Before you start
- Your app is deployed to a cluster. See Deploy an existing app.
- A domain you control, and access to its DNS records.
- A TLS certificate and private key for the domain, in PEM format.
Ask Monk
Make sure the cluster has an ingress, and see what it serves now:What you review
A form opens in the local dashboard. Enter the domain, then paste or upload the certificate and private key there. You can add several domains, each with its own certificate and key. Submitting the form is your approval. The certificate and key never pass through the chat.Point DNS at the cluster
Create a DNS record at your DNS provider that points the domain at the cluster. Ask Monk for the address to use:What you get
The cluster’s ingress serves your domain with your certificate. Requests are matched to the right certificate by domain name.Renewing and resetting
- Your certificate is expiring. Ask Monk to set the certificate again and upload the new one in the form.
- A Monk-managed certificate has expired (for example, image pushes fail with an x509 error):
/monk reset the certificate on this node. This does not apply to custom domains. - To stop using your certificate:
/monk clear the ingress certificate. The ingress goes back to its default certificate.

