Skip to main content

Domain and HTTPS Configuration

To serve your platform deployment over HTTPS, complete two steps: make the platform reachable through a domain name, then decide where TLS terminates — on your client-side load balancer, on the server's Kubernetes Ingress, or not at all.

This page covers the domain name setup and compares the three TLS termination options. Option A, terminating TLS on your client-side load balancer, is the most common setup in customer environments.

ItemDescription
Number of domainsOne is sufficient. All services of the platform share the same domain and are distinguished by URL path.
DNS recordsAn A record that points the domain to the server's public IP address.
Examplemaas.your-company.com → x.x.x.x

You can access the platform directly without a domain name at http://<server-ip>, but HTTPS cannot be enabled without a domain name.

Choose a TLS termination option​

OptionDescription
Option A: Terminate TLS on your client-side load balancerYour LB/WAF handles HTTPS and reverse-proxies plain HTTP to the server's port 80 (Kubernetes Ingress). Recommended and the most common customer approach.
Option B: Terminate TLS on the server's IngressA TLS certificate is configured on the Kubernetes Ingress of the server.
Option C: Do not enable HTTPSThe platform is accessed directly over HTTP.

Option A: Terminate TLS on your client-side load balancer​

Traffic flow:

User browser --HTTPS--> Your LB/WAF --HTTP--> Server :80 (Kubernetes Ingress)

Key points for the client-side load balancer configuration:

  1. Listen on port 443 and configure a TLS certificate on the load balancer.
  2. Forward backend traffic to port 80 (HTTP) on the server.
  3. Set the following headers on the forwarded requests so the platform sees the original scheme and client IP:
    • X-Forwarded-Proto: https
    • X-Forwarded-For: <client-ip>
  4. Set a WebSocket/SSE long connection timeout of ≥ 600 seconds to support model-inference streaming output.

Option B: Terminate TLS on the server's Kubernetes Ingress​

When the server's Kubernetes Ingress terminates TLS, provide the following to the platform operator:

ItemDescription
TLS certificate fileThe certificate file (.crt) for your domain.
Private keyThe matching private key (.key).
Certificate coverageThe certificate must cover the configured domain, for example maas.your-company.com.

If the platform operator manages the Ingress, you only need to hand over the certificate and private key. The operator creates a TLS Secret in Kubernetes and references it in the Ingress, for example:

kubectl create secret tls <tls-secret-name> \
--cert=maas.your-company.com.crt \
--key=maas.your-company.com.key \
--namespace <platform-namespace>
spec:
tls:
- hosts:
- maas.your-company.com
secretName: <tls-secret-name>

Option C: Do not enable HTTPS​

The platform is accessed directly over HTTP, for example at http://<server-ip>. HTTPS cannot be enabled in this mode. Use it only while the domain name is not yet ready or inside a trusted network, and switch to Option A or Option B before exposing the platform to end users.

Next Step​

Continue with SSO for administrator and member sign-in, or Theme for tenant branding.