Production custom domain TLS reset despite ACTIVE/VALID status — force edge re-attach
talsinger
HOBBYOP

a month ago

Our production domain s unavailable because Railway resets the TLS connection before presenting a certificate.

How do you resolve? Please force re-sync/re-attach the custom-domain TLS certificate and hostname routing entry on the Railway edge, currently lhr1.

Railway reports:

  • syncStatus: ACTIVE
  • DNS: PROPAGATED
  • Ownership: verified
  • Certificate: VALID
  • Certificate detail: COMPLETE

DNS is correct at the authoritative Porkbun nameservers. The Railway verification TXT is present and exact. There is no conflicting A, AAAA, CNAME, CAA, or DNSSEC record.

A successful redeployment after the domain was attached did not repair the issue. Certificate retry is unavailable because Railway reports the certificate as valid.

I would like to repair/re-publish the url SNI certificate and hostname-to-service route on the edge. I do not want to delete or recreate the domain, because that would rotate the DNS target again.

Solved

1 Replies

Railway
BOT

a month ago

Our probe of the domain just now shows the TLS certificate (Let's Encrypt, valid for the hostname) is being presented and accepted, the edge routes are installed (no fallback), and the application itself is responding with HTTP 401. From the platform side, DNS, certificate, verification, and routing all read healthy, so there is no wedged state to re-attach. The 401 is coming from the application, not from the edge.


Status changed to Awaiting User Response Railway • about 1 month ago


Railway
BOT

a month ago

This thread has been marked as solved automatically due to a lack of recent activity. Please re-open this thread or create a new one if you require further assistance. Thank you!

Status changed to Solved Railway • about 1 month ago


Welcome!

Sign in to your Railway account to join the conversation.

Loading...