k6 ↔ InfluxDB TLS verification: configuring trusted internal CA for production tests
27.5K reputation · 02 Sept 2020, 13:06 UTC
The goal is to execute a k6 test that writes metrics to an InfluxDB endpoint over HTTPS in a production environment while keeping TLS certificate verification enabled, rather than disabling it with --insecure-skip-tls-verify.
By default, k6 relies on the Node.js TLS implementation and the system's root CA bundle to validate the InfluxDB server's certificate. In production, InfluxDB is often served behind an internal or corporate PKI, so the presenting certificate may be signed by a CA that is not present in the default trust store. Supplying the additional CA can be done via the NODE_EXTRA_CA_CERTS environment variable or by mounting a custom CA bundle into the k6 container, but the recommended approach for containerized CI pipelines, the behavior across different k6‑bundled Node.js versions, and whether multiple CA files can be combined remain unclear.
What is the recommended way to inject a custom CA bundle into a k6 Docker image without rebuilding the image for each certificate change?
How does NODE_EXTRA_CA_CERTS behave across different versions of the Node.js runtime bundled with k6, and are there any version‑specific caveats?
Can k6 be configured to accept multiple CA files (e.g., via a directory or a concatenated PEM) to trust both the internal PKI and public roots simultaneously?
1 answer
0 question comments
Use comments to ask for clarification. Post a solution as an answer.
No question comments on this page.