This guide explains how to configure dstack-ingress to work with different DNS providers for managing custom domains and SSL certificates.
- Cloudflare - The original and default provider
- Linode DNS - For Linode-hosted domains
DOMAIN- Your custom domain (e.g.,app.example.com)GATEWAY_DOMAIN- dstack gateway domain (e.g.,_.dstack-prod5.phala.network)CERTBOT_EMAIL- Email for Let's Encrypt registrationTARGET_ENDPOINT- Backend application endpoint to proxy toDNS_PROVIDER- DNS provider to use (cloudflare,linode)
SET_CAA- Enable CAA record setup (default: false)PORT- HTTPS port (default: 443)TXT_PREFIX- Prefix for TXT records (default: "_tapp-address")
DNS_PROVIDER=cloudflare
CLOUDFLARE_API_TOKEN=your-api-tokenRequired Permissions:
- Zone:Read
- DNS:Edit
DNS_PROVIDER=linode
LINODE_API_TOKEN=your-api-tokenRequired Permissions:
- Domains: Read/Write access
Important Note for Linode:
- Linode has a limitation where CAA and CNAME records cannot coexist on the same subdomain
- To work around this, the system will attempt to use A records instead of CNAME records
- If the gateway domain can be resolved to an IP, an A record will be created
- If resolution fails, it falls back to CNAME (but CAA records won't work on that subdomain)
- This is a Linode-specific limitation not present in other providers
version: '3.8'
services:
ingress:
image: dstack-ingress:latest
ports:
- "443:443"
environment:
# Common configuration
- DNS_PROVIDER=linode
- DOMAIN=app.example.com
- GATEWAY_DOMAIN=_.dstack-prod5.phala.network
- CERTBOT_EMAIL=admin@example.com
- TARGET_ENDPOINT=http://backend:8080
# Linode specific
- LINODE_API_TOKEN=your-api-token
volumes:
- ./letsencrypt:/etc/letsencrypt
- ./evidences:/evidencesIf you're currently using the Cloudflare-only version:
- No changes needed for Cloudflare users - The default behavior remains Cloudflare
- For other providers - Add the
DNS_PROVIDERenvironment variable and provider-specific credentials
If you see "Could not detect DNS provider type", ensure you have either:
- Set
DNS_PROVIDERenvironment variable explicitly, OR - Set provider-specific credential environment variables (e.g.,
CLOUDFLARE_API_TOKEN)
Different providers may have different propagation times. The default is 120 seconds, but you may need to adjust based on your provider's behavior.
Ensure your API tokens/credentials have the necessary permissions listed above for your provider.
- Go to https://dash.cloudflare.com/profile/api-tokens
- Create token with Zone:Read and DNS:Edit permissions
- Scope to specific zones if desired
- Go to https://cloud.linode.com/profile/tokens
- Create a Personal Access Token
- Grant "Domains" Read/Write access