HTTPS & domains

Give any pod a public HTTPS address: certificates, HTTP/2 and HTTP/3 are handled for you.

svl run -d --name web --http 8080 ghcr.io/me/app:latest
https: https://web-acme.svl.blah.au → port 8080

The address is https://<name>-<account>.svl.blah.au. It points at your pod's port 8080. The port doesn't need -p, and it works with --private too: traffic reaches the container over serverless.au's network, not a public port.

Stable addresses

The address belongs to the pod name, not to one pod. Stop the pod and run a new one with the same --name (a new image, a different size, even a different machine) and the same address serves it within seconds. Nothing changes in DNS.

svl stop web
svl run -d --name web --http 8080 ghcr.io/me/app:v2

While nothing with that name is running, the address answers 503 with a short "no healthy backends" page.

Without --name, a pod is named after its id, so the address changes every run. serverless.au warns you when that happens.

Health checks

serverless.au checks each pod every 5 seconds and only sends traffic to healthy ones.

  • Default: GET /health. Any answer below 500 counts as healthy (so an app without a /health route is fine). Refused connections, timeouts and 5xx answers are unhealthy.
  • Your own check: --health-path /healthz makes serverless.au require a 2xx from that path.

A new pod gets traffic as soon as its first check passes.

What your app sees

  • X-Forwarded-For and X-Real-IP: the visitor's IP address.
  • X-Forwarded-Proto: https and X-Forwarded-Host: the original scheme and hostname.
  • WebSockets and server-sent events work. There's no request timeout and no upload size limit.
  • Plain http:// requests are redirected to https://.

Your own domain

Serve a route from your own domain (or subdomain) as well. serverless.au gets the certificate.

svl domain add app.example.com --to web

serverless.au prints the DNS record to create at your DNS provider:

app.example.com  CNAME  web-acme.svl.blah.au

Within a minute or two of the record going live, serverless.au verifies it, issues a certificate, and https://app.example.com serves your pod. svl domain check app.example.com checks right away. Or do it all at once:

svl run -d --name web --http 8080 --domain app.example.com ghcr.io/me/app:latest

Root domains (like example.com) can't have a CNAME. Instead, add the TXT record and the A/AAAA records that svl domain add prints. If your DNS provider supports CNAME flattening or ALIAS records (Cloudflare does), a CNAME to your serverless.au hostname works too.

States you'll see in svl domains:

  • pending_dns: waiting for the DNS record. The detail column says what serverless.au found instead.
  • issuing: DNS is right; the certificate is on its way.
  • active: live.
  • error: something needs fixing (for example, DNS never pointed at serverless.au within 7 days). Fix it and run svl domain check.

A domain only verifies when it points at your own route's hostname, so nobody else can claim it. Each account can attach up to 10 domains.

Managing routes

svl routes                              # addresses, health, domains
svl route add web 8080 --health-path /healthz
svl route rm web
svl domains                             # your domains and their state
svl domain rm app.example.com

Each account can have up to 20 routes. A name can have routes on several ports; pass --port to svl route rm to pick one.