Skip to main content
← Back to list
01Issue
BugShippedSwamp CLIPublic
Assigneeshammz

Relationships

#2893 serve: relative tls cert-file/key-file and --config resolve against the working directory, not the repository

Opened by hammz · 10/1/2026· Shipped 10/6/2026

Summary

Same class of bug as swamp-club#2812 (fixed for grants-dir and grants-file). Several other serve paths are still read as given, so a relative value resolves against the process working directory instead of the repository directory:

  • tls cert-file and key-file (flag, SWAMP_SERVE_CERT_FILE / SWAMP_SERVE_KEY_FILE, or tls: in .swamp/serve.yaml): src/cli/commands/serve.ts reads them with Deno.readTextFile(certFile) around line 2380.
  • --config on foreground swamp serve and swamp serve check-config: loadServeConfig(options.config, repoDir) reads the path as given (serve.ts around lines 2344 and 1928), whereas swamp serve daemon enable resolves a relative --config against the repository (validateServeDaemonArgs, serve.ts around line 1049).

Steps to reproduce

  1. Put tls: with cert-file: certs/server.pem and key-file: certs/server.key in REPO/.swamp/serve.yaml, with the files under REPO/certs.
  2. Run swamp serve --repo-dir REPO from a different directory.
  3. Serve fails to read the certificate, because the path resolved under the working directory.

Expected

Relative serve paths resolve against the repository directory, matching grants-dir/grants-file after #2812, the audit WAL directory, and daemon enable's handling of --config. Document the rule in the help text and serve-flags manual page.

02Bog Flow
✓OPEN✓TRIAGED✓IN PROGRESS✓SHIPPED+ 1 MOREASSIGNED+ 5 MOREREVIEW+ 10 MOREPR_MERGED+ 2 MORESESSION_SUMMARIZED

Shipped

10/6/2026, 3:34:44 PM

Click a lifecycle step above to view its details.

03Sludge Pulse
hammz assigned hammz10/6/2026, 3:07:25 PM

Sign in to post a ripple.