Skip to content

DNS for the control plane

Create these records before you install. Replace the IP with your host’s public address; add AAAA records if the host has IPv6.

Name Type Value Why
falak.example.com A (and/or AAAA) 203.0.113.10 Panel, installer script, agent enrollment, API, webhooks
agents.falak.example.com A (and/or AAAA) 203.0.113.10 Agent API (mutual TLS)
registry.falak.example.com A (and/or AAAA) 203.0.113.10 Built-in image registry: Docker builds push, servers pull
grafana.falak.example.com A (and/or AAAA) 203.0.113.10 Only with --observability
  • The panel, the registry and Grafana get Let’s Encrypt certificates automatically (HTTP-01 / TLS-ALPN-01 on ports 80/443).
  • The agents host does not use Let’s Encrypt. Agents pin Falak’s own Fleet CA, so the edge serves that host with a certificate issued by the Fleet CA and verifies the agents’ client certificates against it.
  • The installer checks that every name resolves to this host’s public IP and prints missing records. Skip with --skip-dns-check.
  • falak-ctl doctor shows the host’s public IPv4/IPv6 and checks each name again.
Terminal window
dig +short falak.example.com agents.falak.example.com registry.falak.example.com grafana.falak.example.com

Domains for the apps you deploy are separate: they point at your servers (or load balancers), not at the control plane. See Domains.

Use falak-ctl domain set. Keep the old agents record pointing at the host: enrolled agents keep calling the host they enrolled with. Keep the old registry record too: images of earlier releases are pinned to the old name. See Change the domain.