# Change the panel domain

> Move the Falak control plane to a new domain with falak-ctl domain set, keep enrolled agents working via the old agents host, and redirect the old panel.

Source: https://falak.sh/docs/operations/change-domain/

1. Create DNS records for the new names (`falak.new-example.com`, `agents.falak.new-example.com`, `registry.falak.new-example.com`, and `grafana.` if you use observability).
2. Run:

   ```bash
   sudo falak-ctl domain set falak.new-example.com            # or add --keep-old
   ```

3. Keep the **old** `agents.` and `registry.` DNS records pointing at the host.
4. Users of the CLI log in again: `falak login --url https://falak.new-example.com`.

## What the command does

- Takes a backup labelled `pre-domain-change`.
- Rewrites `FALAK_DOMAIN`, `FALAK_URL`, `FALAK_AGENT_API_HOST`, `FALAK_AGENT_API_URL` (and the Grafana and OTLP URLs) in `.env`.
- Re-issues the agent API certificate for `agents.<new>`, keeping the **old agents host as an alias** (`FALAK_AGENT_API_HOST_ALIASES`), because enrolled agents keep calling the host they enrolled with.
- Moves the built-in registry to `registry.<new>`, keeping the **old registry host as an alias** (`FALAK_REGISTRY_HOST_ALIASES`): images of earlier releases are pinned to the old name. A rollback to a release built before the move may need a rebuild, because servers get credentials for the current registry name only.
- With `--keep-old`, redirects the old panel domain to the new one (`FALAK_DOMAIN_ALIASES`).
- Waits until the stack is healthy.

New servers enroll against the new domain.

Update webhook URLs that point at the old domain (git providers, CI deploy hooks), or keep `--keep-old` so the old panel domain keeps answering.
