Skip to content

IP certificates

Defang Agent edited this page Oct 1, 2026 · 2 revisions

IP certificates

Azure Stations use their static public IPv4 address as the primary HTTPS address. The existing sslipDomain parameter accepts a custom DNS suffix (issue #647), including defangstation.com for Defang Station's *.defangstation.com names. Set sslipDomain to defangstation.com without the *. prefix to create <dashed-ip>.defangstation.com. The alias redirects to the IP URL, and Caddy requests an alias certificate only on the first TLS handshake for that name. Leaving sslipDomain empty configures no alias and spends no shared registered-domain certificate quota.

The IP site has its own Caddy TLS policy: Let's Encrypt's shortlived ACME profile, with TLS-ALPN-01 on port 443. Caddy 2.11.4 includes acmez 3.1.6, which supports this challenge for IP identifiers. The NixOS module rejects an IP site on an older Caddy. default_sni selects the IP certificate for clients that omit SNI when connecting to a literal IP address.

Upstream references: Let's Encrypt IP certificate availability, certificate profiles, and Caddy's IP ACME support discussion.

Let's Encrypt's IP certificates last 160 hours. Caddy renews managed certificates automatically. Its data directory is /var/lib/caddy on both backends, so ACME account and certificate state survive service restarts and VM reboots. Port 80 stays closed; both IP and DNS policies disable HTTP-01.

The shared Caddyfile fragments under modules/src/ render through both the NixOS module and native agentbox apply. The web-ip-cert check adapts the real NixOS Caddyfile and inspects the IP and alias policies; native rendering and Azure bootstrap tests cover the same address choices. These checks do not contact Let's Encrypt or prove renewal on a live VM.

Existing DNS-primary boxes remain valid. Their web.domain is a DNS name, so the normal Caddy ACME policy remains in use. The AWS templates keep their sslip.io URL defaults. A box can opt into direct IP service by setting its primary web domain to a public IPv4 address.

Clone this wiki locally