Domain Setup
Configuring domains for tsdevstack deployments.
Overview
All domains route through the load balancer, which directs traffic based on hostname:
Required Secrets
Before deploying, set the base domain:
API_URL and KONG_CORS_ORIGINS are auto-derived during cloud-secrets:push from DOMAIN and the domains configured in .tsdevstack/infrastructure.json -- you do not need to set them manually.
Note: All secrets can also be set directly in your cloud provider's console (GCP Secret Manager, AWS Secrets Manager, Azure Key Vault). The CLI commands are a convenience wrapper.
Frontend Domains
Configure frontend domains in .tsdevstack/infrastructure.json:
Services are configured directly at the environment level (not nested under a services key).
Backend services (NestJS) don't need domains - they're accessed via Kong.
Deployment Order
- Set secrets (
DOMAIN—API_URLandKONG_CORS_ORIGINSare auto-derived) - Configure domains in
infrastructure.json - Set up DNS (provider-specific — see below)
- Deploy infrastructure —
npx tsdevstack infra:deploy --env prod - Wait for SSL (varies by provider)
DNS Setup
DNS configuration differs by cloud provider:
Follow your provider's DNS guide:
- GCP DNS & Domains — manual A records + SSL validation CNAMEs at your registrar
- AWS DNS & Domains — move nameservers to Route 53, everything else is automated
- Azure DNS & Domains — move nameservers to Azure DNS, everything else is automated
When setting up DNS, this is also a good time to add the Resend email verification records (DKIM, SPF, DMARC). See Resend setup.
Checking Deployment Info
If you need to retrieve deployment details (IPs, DNS records, certificate status) after deployment, check your provider's console:
- GCP: Load Balancing for IP address, Certificate Manager for SSL validation records
- AWS: Route 53 for DNS records, ACM for certificate status, CloudFront for distribution domains
- Azure: DNS zones for nameservers, Front Door for custom domain status and TLS certificates
Adding a New Domain
To add a new frontend app with its own domain:
- Add the service to
config.json - Add domain to
.tsdevstack/infrastructure.json: - Deploy the service:
npx tsdevstack infra:deploy-service new-app --env prod - Update Load Balancer:
npx tsdevstack infra:deploy-lb --env prod - Add DNS records (A record + SSL validation record)
- Run
npx tsdevstack cloud-secrets:push --env prodto update auto-derived secrets (KONG_CORS_ORIGINSwill include the new domain automatically)
Domain Redirects
To redirect alternate domains (e.g., .app, .io) to your canonical domain, configure redirects in infrastructure.json:
All traffic to redirect domains (and their subdomains) will 301 redirect to the canonical domain.
Troubleshooting
SSL Certificate Not Provisioning
- GCP: Check that A records and SSL validation CNAMEs are correct at your registrar. Enter relative host names (e.g.,
api), not full domain names. See GCP DNS & Domains. - AWS: Check that nameservers at your registrar point to Route 53. Run
dig NS example.com +shortto verify. See AWS DNS & Domains. - Azure: Check that nameservers at your registrar point to Azure DNS. See Azure DNS & Domains.
DNS propagation can take up to 48 hours. After fixing DNS, redeploy: npx tsdevstack infra:deploy --env prod
Wrong Domain Configuration
If you set the wrong domain in secrets or infrastructure.json:
- Fix the configuration
- Redeploy:
npx tsdevstack infra:deploy --env prod - For GCP, update DNS records at your registrar with the new values
CORS Errors
If frontend apps can't call the API:
- Verify all frontend domains are configured in
.tsdevstack/infrastructure.json--KONG_CORS_ORIGINSis auto-derived from these entries - Re-push secrets to regenerate
KONG_CORS_ORIGINS: - Redeploy Kong: