Skip to main content

Domain and SSL Configuration

This guide covers the DNS records required by the platform, then installs Nginx, adds the routes to the application, and issues an SSL certificate so the domain is reachable over HTTPS.

Domain and DNS Configuration

Step 1: Configure the Primary On-Premises Domain

In the DNS provider that manages the customer's domain (Cloudflare, GoDaddy, Route53, etc. - whoever controls their domain, not necessarily Authnull), create an A record:

TypeNameValue
Aonprem.customer-domain.comSERVER_PUBLIC_IP
note

SERVER_PUBLIC_IP is this VM's public IP address - the same value set as SYSTEM_IP in the .env file during Installation.

Step 2: Verify DNS Resolution

dig +short onprem.customer-domain.com @1.1.1.1

Step 3: Configure the Tenant Domain

In the DNS provider that manages the customer's domain, create an additional A record for the tenant subdomain:

TypeNameValue
Adefault.customer-org-name.customer-domain.comSERVER_PUBLIC_IP

Step 4: Verify Tenant DNS Resolution

dig +short default.customer-org-name.customer-domain.com @1.1.1.1

SSL Certificate and Nginx Configuration

The domain was already pointed to this server's IP address in the previous steps. This section installs Nginx, adds the routes to the application, and issues an SSL certificate.

Step 5: Install Nginx

sudo apt update
sudo apt install -y nginx
sudo systemctl status nginx

Step 6: Install Certbot and Obtain SSL Certificates

sudo apt install -y certbot python3-certbot-nginx
sudo certbot certonly --nginx -d onprem.customer-domain.com
sudo certbot certonly --nginx -d default.customer-org-name.customer-domain.com

This creates the certificate files at /etc/letsencrypt/live/onprem.customer-domain.com/fullchain.pem and privkey.pem, used in the Nginx configuration below.

Step 7: Configure Nginx Upstreams

Edit the Nginx config:

sudo nano /etc/nginx/nginx.conf
tip

An example nginx.conf file is included in the deployment package. Use it as a reference and update the routes according to the customer's domain.

Step 8: Configure Firewall Ports

sudo ufw enable
sudo ufw allow 80
sudo ufw allow 443
sudo ufw status

Step 9: Test and Reload Nginx

sudo nginx -t
sudo systemctl reload nginx
note

Repeat this test-and-reload step after adding each server block - both the primary on-premises domain and the tenant domain.

Next Steps

Continue to Organization and Tenant Setup to register your organization.