Configuration
Custom domains
Serve a project's production deployment from your own domain, with a certificate issued automatically.
Add a domain
Cloud → Domains → Add domain (or the project's Settings → Domains), then enter the hostname (for example www.example.com or example.com) and choose the project. You need domains:write.
- A hostname belongs to one project at a time, across all organizations.
- Hostnames under
gov.vinbelong to the platform and can't be added.
Create the DNS record
Cloud then shows the records to create at your DNS provider, named relative to your zone, with a copy button for each. Copy all copies them as a zone file snippet and Download zone file saves it, for DNS hosts that import zone files (Cloudflare does):
| Domain | Records |
|---|---|
A subdomain, like www.example.com | CNAME www → cname.deployments.dev.gov.vin |
The apex, like example.com | CNAME @ → cname.deployments.dev.gov.vin, and TXT _cf-challenge → the edge endpoint shown in Cloud |
cname.deployments.dev.gov.vin is the same for every domain. Most providers flatten a CNAME at the apex (or call it ALIAS or ANAME); the TXT record shows the edge the apex is yours.
Set the record to DNS only (grey cloud). A proxied record points at Cloudflare instead of the platform's edge.
When the zone is on Cloudflare, Cloud offers two ways to add the records:
- Open Cloudflare DNS opens Cloudflare's DNS records page (Cloudflare asks which account and zone); add the records there with the proxy off.
- Connect Cloudflare gives the organization access to your Cloudflare zones; after that, Add record in Cloudflare creates or updates the records for you, as DNS only, and checks the domain right away. The button appears for domains in zones you shared.
Connect Cloudflare
Connecting needs domains:write, from a domain's DNS records or Cloud → Settings → Integrations:
- Continue to Cloudflare signs in at Cloudflare, where you choose the zones to share. The platform keeps the grant, refreshes it as needed and revokes it at Cloudflare when you disconnect or connect again. If the grant expires without a way to refresh it, Cloud shows Expired; reconnect to keep adding records.
- API token is the alternative: create one in Cloudflare under My Profile → API Tokens → Create Token → Edit zone DNS, limited to the zones you'll use, and paste it.
Either way the credential is encrypted, never shown again, and used only for records you ask for. Cloudflare sign-in is available only where the platform has a Cloudflare app configured; otherwise Cloud offers the API token. Disconnect removes the credential.
Status
| Status | Shown as | Means |
|---|---|---|
pending | Waiting for DNS | The record isn't there yet, or points somewhere else. Cloud shows what DNS currently returns. |
verifying | Issuing certificate | DNS points at the edge and the certificate is being issued, which usually takes a few minutes. |
active | Active | Served over HTTPS from the project's production deployment. |
error | Needs attention | The domain is attached to another CloudFront distribution (remove it there), or the certificate couldn't be issued (check the record). |
Nothing needs to be done between pending and active except creating the record.
Checks
The platform moves domains along in the background:
| Domain added | Checked |
|---|---|
| Less than a day ago | Every 5 minutes |
| Less than a week ago | Every hour |
| Less than 30 days ago | Every 6 hours |
| Earlier | Only when you check |
While the Domains page is open, it checks waiting domains every 15 seconds (for up to 30 minutes), and Check now (the refresh icon) checks one immediately. Checks ask your zone's own nameservers, so a record you just created counts without waiting out DNS caches.
Domains that need attention aren't checked in the background: fix the cause, then choose Check now. After a certificate error, that check starts over with a new certificate.
Which deployment it serves
A custom domain serves the project's current production deployment, and follows it on every production deploy, promote and rollback. A domain added before the project has a production deployment starts serving when the first one is ready.
Redirects and moves
From a domain's menu (needs domains:write):
- Redirect to another domain sends every request to another domain of the same project with a
308 Permanent Redirect, keeping the path and query string. The destination must serve the project itself, not redirect too. Change redirect changes or removes it. - Move to another project serves another project of the organization instead. A moved domain stops redirecting.
Both take effect at the edge right away. A domain that another domain redirects to can't be moved or removed until that redirect changes.
Remove a domain
Remove in the domain's menu (needs domains:write) removes the domain's route and certificate right away. Remove the DNS record at your provider afterwards.
Planned
- Moving a domain that already serves traffic elsewhere without downtime. Coming soon