# DNS for the control plane

> The panel, agents, registry and Grafana DNS records Falak's control plane needs, why they must not be proxied, and how falak-ctl doctor checks them.

Source: https://falak.sh/docs/operations/dns/

Create these records **before** you install. Replace the IP with your host's public address; add AAAA records if the host has IPv6.

| Name | Type | Value | Why |
|---|---|---|---|
| `falak.example.com` | A (and/or AAAA) | `203.0.113.10` | Panel, installer script, agent enrollment, API, webhooks |
| `agents.falak.example.com` | A (and/or AAAA) | `203.0.113.10` | Agent API (mutual TLS) |
| `registry.falak.example.com` | A (and/or AAAA) | `203.0.113.10` | [Built-in image registry](/docs/operations/install/#the-built-in-image-registry): Docker builds push, servers pull |
| `grafana.falak.example.com` | A (and/or AAAA) | `203.0.113.10` | Only with `--observability` |

## Certificates per host

- The **panel**, the **registry** and **Grafana** get Let's Encrypt certificates automatically (HTTP-01 / TLS-ALPN-01 on ports 80/443).
- The **agents** host does **not** use Let's Encrypt. Agents pin Falak's own **Fleet CA**, so the edge serves that host with a certificate issued by the Fleet CA and verifies the agents' client certificates against it.

Set all these records to **DNS only** (grey cloud). A proxy terminates TLS: the agents' mutual TLS breaks, and Let's Encrypt HTTP-01 may fail.

## Checks

- The installer checks that every name resolves to this host's public IP and prints missing records. Skip with `--skip-dns-check`.
- `falak-ctl doctor` shows the host's public IPv4/IPv6 and checks each name again.

```bash
dig +short falak.example.com agents.falak.example.com registry.falak.example.com grafana.falak.example.com
```

## Your apps' domains

Domains for the apps you deploy are separate: they point at your **servers** (or load balancers), not at the control plane. See [Domains](/docs/guides/domains/).

## Changing the domain later

Use `falak-ctl domain set`. Keep the **old agents record** pointing at the host: enrolled agents keep calling the host they enrolled with. Keep the **old registry record** too: images of earlier releases are pinned to the old name. See [Change the domain](/docs/operations/change-domain/).
