> ## Documentation Index
> Fetch the complete documentation index at: https://docs.varios-ai.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Custom TLS Certificates

> Use custom CA certificates in VARIOS AI

In many enterprise environments, **internal certificate authorities (CAs)** or self-signed TLS certificates are used—for example for internal APIs, private container registries, or package repositories. For applications in the VARIOS AI container to trust these certificates, you can mount a custom **CA certificate bundle** from the host into the container.

This configuration ensures that the container uses additional or custom CA certificates and can establish TLS connections to servers signed by your internal CAs.

***

## Configuration

In your `docker-compose.yml`, extend the PHP container **command** and mount the certificate bundle as a volume:

```yaml theme={null}
# docker-compose.yml

php:
  [...]
  command: sh -c "/usr/sbin/update-ca-certificates 2>/dev/null || true; /scripts/run.sh"
  volumes:
    [...]
    - "/etc/pki/tls/certs/ca-bundle.crt:/usr/local/share/ca-certificates/ca-bundle.crt:ro"
```

<Note>
  The example path `/etc/pki/tls/certs/ca-bundle.crt` is typical for RHEL/CentOS systems. On Debian/Ubuntu, the system CA bundle is often at `/etc/ssl/certs/ca-certificates.crt`. Adjust the host path to match your distribution.
</Note>

***

## Apply

Save your `docker-compose.yml` and restart the containers:

```bash theme={null}
docker compose up -d
```

If the containers are already running, restarting the PHP container is sufficient—for example, `docker compose up -d php`.

***

## How It Works

On PHP container startup, the customized **command** runs these steps automatically—you do not need to execute anything manually:

1. The **CA bundle** is mounted from the host to `/usr/local/share/ca-certificates/`.
2. **`update-ca-certificates`** adds the certificates to the system-wide trust store.
3. **`/scripts/run.sh`** starts VARIOS AI as usual.

***

## Result

After the container starts:

* The host’s CA bundle is available inside the container.
* The certificates are registered in the **system-wide trust store**.
* Applications in the container can establish TLS connections to servers signed by these CAs.

***

## Typical Use Cases

* Using an **internal corporate CA**
* Accessing **internal APIs with self-signed certificates**
* Trust for **private container registries or package repositories**
