Domains & TLS
A custom domain is attached to a project, and optionally to one service inside it. Attaching is three steps: add the hostname, point DNS at the target NuPaaS gives you, then verify. TLS is issued for you once verification succeeds.
Adding a domain
Add domains from /orgs/<org>/projects/<project>/domains, or from the CLI:
platform domains list --project <projectId>
platform domains add --project <projectId> --hostname app.example.com
platform domains verify --id <domainId>
platform domains delete --id <domainId>Hostnames are unique across the whole platform, not just within your organization. Adding one that is already registered fails.
Pointing DNS at the platform
After the domain is added, the panel shows the exact record to create. Which record you get depends on the hostname:
| Parameter | Type | Description |
|---|---|---|
| Subdomain | CNAME | Point a CNAME at the target shown on the domain row. This is the usual case for app.example.com. |
| Apex domain | A | CNAMEs are not valid at an apex. Create A records pointing at the IPs shown; when more than one is listed, create all of them for availability. |
| Apex, provider with flattening | ALIAS / ANAME | Cloudflare, Route 53 and similar providers can flatten a CNAME at the apex. Use that instead of A records if your provider offers it. |
If NuPaaS holds DNS credentials for the zone, it creates the record itself and the panel says so — there is no manual DNS step in that case, and you can go straight to verification.
Verification
Verification checks that the record you created actually resolves to the expected target. It is not automatic — press Verify on the domain row, or run platform domains verify --id <domainId>, once you believe DNS has propagated.
A failed check reports which way it failed: DNS not resolving to the target at all, or an A record resolving to the wrong IP. Both are retryable — fix the record and verify again.
TLS certificates
You do not request a certificate. Once a domain verifies, it moves to cert_provisioning and the platform issues a certificate for it. A background process polls certificate readiness roughly every 30 seconds and moves the domain to active_tls only after the certificate has actually been issued.
Status reference
| Parameter | Type | Description |
|---|---|---|
| pending | status | Added, DNS record not yet confirmed. |
| dns_propagating | status | The record was seen but has not fully propagated. Verify again shortly. |
| dns_misconfigured | status | The record resolves, but not to the expected target. |
| cert_provisioning | status | DNS verified; TLS certificate is being issued. |
| active_tls | status | Live, with a certificate issued. |
| cert_failed | status | Certificate issuance failed. |
| expired | status | The certificate lapsed. |
| failed | status | Setup failed. Check DNS records and verify again. |
Reserved hostnames
A set of platform hostnames — the platform apex and its infrastructure subdomains — cannot be claimed by a tenant organization. Attempting to add one is refused as a permission error, not as an internal failure, so it is clear the request was understood and denied rather than broken.
Removing a domain
Removing a domain detaches it from the project. The CLI prompts for confirmation first.
platform domains delete --id <domainId>Delete the DNS record at your provider separately — removing the domain here does not remove a record you created by hand.