Request: second custom domain (www.evfreedom.energy) on trial plan for TLS on www subdomain
ceonickk
HOBBYOP

12 hours ago

Hi Railway team,

I'm on the Trial plan (workspace "charismatic-optimism", service "ev-freedom-pass" — my dashboard shows "30 days or $4.99 left"). The trial plan allows only one custom domain, which is already used by evfreedom.energy.

I need to add www.evfreedom.energy as a second custom domain so visitors get a valid TLS certificate. Right now, https://www.evfreedom.energy shows a browser "connection is not private" warning. In the service's Settings → Networking, the "Custom Domain" button is disabled with the message: "You have hit the custom domain limit for your plan. Please upgrade to add more."

Could you please grant a one-time exception to add the second custom domain on the trial plan, or advise any free way to get a valid certificate on www?

Thank you!

Awaiting User Response

6 Replies

Railway
BOT

12 hours ago

The Trial plan is limited to 1 custom domain, so the root domain and its www subdomain can't both be added there, since they count as two separate custom domains. The Hobby plan allows 2 custom domains per service, which covers both.

To stay on your current plan, our docs describe a setup where Cloudflare handles the www subdomain: you add only the root domain on Railway, proxy both it and a www CNAME through Cloudflare, and use a Cloudflare Bulk Redirect to send www traffic to the root with a 301. Cloudflare then serves its own certificate for www. The full steps are in Adding a root domain with www subdomain to Cloudflare.


Status changed to Awaiting User Response Railway • about 12 hours ago


ceonickk
HOBBYOP

12 hours ago

Resolved — thank you! I upgraded the workspace to the Hobby plan and added www.evfreedom.energy as a second custom domain on the ev-freedom-pass service. DNS is updated (CNAME + _railway-verify TXT records). The exception request is no longer needed.


Status changed to Awaiting Railway Response Railway • about 12 hours ago


Status changed to Solved Railway • about 12 hours ago


ceonickk
HOBBYOP

11 hours ago

Hi Railway team — following up on this thread. I upgraded the workspace to the paid Hobby plan (invoice paid today) and added www.evfreedom.energy as a second custom domain on the ev-freedom-pass service.

The apex domain evfreedom.energy works fine over HTTPS, and I've verified at my registrar that DNS is correct: the www CNAME points to gv0jfwtl.up.railway.app.

However, the TLS certificate for www.evfreedom.energy has been stuck in "Certificate Authority is validating challenges" for several hours, and clients still can't reach the site on www. Could you please check on the validation, retry it, or manually verify the challenge so the certificate can be issued? I'd really appreciate any help expediting this. Thank you!


Status changed to Awaiting Railway Response Railway • about 11 hours ago


Railway
BOT

11 hours ago

Your www record isn't pointing at the right target yet. The CNAME currently resolves to gv0jfwtl.up.railway.app, but each custom domain gets its own CNAME target, and the www domain you added needs a different one. gv0jfwtl is most likely your apex domain's target.

Open the www domain in the ev-freedom-pass service's Settings → Networking. Copy the CNAME target it shows for that domain, and update the www CNAME at your registrar to match it exactly. Your verification TXT record is already correct and the domain shows as verified. Once the corrected CNAME propagates, certificate issuance continues on its own, so you don't need to remove and re-add the domain.


Status changed to Awaiting User Response Railway • about 11 hours ago


ceonickk
HOBBYOP

6 hours ago

Hi Railway team — following up on the stalled TLS certificate for www.evfreedom.energy with what I verified just now in the dashboard (Settings → Networking for the ev-freedom-pass service):

DNS is already correct per Railway's own docs. At my registrar (Namecheap) the www record is a CNAME pointing to gv0jfwtl.up.railway.app. The dashboard shows no www-specific CNAME target — the only DNS target the service exposes is the root domain's (CNAME gv0jfwtl.up.railway.app), which is exactly what www is pointing to. Per Railway's documentation, the www CNAME should point at the same service target, so www is resolving to the correct target.

The certificate is still not issuing. The www domain was added around 4:30 AM Pacific (5+ hours ago) and clients still can't establish TLS to https://www.evfreedom.energy. The dashboard currently shows "Failed to issue TLS certificate" for www.evfreedom.energy — "An internal error occurred. Please retry or contact support." — while the apex domain evfreedom.energy's certificate is healthy and the site serves fine over HTTPS on the root.

Since DNS is verified correct and the dashboard offers no working remediation, could you please investigate why issuance is stalled on your side and re-trigger / manually provision the certificate for www.evfreedom.energy?

Thank you!


Status changed to Awaiting Railway Response Railway • about 6 hours ago


Railway
BOT

6 hours ago

We checked the www domain directly, and it is set up with its own CNAME target, which is different from the one your apex domain uses. Public DNS still shows the www record pointing at the apex domain's target, so the certificate cannot issue while it stays that way.

In the ev-freedom-pass service's Settings → Networking, open the DNS records for the www domain itself rather than the root domain, copy the CNAME value shown there, and replace the current value of the www CNAME at Namecheap with it. Your verification TXT record is already correct and the domain shows as verified, so only the CNAME needs to change. There's no need to remove and re-add the domain.


Status changed to Awaiting User Response Railway • about 6 hours ago


Welcome!

Sign in to your Railway account to join the conversation.

Loading...