a month ago
Project: bubbly-radiance (id 4027c115-f49f-4645-bc51-a4a8ba87aa21)
Service: wayner (id c49de997-ec5f-4c7f-aa0d-4e117ee5d61c)
Environment: production (id f8971ae8-23f5-4c0b-bc93-245dc548e1e7)
Custom domains wayner.ai and www.wayner.ai have been stuck at CERTIFICATE_STATUS_TYPE_VALIDATING_OWNERSHIP since 07:24 UTC Sep 2 (re-created 07:38 UTC in case the first attempt was wedged - same state since).
What I've verified on my side:
- DNS has matched the required targets for 12+ hours, DNS-only at Cloudflare: wayner.ai CNAME ek5btbeg.up.railway.app (flattened at apex, resolving to Railway IPs), www.wayner.ai CNAME 81yynql3.up.railway.app. Your API's dnsRecords report PROPAGATED for both.
- No CAA records on the zone; nameservers are Cloudflare's.
- Requests with Host: wayner.ai to your edge return 404 (routing inactive), while the generated domain wayner-production.up.railway.app on the same edge serves 200 - so the app is healthy, the custom domain just never activated.
- No certificateErrorMessage or certificateStatusDetailed is exposed via the GraphQL API, so I can't tell what validation is waiting on.
- Status page shows no incident. Domains currently sit behind a Cloudflare proxy (gray -> orange cloud this morning) so ACME HTTP-01 traffic still reaches your edge; the stall predates that change by ~11 hours.
Could you check what's blocking issuance and/or force the validation through? Happy to flip back to DNS-only if your validator needs the raw CNAME.
1 Replies
a month ago
Both custom domains are showing verified=false because neither has its TXT ownership-verification record published. Custom domains require both a CNAME for traffic routing and a TXT record for ownership verification, and certificates will not issue until both are in place. The CNAME for the apex domain is propagated, but the second domain's CNAME is not yet resolving (status REQUIRES_UPDATE), so that one needs its CNAME confirmed as well. You can find the exact TXT record hostnames and values for each domain under the domain's settings in the Networking section of your service, then add those as TXT records at your DNS provider. Once the TXT records propagate, verification will complete and certificate issuance will proceed automatically.
Status changed to Awaiting User Response Railway • about 1 month ago
a month ago
This thread has been marked as solved automatically due to a lack of recent activity. Please re-open this thread or create a new one if you require further assistance. Thank you!
Status changed to Solved Railway • 26 days ago