GCP DNS & Domains
Provider-specific DNS configuration and SSL certificate setup for GCP deployments.
Overview
GCP uses a Global HTTPS Load Balancer with a static IP. All domains (API, frontends, redirects) point to this single IP via A records. SSL certificates are managed by Certificate Manager with DNS authorization.
Finding the Load Balancer IP
After running infra:deploy-lb, the CLI displays the Load Balancer IP. To find it in the console:
- Go to Network services > Load balancing
- Click on your load balancer (named
{projectName}-lb) - The Frontend section shows the static IP address
Alternatively: VPC network > IP addresses > look for {projectName}-lb-ip
DNS Records
Point all your domains to the Load Balancer IP with A records:
For redirect domains on a separate TLD (e.g., example.io redirecting to example.com), add an A record in that domain's DNS zone:
Most domain registrars automatically append your domain to the host field. Enter only the relative part — e.g., api instead of api.example.com. Using the full domain name would create a record at api.example.com.example.com, which is incorrect. For the root domain, use @ or leave the host field blank.
Create these records at your domain registrar.
SSL Certificate Validation
GCP uses Certificate Manager with DNS authorization. Each domain needs a CNAME record for validation.
Finding Validation Records
- Search for Certificate Manager in the GCP console search bar
- In the Certificates tab, click on each certificate (one per domain/subdomain)
- The certificate detail page shows the CNAME record:
- DNS Record Name — the full domain (e.g.,
_acme-challenge.api.example.com) - DNS Record Type — always
CNAME - DNS Record Data — the value to point to (e.g.,
abc123...authorize.certificatemanager.goog.)
- DNS Record Name — the full domain (e.g.,
- Repeat for every certificate — each domain and subdomain has its own
- At your registrar, create CNAME records using only the relative host — drop your base domain from the name. For example,
_acme-challenge.api.example.combecomes_acme-challenge.api
Example Records
For a domain example.com, the registrar entries would be:
The CLI outputs fully qualified domain names (e.g., _acme-challenge.api.example.com). When entering these at your registrar, drop the base domain suffix — enter _acme-challenge.api instead of _acme-challenge.api.example.com. Most registrars auto-append your domain, so using the full name would create a record at _acme-challenge.api.example.com.example.com.
For redirect domains on a separate TLD, create the CNAME in that domain's DNS zone. For example, if example.io is a redirect domain, add the CNAME record in the example.io DNS zone with host _acme-challenge.
Checking Certificate Status
- Search for Certificate Manager in the GCP console search bar
- Click the Certificates tab, then click on your certificate (named
{projectName}-cert) - Status should be ACTIVE once DNS records propagate (can take up to 60 minutes)
- If stuck on PROVISIONING, verify your CNAME records are correctly set
Redirect Domains
To redirect alternate domains (e.g., .io, .app) to your canonical domain:
- Add redirect domains to
infrastructure.json: - Deploy:
npx tsdevstack infra:deploy-lb --env prod - At each redirect domain's registrar, add:
- A record
@→ Load Balancer IP (same IP as your main domain) - CNAME record for SSL validation — use the values printed by the CLI
- A record
Each redirect domain (e.g., example.com, example.app) requires records configured at that domain's registrar, not your main domain's registrar. The infra:deploy-lb command prints all required records for every domain including redirects.
Troubleshooting
SSL Certificate Not Provisioning
- Check CNAME host names — the most common mistake is entering the full domain name in the registrar's host field. Use relative names (e.g.,
_acme-challenge.api, not_acme-challenge.api.example.com). You can verify with: - Verify A records are also pointing to the Load Balancer IP
- Check that the CNAME value matches exactly what Certificate Manager shows
- Wait for DNS propagation (can take up to 48 hours for some registrars)
- After fixing DNS, redeploy to refresh:
npx tsdevstack infra:deploy-lb --env prod