a month ago
A custom domain on one of my services has been stuck issuing its certificate for about two days, and your own API reports the DNS as propagated and correct, so I think something is wedged on the certificate side rather than mine.
Details:
Project: growth-engine (1bfa8629-986f-49ba-af73-69114b1a95b3)
Environment: production (76f84a53-2757-4100-94e6-f5351b16aa7e)
Service: growth-agent (3e208771-e0ec-4679-9661-42ebf7052850)
Domain: go.locallayer.io
Current custom domain id: 21134fa5-4e65-46f1-9933-2d78f4941102
What the API reports right now:
dnsRecords: currentValue "loucaajd.up.railway.app", requiredValue "loucaajd.up.railway.app", status DNS_RECORD_STATUS_PROPAGATED
certificateStatus: CERTIFICATE_STATUS_TYPE_VALIDATING_OWNERSHIP
Timeline:
- Aug 23, afternoon: added go.locallayer.io to the service and pointed the CNAME at zbrq8gpw.up.railway.app at my registrar (Namecheap).
- Aug 23, evening: DNS fully propagated, confirmed at the authoritative nameservers and at 1.1.1.1 and 8.8.8.8. Certificate stayed in VALIDATING_OWNERSHIP.
- Aug 24, early: still no certificate after 12 hours. Called customDomainIssueCertificate on the domain id, which returned true. No change.
- Aug 24, morning: deleted the custom domain and recreated it to force a clean validation. That minted a new target, loucaajd.up.railway.app. I updated the CNAME at the registrar and it propagated within 90 seconds, verified again at the authoritative nameservers and at public resolvers.
- Aug 24 through Aug 25: the certificate has now been in VALIDATING_OWNERSHIP for roughly 24 more hours on the fresh domain. Called customDomainIssueCertificate again, returned true, no change.
Other things I checked so it is not the usual suspects:
There are no CAA records anywhere on locallayer.io, so nothing is blocking Let's Encrypt.
A TLS handshake to the edge with SNI go.locallayer.io returns your wildcard *.up.railway.app certificate, so traffic is reaching Railway, there just is no certificate for the custom domain.
The service itself is healthy and serving fine on its railway.app domain.
Could you check what is blocking validation for this domain on your side, or tell me what you need from me? Happy to run anything you want against the API.
1 Replies
a month ago
The domain is stuck because the TXT ownership-verification record is missing. Your CNAME is correctly propagated, but the verification TXT record has not been added. Per the custom domain setup docs, both a CNAME record and a TXT verification record are required. Add a TXT record at the verification hostname shown in your service's Settings under Networking, with the token value displayed there, and once it propagates the domain will verify and the certificate will issue.
Status changed to Awaiting User Response Railway • about 1 month ago
a month ago
This thread has been marked as solved automatically due to a lack of recent activity. Please re-open this thread or create a new one if you require further assistance. Thank you!
Status changed to Solved Railway • about 1 month ago