domain
Serve your application from your own domain with automated edge TLS — no manual certificate requests, validation emails, or CloudFront console edits.
What it does
Section titled “What it does”domain add <domain>provisions an ACM TLS certificate inus-east-1(required by CloudFront) and wires it into your distribution’saliasesandviewer_certificate.- With
--zone-id <id>, validation and routing are fully automated: grada creates the ACM validation records plus apexA/AAAAalias records in your Route 53 hosted zone, then binds the certificate to CloudFront in a singleapply. - Without
--zone-id, you get a guided 2-step flow for external DNS providers (Cloudflare, Namecheap):domain addstages the certificate,domain statusshows the exact CNAME records to paste, anddomain verifyactivates the domain once DNS is in place. domain statusshows the configured domain, its mode, whether CloudFront is wired, and a copy-paste DNS record table.domain removedeletes the domain configuration and restores the free*.cloudfront.netdefault certificate.- PR preview workspaces are unaffected: domain resources are scoped to the production workspace, so previews keep serving over their own
*.cloudfront.netURL and teardowns never touch your certificate, aliases, or DNS. - Domain configuration lives in
terraform/domain.tf, sodestroytears it down andejectkeeps it automatically. - Emits a
domain_runtelemetry event recording the subcommand and outcome.
# Route 53, fully automated (one step)npx grada-run domain add example.com --zone-id Z1234567890ABCnpx grada-run apply
# External DNS, guided (two steps)npx grada-run domain add example.comnpx grada-run apply# add the printed CNAMEs at your DNS provider, then:npx grada-run domain verifynpx grada-run apply
# Inspect or removenpx grada-run domain statusnpx grada-run domain removeTo replace a configured domain, run domain add <new-domain> again with --force — the old domain is swapped out of CloudFront cleanly.
| Flag | Description |
|---|---|
--zone-id <id> |
Route 53 hosted zone ID for automated validation and routing. Accepts a bare ID (Z123…) or the console’s /hostedzone/Z123… form. Only applies to domain add. |
--activate |
Activate immediately in external-DNS mode (skips the pending stage). Make sure your validation CNAMEs exist first — apply waits on DNS propagation. Only applies to domain add. |
--force |
Replace an already-configured domain. Without it, re-adding refuses to clobber your configuration. Only applies to domain add. |
--yes |
Skip the confirmation prompt. Required in headless/CI mode. Only applies to domain remove. |
Requires a project initialized with grada (terraform/cloudfront.tf must exist).
One domain per project: each project manages a single custom domain. Need apex plus
www? Configure the apex here and add a redirect rule forwwwat your DNS provider.