Domains & TLS — NuPaaS Docs
Deploy & projects

Domains & TLS

A custom domain is attached to a project, and optionally to one service inside it. Attaching is three steps: add the hostname, point DNS at the target NuPaaS gives you, then verify. TLS is issued for you once verification succeeds.

Adding a domain

Add domains from /orgs/<org>/projects/<project>/domains, or from the CLI:

Manage domains
platform domains list   --project <projectId>
platform domains add    --project <projectId> --hostname app.example.com
platform domains verify --id <domainId>
platform domains delete --id <domainId>

Hostnames are unique across the whole platform, not just within your organization. Adding one that is already registered fails.

Pointing DNS at the platform

After the domain is added, the panel shows the exact record to create. Which record you get depends on the hostname:

ParameterTypeDescription
SubdomainCNAMEPoint a CNAME at the target shown on the domain row. This is the usual case for app.example.com.
Apex domainACNAMEs are not valid at an apex. Create A records pointing at the IPs shown; when more than one is listed, create all of them for availability.
Apex, provider with flatteningALIAS / ANAMECloudflare, Route 53 and similar providers can flatten a CNAME at the apex. Use that instead of A records if your provider offers it.

If NuPaaS holds DNS credentials for the zone, it creates the record itself and the panel says so — there is no manual DNS step in that case, and you can go straight to verification.

Verification

Verification checks that the record you created actually resolves to the expected target. It is not automatic — press Verify on the domain row, or run platform domains verify --id <domainId>, once you believe DNS has propagated.

A failed check reports which way it failed: DNS not resolving to the target at all, or an A record resolving to the wrong IP. Both are retryable — fix the record and verify again.

TLS certificates

You do not request a certificate. Once a domain verifies, it moves to cert_provisioning and the platform issues a certificate for it. A background process polls certificate readiness roughly every 30 seconds and moves the domain to active_tls only after the certificate has actually been issued.

Status reference

ParameterTypeDescription
pendingstatusAdded, DNS record not yet confirmed.
dns_propagatingstatusThe record was seen but has not fully propagated. Verify again shortly.
dns_misconfiguredstatusThe record resolves, but not to the expected target.
cert_provisioningstatusDNS verified; TLS certificate is being issued.
active_tlsstatusLive, with a certificate issued.
cert_failedstatusCertificate issuance failed.
expiredstatusThe certificate lapsed.
failedstatusSetup failed. Check DNS records and verify again.

Reserved hostnames

A set of platform hostnames — the platform apex and its infrastructure subdomains — cannot be claimed by a tenant organization. Attempting to add one is refused as a permission error, not as an internal failure, so it is clear the request was understood and denied rather than broken.

Removing a domain

Removing a domain detaches it from the project. The CLI prompts for confirmation first.

platform domains delete --id <domainId>

Delete the DNS record at your provider separately — removing the domain here does not remove a record you created by hand.