Domains
Attach a hostname, publish its TXT ownership record, then verify DNS.
Surface contract
Primary object: workspace domain bindings: hostname, DNS ownership status and the required TXT record.
Actions
- Add domainCreates a pending binding through POST /v1/domains (owner/admin only) and shows the DNS record the server expects; the domain serves no traffic until Verify succeeds.
- VerifySends POST /v1/domains/{id}/verify, which checks the TXT record using the server’s DNS resolver. A missing record keeps verification pending and shows the server’s reason.
- DetachSends DELETE /v1/domains/{id} after confirmation; traffic stops with the binding and the hostname becomes free to attach elsewhere.
Required states and how this surface reaches them
- loading
- the session probe and each list show Loading… until the control plane answers.
- ready
- the server’s own records render as returned; the primary object is named before its details.
- empty
- no domain is attached; Add domain sends POST /v1/domains with the hostname and the server creates the pending record.
- error
- a hostname the deployment refuses (platform host, malformed, or duplicate) keeps the server’s own detail and the typed value is preserved by the dialog.
- offline
- no control plane is reachable; nothing is rendered rather than invented.
- permission_denied
- a 401 returns to sign-in with this path; a 403 states that the role cannot read this surface.
- not_configured
- a 503 names the missing provider or secret; setup is shown, never fake results.
- budget_paused
- a 402 (quota_exceeded / upgrade_required) pauses spending; the budget row shows the cap and consumption that caused it.
- requires_approval
- mutations the server reserves for an explicit human owner/admin are refused with its own detail and never auto-approved here.
Publish the exact TXT name and value at your DNS provider, then select Verify. DNS propagation can take time. Certificate provisioning is separate.
Domains
checkingLoading…
Rows come from the authenticated control plane; this page never renders placeholder records. Actions report the server's own response, including refusals.