Cloudflare.MtlsCertificate reference
Source:
src/Cloudflare/MtlsCertificate/Fetch.ts
Send requests from an Effect Worker that present a leaf
MtlsCertificate to the origin.
Fetch is a single identifier that is the binding’s Context tag, its type,
and the callable: yield* Cloudflare.MtlsCertificate.Fetch(cert) binds the
certificate to the Worker as an mtls_certificate binding and returns a
function from HttpClientRequest to HttpClientResponse. Every request it
sends goes out over TLS presenting the certificate, so origins that require
client authentication (mTLS) accept it.
Bind a leaf certificate uploaded with its private key (ca: false). Provide
FetchBinding on the Worker’s Effect to resolve the native binding at
request time. Async Workers get the same binding by passing the certificate
in env instead, where it is typed as a Fetcher.
Fetch: Calling an mTLS origin
Section titled “Fetch: Calling an mTLS origin”import * as Cloudflare from "alchemy/Cloudflare";import * as Config from "effect/Config";import * as Effect from "effect/Effect";import * as HttpClientRequest from "effect/http/HttpClientRequest";import * as HttpServerResponse from "effect/http/HttpServerResponse";
export const OriginCert = Effect.gen(function* () { return yield* Cloudflare.MtlsCertificate.MtlsCertificate("OriginCert", { ca: false, certificates: leafPem, privateKey: yield* Config.Redacted("ORIGIN_CLIENT_KEY"), });});
export default class Api extends Cloudflare.Worker<Api>()( "Api", { main: import.meta.url }, Effect.gen(function* () { const fetchOrigin = yield* Cloudflare.MtlsCertificate.Fetch(yield* OriginCert); return { fetch: Effect.gen(function* () { const response = yield* fetchOrigin( HttpClientRequest.get("https://origin.example.com/orders"), ); return HttpServerResponse.text(yield* response.text); }), }; }).pipe(Effect.provide(Cloudflare.MtlsCertificate.FetchBinding)),) {}Fetch: Requests with bodies
Section titled “Fetch: Requests with bodies”const response = yield* fetchOrigin( HttpClientRequest.post("https://origin.example.com/orders").pipe( HttpClientRequest.bodyJsonUnsafe({ sku: "abc", quantity: 1 }), ),);MtlsCertificate
Section titled “MtlsCertificate”Source:
src/Cloudflare/MtlsCertificate/MtlsCertificate.ts
An account-level Cloudflare mTLS certificate.
Uploads a certificate to the account-level mTLS certificate store. Upload a
CA certificate (ca: true) to validate client certificates (referenced by
certificate-authority hostname associations and Hyperdrive
caCertificateId), or a leaf certificate plus private key (ca: false)
that Cloudflare presents to your origin (referenced by Worker
mtls_certificate bindings and Hyperdrive mtlsCertificateId).
Certificates are immutable: there is no update API, so changing any property triggers a replacement.
MtlsCertificate: Uploading Certificates
Section titled “MtlsCertificate: Uploading Certificates”CA certificate
const ca = yield* Cloudflare.MtlsCertificate.MtlsCertificate("client-ca", { ca: true, certificates: caPem,});Leaf certificate with private key
const cert = yield* Cloudflare.MtlsCertificate.MtlsCertificate("origin-client-cert", { ca: false, certificates: leafPem, privateKey: yield* Config.Redacted("ORIGIN_CLIENT_KEY"),});Named certificate
const ca = yield* Cloudflare.MtlsCertificate.MtlsCertificate("client-ca", { name: "my-client-ca", ca: true, certificates: caPem,});MtlsCertificate: Referencing from Hyperdrive
Section titled “MtlsCertificate: Referencing from Hyperdrive”const ca = yield* Cloudflare.MtlsCertificate.MtlsCertificate("db-ca", { ca: true, certificates: caPem,});
const hd = yield* Cloudflare.Hyperdrive.Connection("my-db", { origin: { ... }, mtls: { caCertificateId: ca.mtlsCertificateId, sslmode: "verify-full", },});MtlsCertificate: Binding to a Worker
Section titled “MtlsCertificate: Binding to a Worker”Present a leaf certificate on subrequests
const cert = yield* Cloudflare.MtlsCertificate.MtlsCertificate("origin-client-cert", { ca: false, certificates: leafPem, privateKey: yield* Config.Redacted("ORIGIN_CLIENT_KEY"),});
// `env.ORIGIN_CERT` is a `Fetcher`: `env.ORIGIN_CERT.fetch(url)` presents// the certificate to the origin.const worker = yield* Cloudflare.Worker("Worker", { main: "./src/worker.ts", env: { ORIGIN_CERT: cert },});Present a leaf certificate from an Effect Worker
// Inside the Worker's Effect; provide `Cloudflare.MtlsCertificate.FetchBinding`.const fetchOrigin = yield* Cloudflare.MtlsCertificate.Fetch(cert);const response = yield* fetchOrigin( HttpClientRequest.get("https://origin.example.com/"),);