> ## Documentation Index
> Fetch the complete documentation index at: https://docs.monk.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Custom domain and HTTPS

> Serve your app on your own domain with your TLS certificate

Cluster nodes can use a Monk-managed domain and certificate. Use this guide to serve your app on your own domain with your own certificate.

## Before you start

* Your app is deployed to a cluster. See [Deploy an existing app](/guides/deploy-existing-app).
* A domain you control, and access to its DNS records.
* A TLS certificate and private key for the domain, in PEM format.

## Ask Monk

Make sure the cluster has an ingress, and see what it serves now:

```
/monk check the ingress on this cluster
```

Then add your domain:

```
/monk serve the app on app.example.com
```

To use a certificate on one node only, rather than for the whole cluster, say which node:

```
/monk set a custom domain and certificate on the node that runs the frontend
```

## What you review

A form opens in the [local dashboard](/getting-started/local-dashboard). Enter the domain, then paste or upload the certificate and private key there. You can add several domains, each with its own certificate and key. Submitting the form is your approval. The certificate and key never pass through the chat.

## Point DNS at the cluster

Create a DNS record at your DNS provider that points the domain at the cluster. Ask Monk for the address to use:

```
/monk what address should app.example.com point to?
```

If your DNS is hosted on Cloudflare, DigitalOcean or a cloud provider Monk supports, you can ask for the record to be part of the plan instead. See the [integrations catalog](https://monk.io/integrations).

## What you get

The cluster's ingress serves your domain with your certificate. Requests are matched to the right certificate by domain name.

```
/monk which domains does the ingress serve?
```

## Renewing and resetting

* **Your certificate is expiring.** Ask Monk to set the certificate again and upload the new one in the form.
* **A Monk-managed certificate has expired** (for example, image pushes fail with an x509 error): `/monk reset the certificate on this node`. This does not apply to custom domains.
* **To stop using your certificate:** `/monk clear the ingress certificate`. The ingress goes back to its default certificate.

## Next

* [CI/CD](/guides/cicd)
* [Networking](/concepts/networking)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.