Skip to content

Configuration

Custom domains

Serve an app on your own hostname with a managed TLS certificate.

Every service gets a Cloud Run URL. You can also serve it on a hostname you own, such as app.example.com. Elula sets up a managed TLS certificate and a load balancer for it in your own Google Cloud project.

Requirements

  • An active subscription. Without one, adding a domain is refused with "Custom domains need an active subscription."
  • Google Cloud connected for the workspace.
  • You are a workspace owner. Other members can see the domains of apps they have access to, but can't add or remove them.
  • Access to your domain's DNS settings.

Add a domain

  1. Open the app, go to Settings → Domains, and click Bind a custom domain. The Custom domain link next to the app's URL takes you there too.
  2. Enter the hostname, for example app.example.com, and click Continue.
  3. Elula shows two DNS records. Add both at your DNS provider:
TypePurpose
CNAMEProves you own the domain so Google can issue the certificate
APoints the hostname at the load balancer in your Google Cloud project
  1. Click I've added them — verify.

Copy the exact host and value from the dashboard. The CNAME value is generated for your domain.

DNS changes can take a few minutes to be visible. If verification says the record isn't visible yet, nothing is lost: wait and click Check again. Certificates usually issue within a few minutes of DNS going live.

Add a domain with the CLI

Run these in the app's folder (the one with .elula.json). The same rules apply as in the dashboard: you need to be a workspace owner, with Google Cloud connected and an active plan.

1. Add the domain. Elula sets up the certificate in your Google Cloud project and prints the two records to create:

elula domains add app.example.com

It asks you to type the hostname again, so a typo can't create certificates for the wrong name:

This adds app.example.com to my-app and creates its certificate in your Google Cloud.
Type app.example.com again to confirm: app.example.com
app.example.com added to my-app.

Add these records at your DNS provider:

  CNAME
    Name:  _acme-challenge.app.example.com.
    Value: 8f3a1c.4.authorize.certificatemanager.goog.

  A
    Name:  app.example.com
    Value: 34.120.10.20

Copy the name and value exactly. Some DNS providers want the name without the trailing dot, or without your domain at the end (for example just _acme-challenge.app).

If the domain is already on this app, add says so (with its status) and changes nothing. If it's on another app in your workspace, it names that app and stops: one domain serves one app, so remove it there first. A domain registered in another workspace is refused.

2. Add both records at your DNS provider.

3. Verify. --wait checks every 15 seconds, for up to 15 minutes, and stops as soon as the domain is live:

elula domains verify app.example.com --wait
Waiting for DNS and the certificate for app.example.com (up to 15 minutes)…
  0:00  CNAME record not visible yet — DNS can take a few minutes to propagate.
  0:15  Certificate is being provisioned — CNAME may still be propagating.
✓ Domain is live.
  https://app.example.com

Without --wait it checks once: it exits with code 0 when the domain is verified and 1 when it isn't yet. If the app has never been deployed, the domain verifies but only starts serving after the next elula deploy.

You can also do steps 1 and 3 in one go with elula domains add app.example.com --wait.

See and manage your domains:

elula domains                           # this app's domains: waiting for DNS, verified, or live
elula domains --all                     # every custom domain in the workspace
elula domains records app.example.com   # print the DNS records again
elula domains remove app.example.com    # stop serving it (type the hostname again to confirm)

Add --json to add, verify or list for scripts. Scripts and AI agents can't type the confirmation, so they pass --yes (-y) to add and remove. An AI agent can run all of this, but you have to add the DNS records yourself. See the command reference.

Domain status

Status in the dashboardMeaning
waiting for DNSThe certificate hasn't been issued yet. Check your records and verify again
verified · live after next deployThe certificate is issued, but the app had no running service yet. The domain starts serving after the app's next successful deploy
active · cert issuedThe domain is serving the app

Once a domain is active, the app's header shows it instead of the Cloud Run URL.

Certificate errors

If the certificate can't be issued, verification tells you why:

  • "CNAME record not visible yet": DNS hasn't propagated, or the record is wrong.
  • "CAA DNS record is blocking certificate issuance" or "CAA record forbids this certificate authority": your domain has a CAA record that doesn't allow Google to issue certificates. Update it at your DNS provider.
  • "Certificate rate limit hit": try again in an hour.

Rules

  • One hostname serves one app. A hostname already bound to another app can't be added again.
  • A hostname belongs to one workspace.
  • Your workspace's team domain (the one used for private apps) can't be bound to an app.
  • Domains of personal email providers, such as gmail.com, are refused.
  • Custom domains are for services. Jobs have no URL.

Private apps

A custom domain doesn't change who can open the app. A private app stays private on its custom domain.

Remove a domain

In Settings → Domains, click remove next to the domain, then confirm remove. From the CLI: elula domains remove app.example.com. Elula deletes the certificate and routing for that hostname from your Google Cloud project. You can then delete the DNS records.

Cost

The load balancer, static IP address and certificates are created in your Google Cloud project, and Google bills them to you directly.