Add optional loopback TLS to API startup
This commit is contained in:
@@ -24,4 +24,25 @@ if (-not ($ollama.models.name -contains $model)) {
|
||||
throw "Ollama is running, but model '$model' is missing. Run: ollama pull $model"
|
||||
}
|
||||
$port = if ($env:SOVEREIGNAI_API_PORT) { $env:SOVEREIGNAI_API_PORT } else { '8000' }
|
||||
& (Join-Path $project '.venv\Scripts\python.exe') -m uvicorn app.main:app --app-dir $project --host 127.0.0.1 --port $port
|
||||
$uvicornArgs = @(
|
||||
'-m', 'uvicorn', 'app.main:app',
|
||||
'--app-dir', $project,
|
||||
'--host', '127.0.0.1',
|
||||
'--port', $port
|
||||
)
|
||||
$tlsCertificate = $env:SOVEREIGNAI_TLS_CERTFILE
|
||||
$tlsPrivateKey = $env:SOVEREIGNAI_TLS_KEYFILE
|
||||
if ([string]::IsNullOrWhiteSpace($tlsCertificate) -ne [string]::IsNullOrWhiteSpace($tlsPrivateKey)) {
|
||||
throw 'Set both SOVEREIGNAI_TLS_CERTFILE and SOVEREIGNAI_TLS_KEYFILE, or leave both empty.'
|
||||
}
|
||||
if (-not [string]::IsNullOrWhiteSpace($tlsCertificate)) {
|
||||
if (-not (Test-Path -LiteralPath $tlsCertificate -PathType Leaf) -or
|
||||
-not (Test-Path -LiteralPath $tlsPrivateKey -PathType Leaf)) {
|
||||
throw 'The configured TLS certificate or private-key file does not exist.'
|
||||
}
|
||||
$uvicornArgs += @('--ssl-certfile', $tlsCertificate, '--ssl-keyfile', $tlsPrivateKey)
|
||||
Write-Host 'Local HTTPS enabled with the configured certificate (loopback only).'
|
||||
} else {
|
||||
Write-Host 'Local HTTP enabled (loopback only).'
|
||||
}
|
||||
& (Join-Path $project '.venv\Scripts\python.exe') @uvicornArgs
|
||||
|
||||
Reference in New Issue
Block a user