Cosmic custom domains: certificate issuance fails internally
anderegurrola
HOBBYOP

25 days ago

Our production service cosmic-app is healthy at https://cosmic-app-production.up.railway.app. We are moving traffic from a Netlify proxy to Railway directly because the proxy intermittently times out while the same Railway URL responds in about 0.3 seconds.

The custom apex domain cosmicleads.net was created on September 11, 2026 at about 01:24 UTC. Certificate issuance now reports:

  • CERTIFICATE_STATUS_TYPE_ISSUE_FAILED
  • CERTIFICATE_ERROR_TYPE_INTERNAL
  • An internal error occurred. Please retry or contact support.

The apex ownership TXT is verified. A short trial with the required dynamic ALIAS to 9azmwmah.up.railway.app was confirmed propagated by Railway and public resolvers, but HTTPS continued serving a certificate that did not match our hostname. We restored the previous apex route to avoid leaving production with invalid TLS. The apex currently points to Netlify again, so its traffic DNS is intentionally not yet on Railway.

The custom wildcard *.cosmicleads.net, created around 01:27 UTC, remains ISSUING / POLLING_AUTHORIZATIONS. Its CNAME to wpztu7ks.up.railway.app, ownership TXT, and _acme-challenge CNAME to wpztu7ks.authorize.railwaydns.net are all in place. Both traffic and challenge records show propagated. The wildcard traffic record was added around 01:49 UTC. The challenge TXT resolves through public resolvers. There are no restrictive CAA records and no DS record for the domain. We requested wildcard issuance once after all required records propagated.

Could Railway staff investigate the certificate error and confirm how to pre-provision the apex certificate for this migration without leaving the production domain on an invalid certificate? Please also check whether wildcard certificate issuance is progressing normally. We have not repeatedly deleted and recreated either current domain.

The service uses the Hobby plan. We can provide project and service IDs directly to Railway staff if needed.

Solved

1 Replies

Status changed to Awaiting Railway Response Railway • 25 days ago


sam-a
EMPLOYEE

25 days ago

Both certificates have been issued and are valid. The apex domain's certificate status is now CERTIFICATE_STATUS_TYPE_VALID, and the wildcard certificate has also completed issuance successfully. The ACME DNS-01 delegation for the wildcard is healthy.

The apex currently resolves to our edge and returns a 200 with valid TLS, so you should be able to proceed with your migration. If you encounter the ISSUE_FAILED state again after a future DNS change, the service's Settings page will show a "Try Again" button on the domain row that starts a fresh certificate order.


Status changed to Awaiting User Response Railway • 25 days ago


Status changed to Solved sam-a • 25 days ago


Welcome!

Sign in to your Railway account to join the conversation.

Loading...