← Back to list
01Issue
BugShippedSwamp CLIPublic
Assigneeshammz
Relationships
#2893 serve: relative tls cert-file/key-file and --config resolve against the working directory, not the repository
Opened by hammz · 10/1/2026· Shipped 10/6/2026
Summary
Same class of bug as swamp-club#2812 (fixed for grants-dir and grants-file). Several other serve paths are still read as given, so a relative value resolves against the process working directory instead of the repository directory:
- tls cert-file and key-file (flag, SWAMP_SERVE_CERT_FILE / SWAMP_SERVE_KEY_FILE, or tls: in .swamp/serve.yaml): src/cli/commands/serve.ts reads them with Deno.readTextFile(certFile) around line 2380.
- --config on foreground swamp serve and swamp serve check-config: loadServeConfig(options.config, repoDir) reads the path as given (serve.ts around lines 2344 and 1928), whereas swamp serve daemon enable resolves a relative --config against the repository (validateServeDaemonArgs, serve.ts around line 1049).
Steps to reproduce
- Put tls: with cert-file: certs/server.pem and key-file: certs/server.key in REPO/.swamp/serve.yaml, with the files under REPO/certs.
- Run swamp serve --repo-dir REPO from a different directory.
- Serve fails to read the certificate, because the path resolved under the working directory.
Expected
Relative serve paths resolve against the repository directory, matching grants-dir/grants-file after #2812, the audit WAL directory, and daemon enable's handling of --config. Document the rule in the help text and serve-flags manual page.
02Bog Flow
Shipped
Click a lifecycle step above to view its details.
03Sludge Pulse
Sign in to post a ripple.