1diff --git a/server/config/config.go b/server/config/config.go
2index 649ff70929e8ad6edac925d33258944ecb5b5ecf..6a3d5610cdb2182c93d02607ea9f67d98a81cc10 100644
3--- a/server/config/config.go
4+++ b/server/config/config.go
5@@ -51,6 +51,12 @@ type HTTPConfig struct {
6 // ListenAddr is the address on which the HTTP server will listen.
7 ListenAddr string `env:"LISTEN_ADDR" yaml:"listen_addr"`
8 9+ // TLSKeyPath is the path to the TLS private key.
10+ TLSKeyPath string `env:"TLS_KEY_PATH" yaml:"tls_key_path"`
11+
12+ // TLSCertPath is the path to the TLS certificate.
13+ TLSCertPath string `env:"TLS_CERT_PATH" yaml:"tls_cert_path"`
14+
15 // PublicURL is the public URL of the HTTP server.
16 PublicURL string `env:"PUBLIC_URL" yaml:"public_url"`
17 }
18diff --git a/server/config/file.go b/server/config/file.go
19index 00baa13154babf334df97282b6bbbf121e8f5644..932b8063700bb17ceb19649583530f02c596ae4c 100644
20--- a/server/config/file.go
21+++ b/server/config/file.go
22@@ -54,6 +54,12 @@ http:
23 # The address on which the HTTP server will listen.
24 listen_addr: "{{ .HTTP.ListenAddr }}"
2526+ # The relative path to the TLS private key.
27+ tls_key_path: "{{ .HTTP.TLSKeyPath }}"
28+
29+ # The relative path to the TLS certificate.
30+ tls_cert_path: "{{ .HTTP.TLSCertPath }}"
31+
32 # The public URL of the HTTP server.
33 # This is the address will be used to clone repositories.
34 public_url: "{{ .HTTP.PublicURL }}"
35diff --git a/server/http.go b/server/http.go
36index f36e041cf0e6aade521aab563c8897811280b3de..2ac99b5e497db0ceb1d954a0a23801caa7d5f733 100644
37--- a/server/http.go
38+++ b/server/http.go
39@@ -105,6 +105,9 @@ func (s *HTTPServer) Close() error {
4041 // ListenAndServe starts the HTTP server.
42 func (s *HTTPServer) ListenAndServe() error {
43+ if s.cfg.HTTP.TLSKeyPath != "" && s.cfg.HTTP.TLSCertPath != "" {
44+ return s.server.ListenAndServeTLS(s.cfg.HTTP.TLSCertPath, s.cfg.HTTP.TLSKeyPath)
45+ }
46 return s.server.ListenAndServe()
47 }
48