# Split out "tls\_dir" into individual files so that Docker/K8s secrets management can be plugged in

**URL:** <https://discuss.dgraph.io/t/split-out-tls-dir-into-individual-files-so-that-docker-k8s-secrets-management-can-be-plugged-in/8786>\
**Category:** Dgraph\
**Tags:** dgraph, kind:enhancement, status:accepted, area:operations, area:kubernetes\
**Created:** [August 15, 2019, 2:06pm UTC](https://discuss.dgraph.io/t/split-out-tls-dir-into-individual-files-so-that-docker-k8s-secrets-management-can-be-plugged-in/8786 "2019-08-15T14:06:36Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![diggy](https://yyz1.discourse-cdn.com/flex007/user_avatar/discuss.dgraph.io/diggy/32/3666_2.png) [@diggy](https://discuss.dgraph.io/u/diggy)\
**Post date:** [August 15, 2019, 2:06pm UTC](https://discuss.dgraph.io/t/split-out-tls-dir-into-individual-files-so-that-docker-k8s-secrets-management-can-be-plugged-in/8786/1 "2019-08-15T14:06:36Z")

</div>

**Moved from GitHub [dgraph/3820](https://github.com/dgraph-io/dgraph/issues/3820)**

_Posted by_ [sandys](https://github.com/sandys):

dgraph alpha has an option parameter “tls\_dir” to take in TLS certificates created in a directory.

Usually this has CA certificates, node and user keys.

The industry recommended way to do secret management in Docker is through Docker Secrets : [Manage sensitive data with Docker secrets | Docker Documentation](https://docs.docker.com/engine/swarm/secrets/)

There are equivalents in Kubernetes as well as external tools like Hashicorp Vault. Most of them work at the file level and not at the directory level.

I request for additional parameters like “tls\_ca\_cert”, “tls\_node\_key”, etc so that these individual files can be passed in using secret management

---

<div class="post-metadata">

**Author:** ![aman-bansal](https://yyz1.discourse-cdn.com/flex007/user_avatar/discuss.dgraph.io/aman-bansal/32/4475_2.png) [@aman-bansal](https://discuss.dgraph.io/u/aman-bansal)\
**Post date:** [November 10, 2020, 11:24am UTC](https://discuss.dgraph.io/t/split-out-tls-dir-into-individual-files-so-that-docker-k8s-secrets-management-can-be-plugged-in/8786/2 "2020-11-10T11:24:48Z")

</div>

This has been merged in master with [feat(tls): splitting tls\_dir + making health point available on HTTP by aman-bansal · Pull Request #6821 · dgraph-io/dgraph · GitHub](https://github.com/dgraph-io/dgraph/pull/6821). This will be available from 20.11 release
