Skip to content

Domains

A domain is healthy only when backend attachment, route attachment, DNS, TLS, and HTTP reachability agree.

backend ownership -> route attachment -> DNS -> TLS -> HTTP
Terminal window
1ctl deploy --domain api.example.com
1ctl domains add api.example.com --app api
1ctl domains check api.example.com --probe
1ctl domains setup api.example.com
1ctl domains remove api.example.com --app api --yes

The CLI intentionally separates three things that can share the same name:

Resource Commands What it controls
Registration search or purchase domains search, available, purchase, purchase-status Registrar availability and checkout intent.
Managed DNS zone domains managed, domains dns Nameserver delegation and records for a zone owned or delegated to SatuSky DNS.
App hostname attachment domains add, list, check, setup, delete A hostname routed to one app Service in the current organization.

Creating or changing a managed DNS record does not attach a hostname to an app. Likewise, attaching a hostname does not transfer its registration or DNS zone. All managed-zone and registration operations are scoped to the authenticated user and selected organization.

An external custom hostname is normalized as a hostname (not a URL); wildcard hostnames are currently unsupported because custom-domain TLS uses HTTP-01 validation.

Dimension Meaning
Backend attachment Domain belongs to the intended app.
Route attachment Kubernetes routing points the hostname at the app Service.
DNS The authoritative DNS condition is verified, which proves public DNS resolves to the expected target.
TLS Certificate is issued and served.
HTTP Optional probe reaches the app.

Workload readiness and domain readiness are different. A pod can be healthy while DNS or TLS is still pending.

The control plane’s default-hostname feature requires explicit production values for DEFAULT_HOSTNAME_DOMAIN and DEFAULT_HOSTNAME_EXPECTED_TARGET. Non-production environments use explicit localhost defaults only; they must not become an implicit production fallback. These are control-plane environment variables, not satusky.toml or application runtime configuration.