Guide🇹🇷 Türkçe

DNS Setup

Every SupportBot service is published on subdomains derived from a single root domain. This guide covers the records to create on Cloudflare and the one setting that matters (proxy mode).

Records to Create

Cloudflare → your domain → DNS → Records. Replace <server-ip> with your VPS's IPv4 address:

Type Name Content Proxy status
A @ (root) <server-ip> DNS only (grey)
CNAME www @ DNS only (grey)
CNAME chat @ DNS only (grey)
CNAME dashboard @ DNS only (grey)
CNAME ai @ DNS only (grey)
CNAME bot @ DNS only (grey)
CNAME showcase @ DNS only (grey)
CNAME status @ DNS only (grey)
CNAME n8n @ DNS only (grey) — optional

Which subdomain serves what: Getting Started → Domains.

Proxy Mode: Why "DNS only"?

SupportBot's reverse proxy (Caddy) obtains TLS certificates from Let's Encrypt itself. With the Cloudflare proxy (orange cloud) enabled, ACME validation can get stuck at Cloudflare's edge and certificate issuance may fail.

  • Recommended: create all records as DNS only (grey cloud). Caddy obtains and renews certificates for every subdomain automatically; no further setup.
  • If you specifically want Cloudflare's proxy (CDN/WAF): start grey, verify certificates are issued, then switch the SSL/TLS mode to Full (strict) and flip records to orange. If renewal ever misbehaves, reverting to grey is always safe.

Server-side Prerequisites

  • Ports 80 and 443 must be open in the VPS firewall (Let's Encrypt validation uses 80).
  • APP_DOMAIN in infra/.env must match your domain; CADDY_ACME_EMAIL should be a valid address (certificate notifications).

Verification

After the records propagate (usually a few minutes):

# Does DNS resolve?
dig +short chat.<your-domain>

# Certificate issued, service responding?
curl -I https://chat.<your-domain>
curl -I https://<your-domain>          # marketing site

Caddy obtains the certificate on the first request; a few seconds of delay is normal. If something fails, check the tls.obtain lines in docker compose logs caddy on the server.

Troubleshooting

Symptom Check
curl reports a certificate error Is the record orange (proxied)? Switch to grey and wait a few minutes.
tls.obtain ... connection refused Ports 80/443 may be blocked by the firewall.
A subdomain hits the wrong service Check APP_DOMAIN in infra/.env and that Caddy was restarted.