Public address and app hostnames
People reach your realm at one address, such as https://cloud.example.se/. On a server with a single public IP address, as most VPSs have, the realm and the apps you give hostnames share ports 80 and 443 on it.
One address for the realm and its apps
The ingress module holds ports 80 and 443. It answers your apps’ hostnames itself, and hands the realm’s own hostname on to the edge, unopened, so the realm’s sign-in and sessions never pass through the code that serves apps. UDP port 4443 stays the edge’s, for the fastest connection to the web client.
Realms installed from release 2026.10.2 on have this from the start. An older realm gets it from that update, which adds the ingress module and needs the realm key once (Updates).
- Point the realm’s hostname, and each app’s hostnames, at the same address in DNS.
- Give the realm its certificate in Manager › Certificate. Ports 80 and 443 now pass through ingress, and HTTP-01 still works.
Hostnames for an app
An app reached by name needs a domain its owner has proved.
- Prove the domain. Add it on the app’s Hostnames tab. Velrix gives you a TXT record to publish at
_velrix.<domain>. Once it is there, the domain is verified for you or your organisation, and nobody else can use it. A domain registered through Velrix’s Domains app counts as verified. - Give the app its names. On the app’s Hostnames tab, or in the create form, enter the names (the domain or names under it, up to ten) and the container port they go to. Add a health path if the app has one.
- Certificates come by themselves once the names point at the realm. Until a name has one, it is served over plain HTTP; after, HTTP is redirected to HTTPS.
Requests are spread over the app’s running copies that answer their health check. HTTP/1.1, HTTP/2 and WebSocket all work.
Velrix checks each verified domain’s TXT record again every six hours. If it is gone, the owner is told at once, and the names are served for seven more days before they stop.
The registry and MCP
Neither has a port of its own: the edge relays them over the realm’s HTTPS address, so an API key or a registry password only ever crosses the network inside TLS.
| Address | |
|---|---|
| Image registry | <realm>/v2/, so images are named <realm>/u-<you>/<name>:<tag> (Registry) |
| MCP for AI agents | https://<realm>/mcp |
While the realm uses the certificate it made for itself, the registry’s tlsVerify setting is false, and the Registry window shows --tls-verify=false in its commands. Once Manager › Certificate has a certificate from a CA, set settings.registry.tlsVerify to true in deploy.json and run velrix up on each server.
For other ports, floating IP addresses and load balancers go through the realm’s gateways, which an operator sets under Networks › Gateways. Gateways work over IPv4 only: on servers with IPv6 alone there are no floating IP addresses or load balancers yet.