Commit ae9cf5c1b2

ae9cf5c1b22c1c89dfb907bac752df08afd0823b

parent: bd1b95ee5d

Verified · cmc

cmc <hello@cleberg.net> · 2026-08-25 17:45 UTC

docs: domain verification challenge and expiry

Layout: unified · split

Admin.org +6 −4
@@ -210,10 +210,12 @@ owners that exist). The domain must not be the site host or a parent of
210it — pages content runs its own scripts and must stay off the forge's 210it — pages content runs its own scripts and must stay off the forge's
211origin. 211origin.
212 212
213Users with repo admin claim custom domains with =repo domain add=; ACME 213Users with repo admin claim custom domains with =repo domain add=.
214issues certificates only for claimed hosts, so stray DNS pointed at the 214Claims activate only after a DNS TXT challenge proves control of the
215server gets nothing. Claims are unverified in v1 — fine while 215domain (=repo domain verify=, audit-logged); pending claims serve
216registration is closed; add DNS TXT verification before opening it. 216nothing, get no certificates, and expire after 7 days. ACME issues
217certificates only for verified hosts, so stray DNS pointed at the
218server gets nothing.
217 219
218* Security 220* Security
219 221
Users.org +8 −6
@@ -329,12 +329,14 @@ build and push the branch for automatic deploys. Sites run on a
329separate origin — your scripts work, and the forge's cookies are out of 329separate origin — your scripts work, and the forge's cookies are out of
330reach. 330reach.
331 331
332A repo can also serve its pages branch on a domain you own: 332A repo can also serve its pages branch on a domain you own.
333=gitbay repo domain add <owner/name> <domain>=, then point the domain's 333=repo domain add <owner/name> <domain>= claims it and prints a DNS TXT
334A/AAAA records at the instance (DNS-only if the domain sits behind a 334challenge (=_gitbay-challenge.<domain>=); create the record, run
335proxying provider — the instance issues its own certificates). Claims 335=repo domain verify=, then point the domain's A/AAAA records at the
336are exclusive per instance; =repo domain list= and =repo show= report 336instance (DNS-only if the domain sits behind a proxying provider — the
337them. 337instance issues its own certificates). Claims are exclusive per
338instance; unverified claims serve nothing and expire after 7 days.
339=repo domain list= reports pending/verified/expired.
338 340
339* Notifications 341* Notifications
340 342