording reads clearly for a first-time enterprise installer

@mintlify
Copy link
Copy Markdown

mintlify Bot commented Apr 21, 2026

Preview deployment for your docs. Learn more about Mintlify Previews.

Project Status Preview Updated (UTC)
all-hands-ai 🟢 Ready View Preview Apr 21, 2026, 8:38 PM

💡 Tip: Enable Workflows to automatically generate PRs for you.

Copy link
Copy Markdown
Contributor

@all-hands-bot all-hands-bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Taste Rating: 🟢 Good taste - Clear, actionable documentation improvement that solves a real field problem.

[RISK ASSESSMENT]

  • [Overall PR] ⚠️ Risk Assessment: 🟢 LOW
    Documentation-only change that improves security guidance for enterprise installations. No code, infrastructure, or breaking changes. Scoped appropriately.

VERDICT:
✅ Worth merging: Clean documentation update with clear, professional wording.

KEY INSIGHT:
Steering enterprise users toward well-known CA-signed certificates eliminates a common source of installation confusion and aligns with production security best practices.

Comment thread enterprise/quick-start.mdx Outdated
Co-authored-by: Joe Laverty <jlav@users.noreply.github.com>
@ak684 ak684 merged commit ff18856 into main Apr 21, 2026
5 checks passed
@ak684 ak684 deleted the docs/well-known-ca-certs branch April 21, 2026 21:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants