ROUTING
Publish only after DNS, TLS, and runtime agree.
Midnight stores route intent and publishes Traefik configuration on the trusted host. Generated and custom domains make setup approachable, while explicit route evidence keeps internal state distinct from Internet reachability.
On this page
FAST PATH
Create the service-managed hostname.
midnight domain add
midnight domain list
midnight domain get dom_exampleThe generated-domain command uses the project, environment, and service in .midnight/project.json. It converges one service-managed hostname rather than accepting an arbitrary host or path.
OWNED HOSTNAME
Prove control before activating a custom domain.
- 1
Add the hostname
Create the custom-domain intent for the exact service and environment in the console or CLI.
- 2
Publish the TXT challenge
Copy the exact DNS TXT name and value Midnight returns into the authoritative zone.
- 3
Wait for verification
DNS caches and provider propagation take time. Do not repeatedly delete and recreate the request while it propagates.
- 4
Point application DNS
After ownership verification, add the application record required by your installation and confirm it resolves to the ingress host.
- 5
Verify TLS and reachability
Confirm the certificate matches the hostname, the route is applied, the backend is healthy, and an external request succeeds.
midnight domain custom add --tls app.example.com
# Publish the TXT name/value returned by add, then wait for DNS propagation.
midnight domain custom verify --expected-version 1 dom_example
midnight domain custom list
# Deletion also requires the current desired-state version.
midnight domain custom delete --expected-version 2 dom_exampleEVIDENCE
Read every layer of route state.
- Desired domain
- The hostname, service/environment target, and public-route intent accepted by the control plane.
- Route apply state
- Whether the worker published the route group to the configured Traefik directory.
- Backend health
- The runtime and trusted host-header probe agree that the target is available.
- Certificate evidence
- The durable certificate reference and issuance state; private key material never belongs in shared evidence.
- External probe
- A request from outside the VM proves public DNS, firewall, ingress, TLS, and backend work together.
dig +short app.example.com
curl --fail-with-body --show-error --include https://app.example.com/
openssl s_client -connect app.example.com:443 -servername app.example.com </dev/nullSERVICE-TO-SERVICE
Use the project/environment bridge for private traffic.
Services in the same project and environment share a Docker bridge managed on the single trusted host. Keep databases and internal APIs off public domains when only sibling services need them.