MidnightDocumentation

ROUTING

Publish only after DNS, TLS, and runtime agree.

Midnight stores route intent and publishes Traefik configuration on the trusted host. Generated and custom domains make setup approachable, while explicit route evidence keeps internal state distinct from Internet reachability.

TraefikHTTP/SDNS challengePrivate bridge
On this page

FAST PATH

Create the service-managed hostname.

Linked servicebash
midnight domain add
midnight domain list
midnight domain get dom_example

The generated-domain command uses the project, environment, and service in .midnight/project.json. It converges one service-managed hostname rather than accepting an arbitrary host or path.

OWNED HOSTNAME

Prove control before activating a custom domain.

  1. 1

    Add the hostname

    Create the custom-domain intent for the exact service and environment in the console or CLI.

  2. 2

    Publish the TXT challenge

    Copy the exact DNS TXT name and value Midnight returns into the authoritative zone.

  3. 3

    Wait for verification

    DNS caches and provider propagation take time. Do not repeatedly delete and recreate the request while it propagates.

  4. 4

    Point application DNS

    After ownership verification, add the application record required by your installation and confirm it resolves to the ingress host.

  5. 5

    Verify TLS and reachability

    Confirm the certificate matches the hostname, the route is applied, the backend is healthy, and an external request succeeds.

Custom-domain lifecyclebash
midnight domain custom add --tls app.example.com

# Publish the TXT name/value returned by add, then wait for DNS propagation.
midnight domain custom verify --expected-version 1 dom_example
midnight domain custom list

# Deletion also requires the current desired-state version.
midnight domain custom delete --expected-version 2 dom_example

EVIDENCE

Read every layer of route state.

Desired domain
The hostname, service/environment target, and public-route intent accepted by the control plane.
Route apply state
Whether the worker published the route group to the configured Traefik directory.
Backend health
The runtime and trusted host-header probe agree that the target is available.
Certificate evidence
The durable certificate reference and issuance state; private key material never belongs in shared evidence.
External probe
A request from outside the VM proves public DNS, firewall, ingress, TLS, and backend work together.
External checksbash
dig +short app.example.com
curl --fail-with-body --show-error --include https://app.example.com/
openssl s_client -connect app.example.com:443 -servername app.example.com </dev/null

SERVICE-TO-SERVICE

Use the project/environment bridge for private traffic.

Services in the same project and environment share a Docker bridge managed on the single trusted host. Keep databases and internal APIs off public domains when only sibling services need them.