2
4 Comments

How do you mange vanity-url (customer domains)?

Do you have a SaaS that allows the customers to point a cname to you?
I.e if you're help.com, then help.customer.com points to customer.help.com

If you do, how do you manage ssl for customers domains?
I saw cloudflare have a solution but it's quite expensive for me at this point.

on April 11, 2020
  1. 2

    I run a website monitoring service, and one of the features I offer is status pages, which can be served either from my subdomain or customer's domain.

    You need to take care of 2 things:

    • generate a wildcard certificate for your domain (i.e., for subdomains to work)
    • generate certificates for your customers' domains

    I've done this with Caddy, Let's Encrypt, and Rails (most backend web frameworks will do).

    To generate a Let's Encrypt wildcard certificate with Caddy, you will have to compile Caddy + DNS plugin from the source, and create a DNS TXT record. See linked forum threads below.

    Caddy can also obtain Let's Encrypt certificates on the fly (On-demand TLS is the term-of-art). For this to work, you'll have to collect the customer's domain, and they need to point the CNAME record to you.

    Caddy takes care of certificate renewals as well.

    The Rails app is responsible for serving the right page given the subdomain/custom domain, and approving domains for which Caddy should issue certificates.

    I don't want to bore you with implementation details too much, but suffice it to say it was quite tricky to get it right. Below are two forum threads where I was trying to figure things out:

    You don't have to use Caddy per se, but I found it to be the least painful choice (if you want to fully control your software that is).

    1. 1

      Thanks for the detailed response.
      If I'm able to find a ready made solution for a reasonable price I'd probably use it.
      Otherwise, I'll take a deeper look into your stack!
      Thanks!

  2. 1

    I have a Cloudflare DNS only CNAME record, that points at a CloudFront Distribution (example). Then in my AWS CloudFront Distribution, I define a CNAME record for each customer, along with a wildcard SSL Certificate (example). This points to a single S3 bucket where I then capture the URL's subdomain as the user is logging in to a specific company. This part is just because some email addresses (super admins) require the ability to login to multiple companies.

    Hope this helps a little bit! Let me know if you have any questions.

    1. 3

      Thanks for the details!
      As this is not top priority for me right now, I think I'll wait a little and then probably use a service like https://autossl.co/