Commit bd1b95ee5d
Verified · cmc
Layout: unified · split
Admin.org +5
| @@ -210,6 +210,11 @@ owners that exist). The domain must not be the site host or a parent of | ||
| 210 | 210 | it — pages content runs its own scripts and must stay off the forge's |
| 211 | 211 | origin. |
| 212 | 212 | |
| 213 | Users with repo admin claim custom domains with =repo domain add=; ACME | |
| 214 | issues certificates only for claimed hosts, so stray DNS pointed at the | |
| 215 | server gets nothing. Claims are unverified in v1 — fine while | |
| 216 | registration is closed; add DNS TXT verification before opening it. | |
| 217 | ||
| 213 | 218 | * Security |
| 214 | 219 | |
| 215 | 220 | The [[Threat-Model]] file is the reference for what the forge |
Users.org +7
| @@ -329,6 +329,13 @@ build and push the branch for automatic deploys. Sites run on a | ||
| 329 | 329 | separate origin — your scripts work, and the forge's cookies are out of |
| 330 | 330 | reach. |
| 331 | 331 | |
| 332 | A repo can also serve its pages branch on a domain you own: | |
| 333 | =gitbay repo domain add <owner/name> <domain>=, then point the domain's | |
| 334 | A/AAAA records at the instance (DNS-only if the domain sits behind a | |
| 335 | proxying provider — the instance issues its own certificates). Claims | |
| 336 | are exclusive per instance; =repo domain list= and =repo show= report | |
| 337 | them. | |
| 338 | ||
| 332 | 339 | * Notifications |
| 333 | 340 | |
| 334 | 341 | When the instance has SMTP configured, activity mails you: someone |