Custom domains
Serve an app on your own hostname. VibeHost provisions the TLS certificate for you.
Every app gets a free *.vibehost.space URL by default. Add a custom hostname when you want to ship it under your own brand.
Add a domain
vibehost domain add www.example.com --app my-siteOutput, trimmed to the fields you act on:
{
"ok": true,
"data": {
"hostname": "www.example.com",
"verifiedAt": null,
"mode": "normal",
"instructions": {
"recordType": "CNAME",
"name": "www.example.com",
"value": "cname.vibehost-dns.com",
"verifyRecord": {
"name": "_vibehost.www.example.com",
"value": "vh-verify=<token>"
}
}
}
}Configure DNS
Add a CNAME record at your DNS provider:
CNAME www cname.vibehost-dns.comThe target is a shared edge hostname on our SaaS DNS zone, not the per-app <app>.vibehost.space URL. The same CNAME target works for every custom domain, because our edge routes by the Host header rather than by where the CNAME points.
vibehost domain add www.example.com --app my-site prints the current target the API expects (it can change if we migrate zones), so prefer copying from the CLI output over hard-coding this string.
- Open the zone for your domain.
- DNS → Add record.
- Type:
CNAME. Name:www. Target:cname.vibehost-dns.com. - Set Proxy status to DNS only (grey cloud) at first, so VibeHost can provision the cert directly. You can switch to proxied (orange cloud) later if you want Cloudflare in front of VibeHost.
- Set SSL/TLS encryption mode to Full or Full (strict). Avoid Flexible, which breaks HSTS.
- Open the hosted zone.
- Create record.
- Record type:
CNAME. Record name:www. Value:cname.vibehost-dns.com. TTL: 300.
The DNS spec doesn't allow CNAME at the apex of a zone. Pick one:
- Use an ALIAS, ANAME or flattened CNAME record. Cloudflare, Route 53
and DNSimple all support a non-RFC
ALIAS/ANAMErecord that behaves like a CNAME at the apex. Target it atcname.vibehost-dns.com. - Redirect the apex to
www. Set the apex to redirect tohttps://www.example.com(most DNS providers do this for free) and CNAMEwwwtocname.vibehost-dns.comas above.
Verify and provision the cert
vibehost domain verify www.example.com --app my-siteThe verifier checks your DNS records, then sets the hostname up on VibeHost's edge, which terminates TLS and has a domain-validated certificate issued for you. vibehost domain list shows each hostname as pending until it verifies, then verified. The certificate is issued after the hostname verifies. A hostname another workspace holds or held shows pending reclaim instead: prove you control it with the TXT record from domain add (instructions.verifyRecord).
Manage
vibehost domain list --app my-site
vibehost domain remove www.example.com --app my-siteRemoving a domain stops routing immediately and removes the hostname from VibeHost's edge, so its certificate stops being served.
Multiple domains per app
You can attach as many hostnames as you like:
vibehost domain add example.com --app my-site
vibehost domain add www.example.com --app my-site
vibehost domain add example.net --app my-siteAll resolve to the same deployment. The primary URL in app.url stays the *.vibehost.space alias. Custom hostnames are added alongside it and don't replace it.
Redirects
vibehost redirects list --app my-site
vibehost redirects add /old-path /new-path --app my-site
vibehost redirects remove <ruleId> --app my-siteFor bulk changes, upload a JSON file of rules and then sync (which diffs the file against the live rules and applies the difference):
vibehost redirects upload ./redirects.json --app my-site
vibehost redirects sync --app my-siteDNS provider walkthroughs
- Open the zone for your domain at dash.cloudflare.com.
- DNS → Add record.
- Type:
CNAME. Name:www. Target:cname.vibehost-dns.com. - Set Proxy status to DNS only (grey cloud) at first, so VibeHost can provision the cert.
- Under SSL/TLS encryption mode, choose Full or Full (strict). Avoid Flexible, which drops HTTPS between Cloudflare and VibeHost and breaks HSTS.
- Once the cert is provisioned, you can switch the proxy to proxied (orange cloud) if you want Cloudflare's CDN in front of VibeHost. You'll need Full (strict), and responses may be cached twice.
To check the record, run this. It should return cname.vibehost-dns.com.
dig +short CNAME www.example.com @1.1.1.1- Console → Route 53 → Hosted zones → your domain.
- Create record.
- Record name:
www. Record type:CNAME. Value:cname.vibehost-dns.com. TTL:300. - Create records.
For the apex (example.com with no www), a Route 53 Alias record only points at AWS resources (CloudFront, ALB, S3 websites), so it can't target an external host like cname.vibehost-dns.com. You have two other options: (a) use Route 53 to redirect apex → www (via an S3 website bucket + Alias, the classic pattern), then CNAME www to cname.vibehost-dns.com; or (b) move the zone to a provider with true ANAME / CNAME flattening (Cloudflare, DNSimple, Porkbun).
Verify:
dig +short CNAME www.example.com @ns-XXX.awsdns-XX.com- Domain List → Manage next to your domain.
- Advanced DNS tab.
- Add New Record.
- Type:
CNAME Record. Host:www. Value:cname.vibehost-dns.com.(trailing dot is optional but Namecheap shows it). TTL: Automatic. - Save.
Namecheap doesn't support a CNAME at the apex. Use its URL Redirect Record to redirect the bare domain to www instead.
- Domain dashboard → DNS for the domain.
- Add → CNAME.
- Name:
www. Value:cname.vibehost-dns.com. TTL: 1 hour. - Save.
GoDaddy's free DNS doesn't support CNAME flattening at the apex. Either move the zone to Cloudflare (free), or use GoDaddy's Forward (HTTP 301) to redirect the apex to www.
Google sold Google Domains to Squarespace; the underlying DNS panel is similar.
- DNS → Manage custom records.
- Create new record.
- Host:
www. Type:CNAME. TTL: 3600. Data:cname.vibehost-dns.com. - Save.
- Manage DNS for the domain.
- Add Record.
- Type:
CNAME. Host:www. Answer:cname.vibehost-dns.com. TTL: 600. - Save.
Porkbun supports ALIAS records at the apex, so you can point example.com at cname.vibehost-dns.com directly.
The DNS spec doesn't allow a CNAME at the apex of a zone, and VibeHost has no fixed IP for an A record to point at. There are two workarounds.
- Use an ALIAS, ANAME or flattened CNAME record: Cloudflare (built-in flattening), DNSimple (ANAME), Porkbun (ALIAS) or Hetzner (ALIAS). These behave like a CNAME at the apex and can target external hosts like
cname.vibehost-dns.com. Route 53's Alias only targets AWS resources, so it can't point at us directly (see the Route 53 tab). - Redirect the apex to
wwwover HTTP. Most registrars (Namecheap, GoDaddy, Porkbun) offer a free "URL forward" that 301sexample.comtohttps://www.example.com. Pair it with a normal CNAME onwww.
Use option 1 if your provider supports it, otherwise option 2. If vibehost domain add example.com --app my-site rejects the apex, the API is enforcing this rule, and its error message names the same two options.
Verification failure modes
When verification fails, vibehost domain verify returns one of three specific codes instead of a generic VALIDATION_FAILED.
| Code | What it means | What to do |
|---|---|---|
DOMAIN_VERIFY_RECORD_NOT_FOUND | DNS resolved to NXDOMAIN / ENODATA | Record not published yet, or DNS hasn't propagated. Wait 5 to 15 minutes and retry. |
DOMAIN_VERIFY_RECORD_MISMATCH | CNAME exists but points elsewhere | Compare details.observed vs details.expected. Update the record to match. |
DOMAIN_VERIFY_DNS_TIMEOUT | Resolvers didn't respond inside 3s × 3 tries | Transient. Retry shortly. |
All three remain HTTP 400 / CLI exit code 3. Use the code to branch your retry logic; the human message is for display only.
Subdomain takeover protection
If you vibehost domain add www.example.com then never publish the matching DNS record, the hostname stays pending indefinitely and we don't accept traffic for it. This prevents "dangling CNAME" subdomain-takeover attacks (where you delete an app but leave the CNAME pointing at us).
When you remove a domain (vibehost domain remove), the cert stops serving immediately. If you later re-add the same hostname, it starts over at pending and has to verify again.
Concurrent claims on the same domain
If two workspaces both try to verify the same hostname concurrently (e.g. a misconfigured DNS pointing at someone else's app), the second one will get 409 RECLAIM_LOST_RACE. The losing side should re-check whether their CNAME actually points where they think it does.
Limits
| Constraint | Default cap |
|---|---|
| Hostnames per app | 25 |
| Hostnames per workspace | 250 |
| Redirects per app | 500 |
vibehost domain verify retries / min | 30 |
An Enterprise contract can raise these caps.
Troubleshooting
| Symptom | Likely cause | Fix |
|---|---|---|
vibehost domain add returns cannot add a hostname under the platform's own domain | You tried *.vibehost.com / *.vibehost.space | Pick a hostname you own at a public registrar |
pending for more than 10 min | DNS not propagated, or record mismatch | dig CNAME <host> to compare; re-run domain verify |
Certificate error persists more than 5 min after verified | The certificate hasn't been issued yet (rare) | Wait 10 min. Email contact@vibehost.com if it persists; re-running verify on a verified domain doesn't restart issuance |
Cloudflare error 525 on the user-facing domain | CF proxy + Full strict, cert mismatch | Switch CF SSL to Full (not Full strict) initially; bump to Full strict once the domain is verified and its certificate is served |
Site loads on apex but not www (or vice versa) | Only one hostname added | vibehost domain add both, or set a URL Forward from one to the other at the registrar |