Domains
A hostname that routes to your app, with a TLS certificate issued and renewed for you.
On this page
What it is
A domain is the public address of an app. You give klickops a hostname and the app it belongs to, and klickops routes traffic to it, issues a certificate, and renews that certificate before it expires. There is nothing to configure in the container.
A domain usually serves one app. That is deliberate: a hostname is a facet of the app it points at, so you manage it from the app's Domains tab rather than from a separate list of routing rules. When several apps share one hostname through different paths, you edit it on the project's Domains page.
When you'd use it
- Your app should be reachable from a browser.
- You want HTTPS without touching a certificate file.
- You are moving a hostname from another provider and want the certificate to exist before you cut the DNS over.
Reaching another workload inside the same project needs no domain. Apps in a project reach each other by name over the internal network, and giving an internal service a public hostname just widens its exposure.
Get a hostname
There are two ways, and the first one needs no DNS at all.
A klickops subdomain. Choose Add domain, keep klickops subdomain selected, and klickops assigns one under its own wildcard, resolving immediately with a certificate already valid. On the hosted service the label is a random slug rather than your project's name, so nothing about your tenancy ends up in public DNS. Self-hosted installs use the readable app.project.your-base-domain form instead.
Your own domain. Add the hostname, then point it at klickops.
- Open the app, go to Domains, and add the hostname you own. On the hosted service your organization verifies the domain first, see below.
- klickops shows the
CNAMErecord to create. For a root domain likeacme.ch, use your provider's ALIAS or ANAME record, or CNAME flattening, with the same target. - Create that record with your DNS provider. A wildcard
CNAMEcovers every subdomain at once if you plan to add more. - Wait for the check to go green. klickops polls DNS and issues the certificate as soon as the record resolves, usually within a minute or two.
Add the domain before you move production traffic. The certificate is issued once DNS resolves, so cutting over after the check goes green means no window where visitors see a warning.
Verify your domain first
On the hosted service an organization proves once that it owns a domain, and every project in it can then use that domain and all of its subdomains. Nobody else can attach a hostname under it, even one you left pointing at klickops.
- Open Domains in your organization's sidebar and choose Verify a domain. Owners and admins can; everyone else sees the list.
- Add the
TXTrecord it shows at your DNS provider: the name_klickops-challenge.<your domain>and the valueklickops-verify=…. - Choose Check again. Once the record is found the domain shows Verified, and you may remove the record again.
Verify the domain you registered (acme.ch), not each hostname: shop.acme.ch and www.acme.ch are covered with it. Domains that worked before verification existed keep working. Self-hosted installs skip this step.
Settings reference
| Setting | Default | What it does |
|---|---|---|
| Hostname | none | The name visitors type. One domain resource per hostname. |
| App | required | Which app receives the traffic, and on which port. |
| HTTPS | on | Issues and renews a certificate. Leave it on. |
| Always use HTTPS | on | Sends plaintext requests to the secure address. |
| Require klickops login | off | Only members of the project get through; everyone else is sent to sign in. An internal tool needs no auth code of its own. |
| Routes | / | Route only a path prefix to an app, when several apps share one hostname. |
Limits and gotchas
- One hostname, one domain resource. The controller in front does not merge two definitions of the same host, so a duplicate hostname is rejected rather than silently half-applied.
- Certificates need public DNS. The issuer proves you control the name over the internet. A hostname that only resolves on your internal network cannot get a public certificate.
- Apex domains need an alias record. Most DNS providers cannot
CNAMEan apex. Use their alias record type, or pointwwwat klickops and redirect the apex to it. - A domain moves with its DNS. If another organization later proves control of a domain yours verified, it moves to them and shows as verified elsewhere on your list. Your running domains keep serving, but changing one needs the domain verified again.
- Your own domains depend on your plan. The free plan serves apps on their klickops subdomain only; paid plans include a set number of custom domains per organization.
- No wildcard certificates on the hosted service. Every address gets its own certificate. To use one you already have, upload it to the project and pick it as the domain's Certificate.
- Removing a domain is immediate. Traffic stops the moment it is deleted, so move DNS first if the name is live.
Related
- Apps is what a domain points at.
- A domain gives the app an address; the project firewall controls who may use it.