Skip to main content
Getting traffic to an app means an ingress, DNS, certificates and a network between your machines. Monk sets up the ingress when it creates a cluster, serves your services over HTTPS, and joins your nodes on an encrypted network.

What you can do

Route traffic with an ingress

Each cluster runs an ingress built on Traefik, on ports 80 and 443. A web-facing service declares ingress routes in its template and the ingress sends matching requests to it. Monk can check the ingress and turn it back on if it was switched off. How: In your Monk config, where your coding agent writes the routes and deploys after a plan review. Ask Monk to check the ingress. See Networking.

Get a domain and certificate from Monk

A cluster node can get a domain managed by Monk, with a certificate issued by the platform. You have a working HTTPS address before you set up your own domain. If that certificate expires, Monk can request a fresh one. How: Ask Monk. See Networking.

Use your own domain

Add your domain and certificate through a form. You can add several domains, each with its own certificate and private key, and the ingress picks the right one by domain name. You point your domain’s DNS at the cluster yourself, or manage it with a DNS integration. How: Ask Monk; you enter the certificate and key in the local dashboard form, and submitting it is your approval. See Custom domain and HTTPS.

Connect nodes across clouds

Every node joins an encrypted WireGuard network with the others, including nodes on different clouds. Services reach each other over it through connections declared in your templates. There is nothing to configure. How: Automatic when nodes join. See Networking.

Add a cloud load balancer

A group template can ask for a cloud load balancer in front of a service, on any of the five clouds, for HTTP, HTTPS, TCP or UDP traffic, or a static IP address. How: In your Monk config; the next deploy creates it after you review the plan. See Networking.

See what Monk creates in the cloud

When Monk creates nodes, it also creates the network pieces they need: a VPC, subnet and security group on AWS, firewall rules on GCP, DigitalOcean and Hetzner, and a virtual network on Azure. How: Part of cluster creation, which you approve in the local dashboard. See Clusters and clouds.

Try it

Good to know

  • Nodes get public IP addresses. Private subnets behind a NAT gateway aren’t supported.
  • Monk doesn’t switch your DNS for you.
  • If the ingress isn’t available at deploy time, Monk reports it and doesn’t fall back to plain ports.

Custom domain and HTTPS

Serve your app on your own domain

Networking

Ingress, certificates and the network between nodes