VibeHost
Guides

Custom domains

Serve an app on your own hostname. VibeHost provisions the TLS certificate for you.

Every app gets a free *.vibehost.space URL by default. Add a custom hostname when you want to ship it under your own brand.

Add a domain

vibehost domain add www.example.com --app my-site

Output, trimmed to the fields you act on:

{
  "ok": true,
  "data": {
    "hostname": "www.example.com",
    "verifiedAt": null,
    "mode": "normal",
    "instructions": {
      "recordType": "CNAME",
      "name": "www.example.com",
      "value": "cname.vibehost-dns.com",
      "verifyRecord": {
        "name": "_vibehost.www.example.com",
        "value": "vh-verify=<token>"
      }
    }
  }
}

Configure DNS

Add a CNAME record at your DNS provider:

CNAME  www  cname.vibehost-dns.com

The target is a shared edge hostname on our SaaS DNS zone, not the per-app <app>.vibehost.space URL. The same CNAME target works for every custom domain, because our edge routes by the Host header rather than by where the CNAME points.

vibehost domain add www.example.com --app my-site prints the current target the API expects (it can change if we migrate zones), so prefer copying from the CLI output over hard-coding this string.

  1. Open the zone for your domain.
  2. DNS → Add record.
  3. Type: CNAME. Name: www. Target: cname.vibehost-dns.com.
  4. Set Proxy status to DNS only (grey cloud) at first, so VibeHost can provision the cert directly. You can switch to proxied (orange cloud) later if you want Cloudflare in front of VibeHost.
  5. Set SSL/TLS encryption mode to Full or Full (strict). Avoid Flexible, which breaks HSTS.
  1. Open the hosted zone.
  2. Create record.
  3. Record type: CNAME. Record name: www. Value: cname.vibehost-dns.com. TTL: 300.

The DNS spec doesn't allow CNAME at the apex of a zone. Pick one:

  1. Use an ALIAS, ANAME or flattened CNAME record. Cloudflare, Route 53 and DNSimple all support a non-RFC ALIAS/ANAME record that behaves like a CNAME at the apex. Target it at cname.vibehost-dns.com.
  2. Redirect the apex to www. Set the apex to redirect to https://www.example.com (most DNS providers do this for free) and CNAME www to cname.vibehost-dns.com as above.

Verify and provision the cert

vibehost domain verify www.example.com --app my-site

The verifier checks your DNS records, then sets the hostname up on VibeHost's edge, which terminates TLS and has a domain-validated certificate issued for you. vibehost domain list shows each hostname as pending until it verifies, then verified. The certificate is issued after the hostname verifies. A hostname another workspace holds or held shows pending reclaim instead: prove you control it with the TXT record from domain add (instructions.verifyRecord).

Manage

vibehost domain list --app my-site
vibehost domain remove www.example.com --app my-site

Removing a domain stops routing immediately and removes the hostname from VibeHost's edge, so its certificate stops being served.

Multiple domains per app

You can attach as many hostnames as you like:

vibehost domain add example.com --app my-site
vibehost domain add www.example.com --app my-site
vibehost domain add example.net --app my-site

All resolve to the same deployment. The primary URL in app.url stays the *.vibehost.space alias. Custom hostnames are added alongside it and don't replace it.

Redirects

vibehost redirects list --app my-site
vibehost redirects add /old-path /new-path --app my-site
vibehost redirects remove <ruleId> --app my-site

For bulk changes, upload a JSON file of rules and then sync (which diffs the file against the live rules and applies the difference):

vibehost redirects upload ./redirects.json --app my-site
vibehost redirects sync --app my-site

DNS provider walkthroughs

  1. Open the zone for your domain at dash.cloudflare.com.
  2. DNS → Add record.
  3. Type: CNAME. Name: www. Target: cname.vibehost-dns.com.
  4. Set Proxy status to DNS only (grey cloud) at first, so VibeHost can provision the cert.
  5. Under SSL/TLS encryption mode, choose Full or Full (strict). Avoid Flexible, which drops HTTPS between Cloudflare and VibeHost and breaks HSTS.
  6. Once the cert is provisioned, you can switch the proxy to proxied (orange cloud) if you want Cloudflare's CDN in front of VibeHost. You'll need Full (strict), and responses may be cached twice.

To check the record, run this. It should return cname.vibehost-dns.com.

dig +short CNAME www.example.com @1.1.1.1
  1. Console → Route 53 → Hosted zones → your domain.
  2. Create record.
  3. Record name: www. Record type: CNAME. Value: cname.vibehost-dns.com. TTL: 300.
  4. Create records.

For the apex (example.com with no www), a Route 53 Alias record only points at AWS resources (CloudFront, ALB, S3 websites), so it can't target an external host like cname.vibehost-dns.com. You have two other options: (a) use Route 53 to redirect apex → www (via an S3 website bucket + Alias, the classic pattern), then CNAME www to cname.vibehost-dns.com; or (b) move the zone to a provider with true ANAME / CNAME flattening (Cloudflare, DNSimple, Porkbun).

Verify:

dig +short CNAME www.example.com @ns-XXX.awsdns-XX.com
  1. Domain List → Manage next to your domain.
  2. Advanced DNS tab.
  3. Add New Record.
  4. Type: CNAME Record. Host: www. Value: cname.vibehost-dns.com. (trailing dot is optional but Namecheap shows it). TTL: Automatic.
  5. Save.

Namecheap doesn't support a CNAME at the apex. Use its URL Redirect Record to redirect the bare domain to www instead.

  1. Domain dashboard → DNS for the domain.
  2. Add → CNAME.
  3. Name: www. Value: cname.vibehost-dns.com. TTL: 1 hour.
  4. Save.

GoDaddy's free DNS doesn't support CNAME flattening at the apex. Either move the zone to Cloudflare (free), or use GoDaddy's Forward (HTTP 301) to redirect the apex to www.

Google sold Google Domains to Squarespace; the underlying DNS panel is similar.

  1. DNS → Manage custom records.
  2. Create new record.
  3. Host: www. Type: CNAME. TTL: 3600. Data: cname.vibehost-dns.com.
  4. Save.
  1. Manage DNS for the domain.
  2. Add Record.
  3. Type: CNAME. Host: www. Answer: cname.vibehost-dns.com. TTL: 600.
  4. Save.

Porkbun supports ALIAS records at the apex, so you can point example.com at cname.vibehost-dns.com directly.

The DNS spec doesn't allow a CNAME at the apex of a zone, and VibeHost has no fixed IP for an A record to point at. There are two workarounds.

  1. Use an ALIAS, ANAME or flattened CNAME record: Cloudflare (built-in flattening), DNSimple (ANAME), Porkbun (ALIAS) or Hetzner (ALIAS). These behave like a CNAME at the apex and can target external hosts like cname.vibehost-dns.com. Route 53's Alias only targets AWS resources, so it can't point at us directly (see the Route 53 tab).
  2. Redirect the apex to www over HTTP. Most registrars (Namecheap, GoDaddy, Porkbun) offer a free "URL forward" that 301s example.com to https://www.example.com. Pair it with a normal CNAME on www.

Use option 1 if your provider supports it, otherwise option 2. If vibehost domain add example.com --app my-site rejects the apex, the API is enforcing this rule, and its error message names the same two options.

Verification failure modes

When verification fails, vibehost domain verify returns one of three specific codes instead of a generic VALIDATION_FAILED.

CodeWhat it meansWhat to do
DOMAIN_VERIFY_RECORD_NOT_FOUNDDNS resolved to NXDOMAIN / ENODATARecord not published yet, or DNS hasn't propagated. Wait 5 to 15 minutes and retry.
DOMAIN_VERIFY_RECORD_MISMATCHCNAME exists but points elsewhereCompare details.observed vs details.expected. Update the record to match.
DOMAIN_VERIFY_DNS_TIMEOUTResolvers didn't respond inside 3s × 3 triesTransient. Retry shortly.

All three remain HTTP 400 / CLI exit code 3. Use the code to branch your retry logic; the human message is for display only.

Subdomain takeover protection

If you vibehost domain add www.example.com then never publish the matching DNS record, the hostname stays pending indefinitely and we don't accept traffic for it. This prevents "dangling CNAME" subdomain-takeover attacks (where you delete an app but leave the CNAME pointing at us).

When you remove a domain (vibehost domain remove), the cert stops serving immediately. If you later re-add the same hostname, it starts over at pending and has to verify again.

Concurrent claims on the same domain

If two workspaces both try to verify the same hostname concurrently (e.g. a misconfigured DNS pointing at someone else's app), the second one will get 409 RECLAIM_LOST_RACE. The losing side should re-check whether their CNAME actually points where they think it does.

Limits

ConstraintDefault cap
Hostnames per app25
Hostnames per workspace250
Redirects per app500
vibehost domain verify retries / min30

An Enterprise contract can raise these caps.

Troubleshooting

SymptomLikely causeFix
vibehost domain add returns cannot add a hostname under the platform's own domainYou tried *.vibehost.com / *.vibehost.spacePick a hostname you own at a public registrar
pending for more than 10 minDNS not propagated, or record mismatchdig CNAME <host> to compare; re-run domain verify
Certificate error persists more than 5 min after verifiedThe certificate hasn't been issued yet (rare)Wait 10 min. Email contact@vibehost.com if it persists; re-running verify on a verified domain doesn't restart issuance
Cloudflare error 525 on the user-facing domainCF proxy + Full strict, cert mismatchSwitch CF SSL to Full (not Full strict) initially; bump to Full strict once the domain is verified and its certificate is served
Site loads on apex but not www (or vice versa)Only one hostname addedvibehost domain add both, or set a URL Forward from one to the other at the registrar

On this page