Domains & TLS
Generated hostnames, adding your own custom domains, and automatic HTTPS.
Every web service on Helicarrier Cloud is reachable over HTTPS from the moment it deploys. You get a generated hostname for free and can attach your own custom domains whenever you are ready.
Generated hostnames
Section titled “Generated hostnames”When a web service deploys, it is assigned a hostname automatically — something like your-service.on.helicarrier.xyz. It works immediately over HTTPS, which is perfect for previewing and internal use before you wire up a real domain.
Custom domains
Section titled “Custom domains”To serve your service on your own domain:
- On the service’s Networking (Domains) tab, add your hostname (for example,
app.example.com). - Create the DNS record your DNS provider requires, pointing your domain at Helicarrier.
- Watch the status move from pending to securing to active.
You can add several domains to one service and remove them at any time.
Automatic TLS
Section titled “Automatic TLS”Helicarrier provisions TLS certificates automatically — there is nothing to upload or renew. Certificates are issued on demand at the first request to a hostname, and renewed for you. Your services are always served over HTTPS.
Using Cloudflare
Section titled “Using Cloudflare”You can keep your domain proxied through Cloudflare (the orange cloud). Helicarrier supports it, and your visitors get Cloudflare’s network in front of your app.
- In Cloudflare, set SSL/TLS → Full (strict), or leave it on Automatic, which picks the right mode for you. Helicarrier always serves a valid certificate, so strict works.
- Don’t use Flexible. Cloudflare would talk to Helicarrier over plain HTTP, Helicarrier redirects to HTTPS, and visitors see a redirect loop. We warn you on verify if we see it.
- While the domain is proxied, its DNS points at Cloudflare rather than at us, so we confirm it by issuing its certificate instead of by DNS. It can sit in securing for a minute or two.
- Visitor IPs: your app receives the visitor’s address as the first entry of
X-Forwarded-Forand in Cloudflare’sCF-Connecting-IPheader. PreferCF-Connecting-IP: it’s set by Cloudflare and can’t be faked by the visitor.
DNS only (the grey cloud) works too, if you’d rather Cloudflare just answer DNS.
Private services
Section titled “Private services”Not everything should be public. A private service (see Service types) has no public domain — it is reachable only by your other services over the internal network. Use it for internal APIs and backends.
- Link services and inject URLs with Service references.
- Confirm traffic is healthy in Runtime logs.