Help & Support

Certificates

Choose how browsers trust HTTPS on the instance.

The Security step in the wizard (and the Certificate tab in admin later) is where you pick a certificate. You can change this after setup without relaunching.

Self-signed is the default and works on any network, including private subnets.

Options

  • Self-signed — always works. The browser warns once. Fine for a private VPC or a first test.
  • Let’s Encrypt with a domain — a trusted certificate for about 90 days, renewed automatically. The hostname must already point at this instance.
  • Let’s Encrypt for the public IP — no domain needed. These certificates last about six days and renew on their own. Use an Elastic IP if you stop and start the instance.
  • Your own certificate — put the files on the instance over SSH, then point the wizard at those paths and validate.

Deep Learning Notebook can also turn TLS off if you terminate HTTPS on a load balancer in front of it. Other AMIs keep HTTPS on.

Let’s Encrypt needs a public IPv4. Private-only instances stay on self-signed or your own cert.

After setup

Admin → Certificate shows the current cert, lets you renew, and lets you download it so you can trust it locally.

Change or renew the certificate from admin without restarting the instance.

Stuck on the browser warning? See first boot.