Commit ae9cf5c1b2
Verified · cmc
Layout: unified · split
Admin.org +6 −4
| @@ -210,10 +210,12 @@ owners that exist). The domain must not be the site host or a parent of | ||
| 210 | 210 | it — pages content runs its own scripts and must stay off the forge's |
| 211 | 211 | origin. |
| 212 | 212 | |
| 213 | Users with repo admin claim custom domains with =repo domain add=; ACME | |
| 214 | issues certificates only for claimed hosts, so stray DNS pointed at the | |
| 215 | server gets nothing. Claims are unverified in v1 — fine while | |
| 216 | registration is closed; add DNS TXT verification before opening it. | |
| 213 | Users with repo admin claim custom domains with =repo domain add=. | |
| 214 | Claims activate only after a DNS TXT challenge proves control of the | |
| 215 | domain (=repo domain verify=, audit-logged); pending claims serve | |
| 216 | nothing, get no certificates, and expire after 7 days. ACME issues | |
| 217 | certificates only for verified hosts, so stray DNS pointed at the | |
| 218 | server gets nothing. | |
| 217 | 219 | |
| 218 | 220 | * Security |
| 219 | 221 | |
Users.org +8 −6
| @@ -329,12 +329,14 @@ build and push the branch for automatic deploys. Sites run on a | ||
| 329 | 329 | separate origin — your scripts work, and the forge's cookies are out of |
| 330 | 330 | reach. |
| 331 | 331 | |
| 332 | A repo can also serve its pages branch on a domain you own: | |
| 333 | =gitbay repo domain add <owner/name> <domain>=, then point the domain's | |
| 334 | A/AAAA records at the instance (DNS-only if the domain sits behind a | |
| 335 | proxying provider — the instance issues its own certificates). Claims | |
| 336 | are exclusive per instance; =repo domain list= and =repo show= report | |
| 337 | them. | |
| 332 | A repo can also serve its pages branch on a domain you own. | |
| 333 | =repo domain add <owner/name> <domain>= claims it and prints a DNS TXT | |
| 334 | challenge (=_gitbay-challenge.<domain>=); create the record, run | |
| 335 | =repo domain verify=, then point the domain's A/AAAA records at the | |
| 336 | instance (DNS-only if the domain sits behind a proxying provider — the | |
| 337 | instance issues its own certificates). Claims are exclusive per | |
| 338 | instance; unverified claims serve nothing and expire after 7 days. | |
| 339 | =repo domain list= reports pending/verified/expired. | |
| 338 | 340 | |
| 339 | 341 | * Notifications |
| 340 | 342 | |