DNS for the control plane
Create these records before you install. Replace the IP with your host’s public address; add AAAA records if the host has IPv6.
| Name | Type | Value | Why |
|---|---|---|---|
falak.example.com |
A (and/or AAAA) | 203.0.113.10 |
Panel, installer script, agent enrollment, API, webhooks |
agents.falak.example.com |
A (and/or AAAA) | 203.0.113.10 |
Agent API (mutual TLS) |
registry.falak.example.com |
A (and/or AAAA) | 203.0.113.10 |
Built-in image registry: Docker builds push, servers pull |
grafana.falak.example.com |
A (and/or AAAA) | 203.0.113.10 |
Only with --observability |
Certificates per host
Section titled “Certificates per host”- The panel, the registry and Grafana get Let’s Encrypt certificates automatically (HTTP-01 / TLS-ALPN-01 on ports 80/443).
- The agents host does not use Let’s Encrypt. Agents pin Falak’s own Fleet CA, so the edge serves that host with a certificate issued by the Fleet CA and verifies the agents’ client certificates against it.
Checks
Section titled “Checks”- The installer checks that every name resolves to this host’s public IP and prints missing records. Skip with
--skip-dns-check. falak-ctl doctorshows the host’s public IPv4/IPv6 and checks each name again.
dig +short falak.example.com agents.falak.example.com registry.falak.example.com grafana.falak.example.comYour apps’ domains
Section titled “Your apps’ domains”Domains for the apps you deploy are separate: they point at your servers (or load balancers), not at the control plane. See Domains.
Changing the domain later
Section titled “Changing the domain later”Use falak-ctl domain set. Keep the old agents record pointing at the host: enrolled agents keep calling the host they enrolled with. Keep the old registry record too: images of earlier releases are pinned to the old name. See Change the domain.