Setting custom_domain is validated for syntax only — validate_custom_domain (lnvps_api/src/api/apps.rs:816, tests at :1124) rejects ports, paths, schemes and malformed labels, and nothing resolves the name. The operator then adds the rule and a second TLS block with its own issuer annotation unconditionally (custom-domain branch of build_ingress, lnvps_operator/src/app_deployments.rs:882).
A customer who sets a domain before pointing it at us gets an ingress rule that cannot serve and an HTTP-01 challenge that cannot be solved, retried on every reconcile. Let's Encrypt counts failed validations against a separate limit, and the deployment carries a permanently pending certificate with no signal about why.
Wanted
DNS-probe the custom domain before creating its ingress rule or requesting its certificate.
- Probe at set time, and re-probe on reconcile for a domain that is held rather than refused.
- Only add the rule and the TLS block once the name resolves to us.
- Surface pending-DNS vs live to the customer. The silent pending certificate is the failure this fixes.
Open, for whoever picks it up: refuse at set time or accept-and-hold — holding is kinder to a customer who sets the domain before the CNAME. And the expected record needs stating in the customer-facing copy.
Sequenced with #306: same function, same file, separate PRs — this one changes customer-visible behaviour and #306 does not.
Setting
custom_domainis validated for syntax only —validate_custom_domain(lnvps_api/src/api/apps.rs:816, tests at:1124) rejects ports, paths, schemes and malformed labels, and nothing resolves the name. The operator then adds the rule and a second TLS block with its own issuer annotation unconditionally (custom-domain branch ofbuild_ingress,lnvps_operator/src/app_deployments.rs:882).A customer who sets a domain before pointing it at us gets an ingress rule that cannot serve and an HTTP-01 challenge that cannot be solved, retried on every reconcile. Let's Encrypt counts failed validations against a separate limit, and the deployment carries a permanently pending certificate with no signal about why.
Wanted
DNS-probe the custom domain before creating its ingress rule or requesting its certificate.
Open, for whoever picks it up: refuse at set time or accept-and-hold — holding is kinder to a customer who sets the domain before the CNAME. And the expected record needs stating in the customer-facing copy.
Sequenced with #306: same function, same file, separate PRs — this one changes customer-visible behaviour and #306 does not.