Commit ae9cf5c1b2
Verified · cmc
Layout: unified · split
Admin.org +6 −4
| @@ -210,10 +210,12 @@ owners that exist). The domain must not be the site host or a parent of | |||
| 210 | it — pages content runs its own scripts and must stay off the forge's | 210 | it — pages content runs its own scripts and must stay off the forge's |
| 211 | origin. | 211 | origin. |
| 212 | 212 | ||
| 213 | Users with repo admin claim custom domains with =repo domain add=; ACME | 213 | Users with repo admin claim custom domains with =repo domain add=. |
| 214 | issues certificates only for claimed hosts, so stray DNS pointed at the | 214 | Claims activate only after a DNS TXT challenge proves control of the |
| 215 | server gets nothing. Claims are unverified in v1 — fine while | 215 | domain (=repo domain verify=, audit-logged); pending claims serve |
| 216 | registration is closed; add DNS TXT verification before opening it. | 216 | nothing, get no certificates, and expire after 7 days. ACME issues |
| 217 | certificates only for verified hosts, so stray DNS pointed at the | ||
| 218 | server gets nothing. | ||
| 217 | 219 | ||
| 218 | * Security | 220 | * Security |
| 219 | 221 | ||
Users.org +8 −6
| @@ -329,12 +329,14 @@ build and push the branch for automatic deploys. Sites run on a | |||
| 329 | separate origin — your scripts work, and the forge's cookies are out of | 329 | separate origin — your scripts work, and the forge's cookies are out of |
| 330 | reach. | 330 | reach. |
| 331 | 331 | ||
| 332 | A repo can also serve its pages branch on a domain you own: | 332 | A repo can also serve its pages branch on a domain you own. |
| 333 | =gitbay repo domain add <owner/name> <domain>=, then point the domain's | 333 | =repo domain add <owner/name> <domain>= claims it and prints a DNS TXT |
| 334 | A/AAAA records at the instance (DNS-only if the domain sits behind a | 334 | challenge (=_gitbay-challenge.<domain>=); create the record, run |
| 335 | proxying provider — the instance issues its own certificates). Claims | 335 | =repo domain verify=, then point the domain's A/AAAA records at the |
| 336 | are exclusive per instance; =repo domain list= and =repo show= report | 336 | instance (DNS-only if the domain sits behind a proxying provider — the |
| 337 | them. | 337 | instance issues its own certificates). Claims are exclusive per |
| 338 | instance; unverified claims serve nothing and expire after 7 days. | ||
| 339 | =repo domain list= reports pending/verified/expired. | ||
| 338 | 340 | ||
| 339 | * Notifications | 341 | * Notifications |
| 340 | 342 | ||