Skip to main content
In many enterprise environments, internal certificate authorities (CAs) or self-signed TLS certificates are used—for example for internal APIs, private container registries, or package repositories. For applications in the VARIOS AI container to trust these certificates, you can mount a custom CA certificate bundle from the host into the container. This configuration ensures that the container uses additional or custom CA certificates and can establish TLS connections to servers signed by your internal CAs.

Configuration

In your docker-compose.yml, extend the PHP container command and mount the certificate bundle as a volume:
# docker-compose.yml

php:
  [...]
  command: sh -c "/usr/sbin/update-ca-certificates 2>/dev/null || true; /scripts/run.sh"
  volumes:
    [...]
    - "/etc/pki/tls/certs/ca-bundle.crt:/usr/local/share/ca-certificates/ca-bundle.crt:ro"
The example path /etc/pki/tls/certs/ca-bundle.crt is typical for RHEL/CentOS systems. On Debian/Ubuntu, the system CA bundle is often at /etc/ssl/certs/ca-certificates.crt. Adjust the host path to match your distribution.

Apply

Save your docker-compose.yml and restart the containers:
docker compose up -d
If the containers are already running, restarting the PHP container is sufficient—for example, docker compose up -d php.

How It Works

On PHP container startup, the customized command runs these steps automatically—you do not need to execute anything manually:
  1. The CA bundle is mounted from the host to /usr/local/share/ca-certificates/.
  2. update-ca-certificates adds the certificates to the system-wide trust store.
  3. /scripts/run.sh starts VARIOS AI as usual.

Result

After the container starts:
  • The host’s CA bundle is available inside the container.
  • The certificates are registered in the system-wide trust store.
  • Applications in the container can establish TLS connections to servers signed by these CAs.

Typical Use Cases

  • Using an internal corporate CA
  • Accessing internal APIs with self-signed certificates
  • Trust for private container registries or package repositories