About this Issue
You built a nice webhook backend in Dark for different aspects of your Discord/guilded.gg servers like GitLab CI, Twitch stream notifications and even a bit of deployment statuses from railway.app, and it's your nth canvas to have a custom domain.
The problem? In the current situation, you need to manually contact support every time you want to enable/disable custom domains for your canvases and cross your 🤞 to provision a delightful SSL cert for your custom domain. You want Cloudflare Origin certificates because you placed it behind their proxies? That would be painful if you self-host Dark on your own k8s cluster.
What I Suggest
Maybe implement UI in canvas settings on managing custom domains and handling SSL certs on self-serve basis. By default, we can do a domain ownership verification process through TXT DNS records (like GitLab Pages would do) before issuing a Let's Encrypt cert. In case the system detected that it is behind Cloudflare proxy, either prompt them to disable it OR generate origin certs and add it to the system.
About this Issue
You built a nice webhook backend in Dark for different aspects of your Discord/guilded.gg servers like GitLab CI, Twitch stream notifications and even a bit of deployment statuses from railway.app, and it's your nth canvas to have a custom domain.
The problem? In the current situation, you need to manually contact support every time you want to enable/disable custom domains for your canvases and cross your 🤞 to provision a delightful SSL cert for your custom domain. You want Cloudflare Origin certificates because you placed it behind their proxies? That would be painful if you self-host Dark on your own k8s cluster.
What I Suggest
Maybe implement UI in canvas settings on managing custom domains and handling SSL certs on self-serve basis. By default, we can do a domain ownership verification process through TXT DNS records (like GitLab Pages would do) before issuing a Let's Encrypt cert. In case the system detected that it is behind Cloudflare proxy, either prompt them to disable it OR generate origin certs and add it to the system.