Skip to content

Cloudflare.MtlsCertificate reference

Source: src/Cloudflare/MtlsCertificate/Fetch.ts

Send requests from an Effect Worker that present a leaf MtlsCertificate to the origin.

Fetch is a single identifier that is the binding’s Context tag, its type, and the callable: yield* Cloudflare.MtlsCertificate.Fetch(cert) binds the certificate to the Worker as an mtls_certificate binding and returns a function from HttpClientRequest to HttpClientResponse. Every request it sends goes out over TLS presenting the certificate, so origins that require client authentication (mTLS) accept it.

Bind a leaf certificate uploaded with its private key (ca: false). Provide FetchBinding on the Worker’s Effect to resolve the native binding at request time. Async Workers get the same binding by passing the certificate in env instead, where it is typed as a Fetcher.

import * as Cloudflare from "alchemy/Cloudflare";
import * as Config from "effect/Config";
import * as Effect from "effect/Effect";
import * as HttpClientRequest from "effect/http/HttpClientRequest";
import * as HttpServerResponse from "effect/http/HttpServerResponse";
export const OriginCert = Effect.gen(function* () {
return yield* Cloudflare.MtlsCertificate.MtlsCertificate("OriginCert", {
ca: false,
certificates: leafPem,
privateKey: yield* Config.Redacted("ORIGIN_CLIENT_KEY"),
});
});
export default class Api extends Cloudflare.Worker<Api>()(
"Api",
{ main: import.meta.url },
Effect.gen(function* () {
const fetchOrigin = yield* Cloudflare.MtlsCertificate.Fetch(yield* OriginCert);
return {
fetch: Effect.gen(function* () {
const response = yield* fetchOrigin(
HttpClientRequest.get("https://origin.example.com/orders"),
);
return HttpServerResponse.text(yield* response.text);
}),
};
}).pipe(Effect.provide(Cloudflare.MtlsCertificate.FetchBinding)),
) {}
const response = yield* fetchOrigin(
HttpClientRequest.post("https://origin.example.com/orders").pipe(
HttpClientRequest.bodyJsonUnsafe({ sku: "abc", quantity: 1 }),
),
);

Source: src/Cloudflare/MtlsCertificate/MtlsCertificate.ts

An account-level Cloudflare mTLS certificate.

Uploads a certificate to the account-level mTLS certificate store. Upload a CA certificate (ca: true) to validate client certificates (referenced by certificate-authority hostname associations and Hyperdrive caCertificateId), or a leaf certificate plus private key (ca: false) that Cloudflare presents to your origin (referenced by Worker mtls_certificate bindings and Hyperdrive mtlsCertificateId).

Certificates are immutable: there is no update API, so changing any property triggers a replacement.

CA certificate

const ca = yield* Cloudflare.MtlsCertificate.MtlsCertificate("client-ca", {
ca: true,
certificates: caPem,
});

Leaf certificate with private key

const cert = yield* Cloudflare.MtlsCertificate.MtlsCertificate("origin-client-cert", {
ca: false,
certificates: leafPem,
privateKey: yield* Config.Redacted("ORIGIN_CLIENT_KEY"),
});

Named certificate

const ca = yield* Cloudflare.MtlsCertificate.MtlsCertificate("client-ca", {
name: "my-client-ca",
ca: true,
certificates: caPem,
});

MtlsCertificate: Referencing from Hyperdrive

Section titled “MtlsCertificate: Referencing from Hyperdrive”
const ca = yield* Cloudflare.MtlsCertificate.MtlsCertificate("db-ca", {
ca: true,
certificates: caPem,
});
const hd = yield* Cloudflare.Hyperdrive.Connection("my-db", {
origin: { ... },
mtls: {
caCertificateId: ca.mtlsCertificateId,
sslmode: "verify-full",
},
});

Present a leaf certificate on subrequests

const cert = yield* Cloudflare.MtlsCertificate.MtlsCertificate("origin-client-cert", {
ca: false,
certificates: leafPem,
privateKey: yield* Config.Redacted("ORIGIN_CLIENT_KEY"),
});
// `env.ORIGIN_CERT` is a `Fetcher`: `env.ORIGIN_CERT.fetch(url)` presents
// the certificate to the origin.
const worker = yield* Cloudflare.Worker("Worker", {
main: "./src/worker.ts",
env: { ORIGIN_CERT: cert },
});

Present a leaf certificate from an Effect Worker

// Inside the Worker's Effect; provide `Cloudflare.MtlsCertificate.FetchBinding`.
const fetchOrigin = yield* Cloudflare.MtlsCertificate.Fetch(cert);
const response = yield* fetchOrigin(
HttpClientRequest.get("https://origin.example.com/"),
);