Domains
A domain is healthy only when backend attachment, route attachment, DNS, TLS, and HTTP reachability agree.
backend ownership -> route attachment -> DNS -> TLS -> HTTPCurrent user workflow
Section titled “Current user workflow”1ctl deploy --domain api.example.com1ctl domains add api.example.com --app api1ctl domains check api.example.com --probe1ctl domains setup api.example.com1ctl domains remove api.example.com --app api --yesResource boundaries
Section titled “Resource boundaries”The CLI intentionally separates three things that can share the same name:
| Resource | Commands | What it controls |
|---|---|---|
| Registration search or purchase | domains search, available, purchase, purchase-status |
Registrar availability and checkout intent. |
| Managed DNS zone | domains managed, domains dns |
Nameserver delegation and records for a zone owned or delegated to SatuSky DNS. |
| App hostname attachment | domains add, list, check, setup, delete |
A hostname routed to one app Service in the current organization. |
Creating or changing a managed DNS record does not attach a hostname to an app. Likewise, attaching a hostname does not transfer its registration or DNS zone. All managed-zone and registration operations are scoped to the authenticated user and selected organization.
An external custom hostname is normalized as a hostname (not a URL); wildcard hostnames are currently unsupported because custom-domain TLS uses HTTP-01 validation.
Readiness dimensions
Section titled “Readiness dimensions”| Dimension | Meaning |
|---|---|
| Backend attachment | Domain belongs to the intended app. |
| Route attachment | Kubernetes routing points the hostname at the app Service. |
| DNS | The authoritative DNS condition is verified, which proves public DNS resolves to the expected target. |
| TLS | Certificate is issued and served. |
| HTTP | Optional probe reaches the app. |
Workload readiness and domain readiness are different. A pod can be healthy while DNS or TLS is still pending.
Operator configuration
Section titled “Operator configuration”The control plane’s default-hostname feature requires explicit production
values for DEFAULT_HOSTNAME_DOMAIN and DEFAULT_HOSTNAME_EXPECTED_TARGET.
Non-production environments use explicit localhost defaults only; they must
not become an implicit production fallback. These are control-plane environment
variables, not satusky.toml or application runtime configuration.