DNS Setup
Every SupportBot service is published on subdomains derived from a single root domain. This guide covers the records to create on Cloudflare and the one setting that matters (proxy mode).
Records to Create
Cloudflare → your domain → DNS → Records. Replace <server-ip> with your VPS's IPv4 address:
| Type | Name | Content | Proxy status |
|---|---|---|---|
| A | @ (root) |
<server-ip> |
DNS only (grey) |
| CNAME | www |
@ |
DNS only (grey) |
| CNAME | chat |
@ |
DNS only (grey) |
| CNAME | dashboard |
@ |
DNS only (grey) |
| CNAME | ai |
@ |
DNS only (grey) |
| CNAME | bot |
@ |
DNS only (grey) |
| CNAME | showcase |
@ |
DNS only (grey) |
| CNAME | status |
@ |
DNS only (grey) |
| CNAME | n8n |
@ |
DNS only (grey) — optional |
Which subdomain serves what: Getting Started → Domains.
Proxy Mode: Why "DNS only"?
SupportBot's reverse proxy (Caddy) obtains TLS certificates from Let's Encrypt itself. With the Cloudflare proxy (orange cloud) enabled, ACME validation can get stuck at Cloudflare's edge and certificate issuance may fail.
- Recommended: create all records as DNS only (grey cloud). Caddy obtains and renews certificates for every subdomain automatically; no further setup.
- If you specifically want Cloudflare's proxy (CDN/WAF): start grey, verify certificates are issued, then switch the SSL/TLS mode to Full (strict) and flip records to orange. If renewal ever misbehaves, reverting to grey is always safe.
Server-side Prerequisites
- Ports 80 and 443 must be open in the VPS firewall (Let's Encrypt validation uses 80).
APP_DOMAINininfra/.envmust match your domain;CADDY_ACME_EMAILshould be a valid address (certificate notifications).
Verification
After the records propagate (usually a few minutes):
# Does DNS resolve?
dig +short chat.<your-domain>
# Certificate issued, service responding?
curl -I https://chat.<your-domain>
curl -I https://<your-domain> # marketing site
Caddy obtains the certificate on the first request; a few seconds of delay is normal. If something fails, check the tls.obtain lines in docker compose logs caddy on the server.
Troubleshooting
| Symptom | Check |
|---|---|
curl reports a certificate error |
Is the record orange (proxied)? Switch to grey and wait a few minutes. |
tls.obtain ... connection refused |
Ports 80/443 may be blocked by the firewall. |
| A subdomain hits the wrong service | Check APP_DOMAIN in infra/.env and that Caddy was restarted. |