I am trying to set up Loki in simple scalable mode with TLS enabled, as each single service is included in Read, Write or Backend, so when I create a self-signed cert, what the CN I should use? For example, frontend.

I don’t have experience setting up Loki with end-to-end encryption, but I’d recommend you to simply use self-signed wildcard cert so you don’t have to worry about CN for each component.

Thanks Tony, that’d be a great idea but this is not supported in our production system, I would like to have a try though.