Skip to content
Helicarrier Developers
DOCUMENTATION

Domains & TLS

Generated hostnames, adding your own custom domains, and automatic HTTPS.

Every web service on Helicarrier Cloud is reachable over HTTPS from the moment it deploys. You get a generated hostname for free and can attach your own custom domains whenever you are ready.

When a web service deploys, it is assigned a hostname automatically — something like your-service.on.helicarrier.xyz. It works immediately over HTTPS, which is perfect for previewing and internal use before you wire up a real domain.

To serve your service on your own domain:

  1. On the service’s Networking (Domains) tab, add your hostname (for example, app.example.com).
  2. Create the DNS record your DNS provider requires, pointing your domain at Helicarrier.
  3. Watch the status move from pending to securing to active.

You can add several domains to one service and remove them at any time.

Helicarrier provisions TLS certificates automatically — there is nothing to upload or renew. Certificates are issued on demand at the first request to a hostname, and renewed for you. Your services are always served over HTTPS.

You can keep your domain proxied through Cloudflare (the orange cloud). Helicarrier supports it, and your visitors get Cloudflare’s network in front of your app.

  • In Cloudflare, set SSL/TLS → Full (strict), or leave it on Automatic, which picks the right mode for you. Helicarrier always serves a valid certificate, so strict works.
  • Don’t use Flexible. Cloudflare would talk to Helicarrier over plain HTTP, Helicarrier redirects to HTTPS, and visitors see a redirect loop. We warn you on verify if we see it.
  • While the domain is proxied, its DNS points at Cloudflare rather than at us, so we confirm it by issuing its certificate instead of by DNS. It can sit in securing for a minute or two.
  • Visitor IPs: your app receives the visitor’s address as the first entry of X-Forwarded-For and in Cloudflare’s CF-Connecting-IP header. Prefer CF-Connecting-IP: it’s set by Cloudflare and can’t be faked by the visitor.

DNS only (the grey cloud) works too, if you’d rather Cloudflare just answer DNS.

Not everything should be public. A private service (see Service types) has no public domain — it is reachable only by your other services over the internal network. Use it for internal APIs and backends.