2 hours ago
Our Design platform's apex getdesign.hu serves trusted HTTPS, but the certificate
for *.getdesign.hu has repeatedly failed with an internal Railway error. This
blocks administration and customer workspace HTTPS. The shared ingress service
is healthy; all workspace traffic is intended to use shared application services.
This is a certificate issuance problem, before application HTTP routing.
1 Replies
2 hours ago
Your _acme-challenge CNAME points at the correct target, but Cloudflare's authoritative nameservers are serving conflicting certificate challenge values. When asked for TXT records on that name, both nameservers return two TXT values that don't match any value currently published at our delegation target, so the certificate authority can't get the expected token and validation fails. The generic "internal error" message on the certificate doesn't change this.
Cloudflare needs to resolve that DNS conflict. These values don't show up as editable records in your zone, so they're likely TXT records that Cloudflare manages for its own edge certificates (Universal, Advanced or backup), which can stay hidden from the dashboard. You can see the mismatch by running a non-recursive TXT query for the challenge name against your Cloudflare nameservers and comparing the result with the TXT at the delegation target shown in your domain settings. Cloudflare support can then identify and remove the conflicting records.
Recreating the CNAME or retrying issuance won't help until Cloudflare stops serving those values. Once it does, the certificate needs a fresh issuance attempt, because the failed attempt can't succeed on its own.
Status changed to Awaiting User Response Railway • about 2 hours ago