Commit bd1b95ee5d

bd1b95ee5d9e76444cab5750bc705afecada5a43

parent: b1b9cddc02

Verified · cmc

cmc <hello@cleberg.net> · 2026-08-25 17:27 UTC

docs: custom pages domains

Layout: unified · split

Admin.org +5
@@ -210,6 +210,11 @@ owners that exist). The domain must not be the site host or a parent of
210it — pages content runs its own scripts and must stay off the forge's 210it — pages content runs its own scripts and must stay off the forge's
211origin. 211origin.
212 212
213Users with repo admin claim custom domains with =repo domain add=; ACME
214issues certificates only for claimed hosts, so stray DNS pointed at the
215server gets nothing. Claims are unverified in v1 — fine while
216registration is closed; add DNS TXT verification before opening it.
217
213* Security 218* Security
214 219
215The [[Threat-Model]] file is the reference for what the forge 220The [[Threat-Model]] file is the reference for what the forge
Users.org +7
@@ -329,6 +329,13 @@ build and push the branch for automatic deploys. Sites run on a
329separate origin — your scripts work, and the forge's cookies are out of 329separate origin — your scripts work, and the forge's cookies are out of
330reach. 330reach.
331 331
332A repo can also serve its pages branch on a domain you own:
333=gitbay repo domain add <owner/name> <domain>=, then point the domain's
334A/AAAA records at the instance (DNS-only if the domain sits behind a
335proxying provider — the instance issues its own certificates). Claims
336are exclusive per instance; =repo domain list= and =repo show= report
337them.
338
332* Notifications 339* Notifications
333 340
334When the instance has SMTP configured, activity mails you: someone 341When the instance has SMTP configured, activity mails you: someone