[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"docs:\u002Fdocs\u002Foperators\u002Fpublic-address":3,"docs:nav":233,"docs:surround:\u002Fdocs\u002Foperators\u002Fpublic-address":442},{"id":4,"title":5,"body":6,"description":223,"extension":224,"launchGate":225,"meta":226,"navigation":227,"path":228,"seo":229,"stem":230,"stub":231,"__hash__":232},"docs_en\u002Fdocs\u002F4.operators\u002F15.public-address.md","Public address and app hostnames",{"type":7,"value":8,"toc":215},"minimark",[9,18,23,31,40,54,58,61,104,115,118,122,125,174,208],[10,11,12,13,17],"p",{},"People reach your realm at one address, such as ",[14,15,16],"code",{},"https:\u002F\u002Fcloud.example.se\u002F",". On a server with a single public IP address, as most VPSs have, the realm and the apps you give hostnames share ports 80 and 443 on it.",[19,20,22],"h2",{"id":21},"one-address-for-the-realm-and-its-apps","One address for the realm and its apps",[10,24,25,26,30],{},"The ",[27,28,29],"strong",{},"ingress"," module holds ports 80 and 443, TCP and UDP; the edge publishes no port of its own. It answers your apps’ hostnames itself, over HTTP\u002F3 too, and hands the realm’s own hostname on to the edge, unopened, so the realm’s sign-in and sessions never pass through the code that serves apps. UDP port 4443, for the fastest connection to the web client, arrives at ingress too and goes on to the edge whole.",[10,32,33,34,39],{},"Realms installed from release 2026.10.2 on have this from the start. An older realm gets it from that update, which adds the ingress module and needs the realm key once (",[35,36,38],"a",{"href":37},"\u002Fdocs\u002Foperators\u002Fupdates#when-an-update-needs-the-realm-key","Updates",").",[41,42,43,47],"ol",{},[44,45,46],"li",{},"Point the realm’s hostname, and each app’s hostnames, at the same address in DNS.",[44,48,49,50,53],{},"Give the realm its certificate in ",[27,51,52],{},"Manager › Certificate",". Ports 80 and 443 now pass through ingress, and HTTP-01 still works.",[19,55,57],{"id":56},"hostnames-for-an-app","Hostnames for an app",[10,59,60],{},"An app reached by name needs a domain its owner has proved.",[41,62,63,85,94],{},[44,64,65,68,69,72,73,76,77,80,81,84],{},[27,66,67],{},"Prove the domain."," Add it in the app’s ",[27,70,71],{},"Settings",", under ",[27,74,75],{},"Networking",". Velrix gives you a TXT record to publish at ",[14,78,79],{},"_velrix.\u003Cdomain>",". Once it is there, the domain is verified for you or your organisation, and nobody else can use it. A domain registered through Velrix’s ",[27,82,83],{},"Domains"," app counts as verified.",[44,86,87,90,91,93],{},[27,88,89],{},"Give the app its names."," Under ",[27,92,75],{},", or in the create form, enter the names (the domain or names under it, up to ten) and the container port they go to. Add a health path if the app has one.",[44,95,96,99,100,103],{},[27,97,98],{},"Certificates"," come by themselves once the names point at the realm. Until a name has one, it is served over plain HTTP; after, HTTP is redirected to HTTPS. A name that does not point here yet says ",[27,101,102],{},"Waiting for DNS to point here",", and its certificate is ordered as soon as it does.",[10,105,106,107,109,110,114],{},"Requests are spread over the app’s running copies that answer their health check. HTTP\u002F3, HTTP\u002F2, HTTP\u002F1.1 and WebSocket all work. ",[27,108,75],{}," shows each name’s HTTPS record: set it in DNS, and browsers use HTTP\u002F3 from their first visit. Redirect names and Velrix Access, the realm’s sign-in in front of an app, are in ",[35,111,113],{"href":112},"\u002Fdocs\u002Fguides\u002Fapps#hostnames-and-http3","Apps",".",[10,116,117],{},"Velrix checks each verified domain’s TXT record again every six hours. If it is gone, the owner is told at once, and the names are served for seven more days before they stop.",[19,119,121],{"id":120},"the-registry-and-mcp","The registry and MCP",[10,123,124],{},"Neither has a port of its own: the edge relays them over the realm’s HTTPS address, so an API key or a registry password only ever crosses the network inside TLS.",[126,127,128,140],"table",{},[129,130,131],"thead",{},[132,133,134,137],"tr",{},[135,136],"th",{},[135,138,139],{},"Address",[141,142,143,164],"tbody",{},[132,144,145,149],{},[146,147,148],"td",{},"Image registry",[146,150,151,154,155,158,159,163],{},[14,152,153],{},"\u003Crealm>\u002Fv2\u002F",", so images are named ",[14,156,157],{},"\u003Crealm>\u002Fu-\u003Cyou>\u002F\u003Cname>:\u003Ctag>"," (",[35,160,162],{"href":161},"\u002Fdocs\u002Fguides\u002Fregistry","Registry",")",[132,165,166,169],{},[146,167,168],{},"MCP for AI agents",[146,170,171],{},[14,172,173],{},"https:\u002F\u002F\u003Crealm>\u002Fmcp",[10,175,176,177,180,181,184,185,188,189,191,192,195,196,199,200,203,204,207],{},"While the realm uses the certificate it made for itself, the registry’s ",[14,178,179],{},"tlsVerify"," setting is ",[14,182,183],{},"false",", and the Registry window shows ",[14,186,187],{},"--tls-verify=false"," in its commands. Once ",[27,190,52],{}," has a certificate from a CA, set ",[14,193,194],{},"settings.registry.tlsVerify"," to ",[14,197,198],{},"true"," in ",[14,201,202],{},"deploy.json"," and run ",[14,205,206],{},"velrix up"," on each server.",[10,209,210,211,214],{},"Apps never publish a port on a server. For other ports, floating IP addresses and load balancers go through the realm’s gateways, which an operator sets under ",[27,212,213],{},"Networks › Gateways",". Gateways work over IPv4 only: on servers with IPv6 alone there are no floating IP addresses or load balancers yet.",{"title":216,"searchDepth":217,"depth":218,"links":219},"",2,3,[220,221,222],{"id":21,"depth":217,"text":22},{"id":56,"depth":217,"text":57},{"id":120,"depth":217,"text":121},"One public IP address for the realm and its apps, hostnames with certificates for apps, and the addresses for the registry and MCP.","md",null,{},true,"\u002Fdocs\u002Foperators\u002Fpublic-address",{"title":5,"description":223},"docs\u002F4.operators\u002F15.public-address",false,"kB772zDcX-2vibpEYFEqYA7ScmnaunWEsPZFqHa2cB0",[234],{"title":235,"path":236,"stem":237,"children":238,"page":-1},"Docs","\u002Fdocs","docs",[239,243,273,300,331,399,413,435],{"title":240,"path":236,"stem":241,"stub":231,"launchGate":225,"icon":242},"Overview","docs\u002Findex","i-lucide-house",{"title":244,"stub":231,"launchGate":225,"icon":245,"path":246,"stem":247,"children":248,"page":231},"Get started","i-lucide-rocket","\u002Fdocs\u002Fget-started","docs\u002F1.get-started",[249,253,257,261,265,269],{"title":250,"path":251,"stem":252,"stub":231,"launchGate":225},"What Velrix is","\u002Fdocs\u002Fget-started\u002Fwhat-is-velrix","docs\u002F1.get-started\u002F1.what-is-velrix",{"title":254,"path":255,"stem":256,"stub":231,"launchGate":225},"Ways to run Velrix","\u002Fdocs\u002Fget-started\u002Fways-to-run","docs\u002F1.get-started\u002F2.ways-to-run",{"title":258,"path":259,"stem":260,"stub":231,"launchGate":225},"Install from USB","\u002Fdocs\u002Fget-started\u002Finstall","docs\u002F1.get-started\u002F3.install",{"title":262,"path":263,"stem":264,"stub":231,"launchGate":225},"The setup wizard","\u002Fdocs\u002Fget-started\u002Fsetup-wizard","docs\u002F1.get-started\u002F4.setup-wizard",{"title":266,"path":267,"stem":268,"stub":231,"launchGate":225},"Your first app","\u002Fdocs\u002Fget-started\u002Ffirst-app","docs\u002F1.get-started\u002F5.first-app",{"title":270,"path":271,"stem":272,"stub":231,"launchGate":225},"Your first VM","\u002Fdocs\u002Fget-started\u002Ffirst-vm","docs\u002F1.get-started\u002F6.first-vm",{"title":274,"stub":231,"launchGate":225,"icon":275,"path":276,"stem":277,"children":278,"page":231},"Concepts","i-lucide-lightbulb","\u002Fdocs\u002Fconcepts","docs\u002F2.concepts",[279,283,287,291,295],{"title":280,"path":281,"stem":282,"stub":227,"launchGate":225},"Realms","\u002Fdocs\u002Fconcepts\u002Frealms","docs\u002F2.concepts\u002F1.realms",{"title":284,"path":285,"stem":286,"stub":227,"launchGate":225},"Instances and hosts","\u002Fdocs\u002Fconcepts\u002Finstances-and-hosts","docs\u002F2.concepts\u002F2.instances-and-hosts",{"title":288,"path":289,"stem":290,"stub":227,"launchGate":225},"Modules and the mesh","\u002Fdocs\u002Fconcepts\u002Fmodules-and-the-mesh","docs\u002F2.concepts\u002F3.modules-and-the-mesh",{"title":292,"path":293,"stem":294,"stub":227,"launchGate":225},"Organisations, projects and permissions","\u002Fdocs\u002Fconcepts\u002Forgs-projects-permissions","docs\u002F2.concepts\u002F4.orgs-projects-permissions",{"title":296,"path":297,"stem":298,"stub":227,"launchGate":299},"Host pools","\u002Fdocs\u002Fconcepts\u002Fhost-pools","docs\u002F2.concepts\u002F5.host-pools","A1",{"title":301,"stub":231,"launchGate":225,"icon":302,"path":303,"stem":304,"children":305,"page":231},"Guides for users","i-lucide-book-open","\u002Fdocs\u002Fguides","docs\u002F3.guides",[306,309,313,317,321,325,327],{"title":113,"path":307,"stem":308,"stub":231,"launchGate":225},"\u002Fdocs\u002Fguides\u002Fapps","docs\u002F3.guides\u002F1.apps",{"title":310,"path":311,"stem":312,"stub":227,"launchGate":225},"Machines","\u002Fdocs\u002Fguides\u002Fmachines","docs\u002F3.guides\u002F2.machines",{"title":314,"path":315,"stem":316,"stub":227,"launchGate":225},"Volumes","\u002Fdocs\u002Fguides\u002Fvolumes","docs\u002F3.guides\u002F3.volumes",{"title":318,"path":319,"stem":320,"stub":231,"launchGate":225},"Stacks","\u002Fdocs\u002Fguides\u002Fstacks","docs\u002F3.guides\u002F4.stacks",{"title":322,"path":323,"stem":324,"stub":227,"launchGate":225},"Terminal and cloud shells","\u002Fdocs\u002Fguides\u002Fterminal","docs\u002F3.guides\u002F5.terminal",{"title":162,"path":161,"stem":326,"stub":231,"launchGate":225},"docs\u002F3.guides\u002F6.registry",{"title":328,"path":329,"stem":330,"stub":227,"launchGate":225},"Kubernetes","\u002Fdocs\u002Fguides\u002Fkubernetes","docs\u002F3.guides\u002F7.kubernetes",{"title":332,"stub":231,"launchGate":225,"icon":333,"path":334,"stem":335,"children":336,"page":231},"Guides for operators","i-lucide-server-cog","\u002Fdocs\u002Foperators","docs\u002F4.operators",[337,341,345,349,353,357,361,362,366,370,375,379,383,387,391,395],{"title":338,"path":339,"stem":340,"stub":231,"launchGate":225},"Updates and maintenance windows","\u002Fdocs\u002Foperators\u002Fupdates","docs\u002F4.operators\u002F1.updates",{"title":342,"path":343,"stem":344,"stub":231,"launchGate":225},"Migrate: moving VMs from VMware","\u002Fdocs\u002Foperators\u002Fmigrate","docs\u002F4.operators\u002F10.migrate",{"title":346,"path":347,"stem":348,"stub":231,"launchGate":225},"Hardware","\u002Fdocs\u002Foperators\u002Fhardware","docs\u002F4.operators\u002F11.hardware",{"title":350,"path":351,"stem":352,"stub":231,"launchGate":225},"Billing","\u002Fdocs\u002Foperators\u002Fbilling","docs\u002F4.operators\u002F12.billing",{"title":354,"path":355,"stem":356,"stub":231,"launchGate":225},"Policies","\u002Fdocs\u002Foperators\u002Fpolicies","docs\u002F4.operators\u002F13.policies",{"title":358,"path":359,"stem":360,"stub":231,"launchGate":225},"Running the realm","\u002Fdocs\u002Foperators\u002Frealm-ops","docs\u002F4.operators\u002F14.realm-ops",{"title":5,"path":228,"stem":230,"stub":231,"launchGate":225},{"title":363,"path":364,"stem":365,"stub":231,"launchGate":225},"Library","\u002Fdocs\u002Foperators\u002Flibrary","docs\u002F4.operators\u002F16.library",{"title":367,"path":368,"stem":369,"stub":231,"launchGate":225},"Backups","\u002Fdocs\u002Foperators\u002Fbackups","docs\u002F4.operators\u002F2.backups",{"title":371,"path":372,"stem":373,"stub":227,"launchGate":374},"Availability and drain","\u002Fdocs\u002Foperators\u002Favailability","docs\u002F4.operators\u002F3.availability","A1, A2, A3",{"title":376,"path":377,"stem":378,"stub":227,"launchGate":225},"Federation","\u002Fdocs\u002Foperators\u002Ffederation","docs\u002F4.operators\u002F4.federation",{"title":380,"path":381,"stem":382,"stub":227,"launchGate":225},"Licensing","\u002Fdocs\u002Foperators\u002Flicensing","docs\u002F4.operators\u002F5.licensing",{"title":384,"path":385,"stem":386,"stub":227,"launchGate":225},"Branding: look and design","\u002Fdocs\u002Foperators\u002Fbranding","docs\u002F4.operators\u002F6.branding",{"title":388,"path":389,"stem":390,"stub":227,"launchGate":225},"Connectivity","\u002Fdocs\u002Foperators\u002Fconnectivity","docs\u002F4.operators\u002F7.connectivity",{"title":392,"path":393,"stem":394,"stub":227,"launchGate":225},"Logs","\u002Fdocs\u002Foperators\u002Flogs","docs\u002F4.operators\u002F8.logs",{"title":396,"path":397,"stem":398,"stub":231,"launchGate":225},"Directory sync: Entra ID and Okta","\u002Fdocs\u002Foperators\u002Fdirectory-sync","docs\u002F4.operators\u002F9.directory-sync",{"title":400,"stub":231,"launchGate":225,"icon":401,"path":402,"stem":403,"children":404,"page":231},"Reference","i-lucide-library","\u002Fdocs\u002Freference","docs\u002F5.reference",[405,409],{"title":406,"path":407,"stem":408,"stub":231,"launchGate":225},"The API reference in your realm","\u002Fdocs\u002Freference\u002Fin-your-realm","docs\u002F5.reference\u002F1.in-your-realm",{"title":410,"path":411,"stem":412,"stub":231,"launchGate":225},"The velrix command","\u002Fdocs\u002Freference\u002Fcli","docs\u002F5.reference\u002F2.cli",{"title":414,"stub":231,"launchGate":225,"icon":415,"path":416,"stem":417,"children":418,"page":231},"Security and compliance","i-lucide-shield-check","\u002Fdocs\u002Fsecurity","docs\u002F6.security",[419,423,427,431],{"title":420,"path":421,"stem":422,"stub":227,"launchGate":225},"Post-quantum","\u002Fdocs\u002Fsecurity\u002Fpost-quantum","docs\u002F6.security\u002F1.post-quantum",{"title":424,"path":425,"stem":426,"stub":227,"launchGate":225},"GDPR","\u002Fdocs\u002Fsecurity\u002Fgdpr","docs\u002F6.security\u002F2.gdpr",{"title":428,"path":429,"stem":430,"stub":227,"launchGate":225},"NIS2 support","\u002Fdocs\u002Fsecurity\u002Fnis2","docs\u002F6.security\u002F3.nis2",{"title":432,"path":433,"stem":434,"stub":227,"launchGate":225},"Data residency","\u002Fdocs\u002Fsecurity\u002Fdata-residency","docs\u002F6.security\u002F4.data-residency",{"title":436,"path":437,"stem":438,"children":439,"stub":231,"launchGate":225,"icon":441},"Release notes","\u002Fdocs\u002Frelease-notes","docs\u002F7.release-notes\u002Findex",[440],{"title":436,"path":437,"stem":438,"stub":231,"launchGate":225},"i-lucide-scroll-text",[443,445],{"title":358,"path":359,"stem":360,"description":444,"children":-1},"See every module on every server, restart, stop or move one, run several edges, and reach your servers when the web client can't be reached.",{"title":363,"path":364,"stem":365,"description":446,"children":-1},"The blueprints and script templates people make things from, in one place, and how to copy them to another installation."]