A site answers for its domain and its aliases. You pick the domain when you create the site and it does not change; you add and remove aliases whenever you like. The certificate covers the domain and the aliases.
Set the Let's Encrypt email
Once per server:
- Open Settings.
- Under Certificates, type the Let's Encrypt email. It is used to register and for expiry notices.
- Save.
Without this email the panel neither issues nor renews certificates.
Issue the certificate
- Open the site and its SSL tab.
- Choose Issue / renew.
The panel starts the Certificate task. Before it asks for the certificate, the server checks that
every name really reaches it: it writes a test file and reads it from http://<name>/.well-known/acme-challenge/.
If a name does not answer, the task fails without spending a Let's Encrypt attempt and says where its
DNS points.
The Current certificate box shows who issued it and when it expires. The panel renews Let's Encrypt certificates by itself when 30 days are left. When a renewal fails, the box shows Last renewal failed with the reason.
A wildcard certificate
A wildcard covers <domain> and *.<domain>, and uses Cloudflare DNS instead of the test file.
- In Settings, under Certificates, type the Cloudflare API token. It needs the Zone:DNS:Edit permission.
- In the site's SSL tab, choose Wildcard.
A wildcard does not request the aliases: it covers only the domain and its subdomains.
Your own certificate
- In the SSL tab, under Custom certificate, paste the Full chain (PEM) and the Private key (PEM).
- Choose Install.
The server refuses a certificate that does not match the key, does not cover the domain or has already expired. A custom certificate takes precedence over the Let's Encrypt one, and the panel does not renew it. To go back to Let's Encrypt, choose Back to Let's Encrypt.
Add an alias
Only an administrator changes the aliases.
- Open the site, Overview tab, Domains and folder card.
- In Aliases type each name and press Enter; the × on a name removes it.
- Choose Apply.
With the API, send the whole list; [] removes them all:
curl --unix-socket /run/cloudground/api.sock http://localhost/api/sites/<id> \
-X PATCH \
-H "Authorization: Bearer $CLOUDGROUND_TOKEN" \
-H 'Content-Type: application/json' \
-d '{"aliases": ["www.example.com"]}'
- Each alias is a plain host name, different from the site's domain. At most 50.
- No name can belong to two sites: an alias another site already uses is refused with
400(alias … is already used by …), and nothing changes. - When the site has a Let's Encrypt certificate, the panel reissues it for the new names by itself. If the reissue fails, the site keeps serving its previous certificate.
- When the site has a custom certificate, the panel warns that it may not cover the new aliases: install one that does. If you then choose Back to Let's Encrypt, the site takes back its previous Let's Encrypt certificate: choose Issue / renew so that it covers the new aliases.