← All posts

3 min read

Included subdomains for self-hosted Maester Cloud

Your own domain is still the best address for a self-hosted Maester Cloud portal. When you can't change your organization's DNS, every subscription now includes up to three subdomains like contoso.maester.fyi.

A self-hosted Maester Cloud instance runs in your own Azure subscription, so out of the box its address is the one Azure generates for it. It looks something like ca-maestercloud.happyhill-1a2b3c4d.eastus2.azurecontainerapps.io. It works, but it isn’t something you can say out loud in a meeting, put in a runbook, or expect a colleague to remember.

The best option is your own domain, something like maester.contoso.com. It carries your organization’s name, it sits under DNS you already manage and trust, and setup’s Custom domain step does most of the work: it shows you the two DNS records to create, then binds the address, issues a free certificate and registers it for sign-in. If you can add records to your company’s DNS, start there.

That isn’t always possible. Some teams don’t have access to their organization’s DNS, or changing it takes a change request and a few weeks. For those cases, every Maester Cloud subscription now includes up to three subdomains under a domain we operate:

  • maester.fyi
  • maester.live
  • maester.pro
  • maester.run

Pick a name, like contoso.maester.fyi, and your portal answers there as soon as its certificate is issued, usually within a few minutes. There are no DNS records for you to create and no certificate to buy or renew.

How to claim one

Update your instance to the latest release first. Then:

  1. Open setup.maester.cloud, choose your instance, and open the Custom domain step.
  2. Choose A Maester subdomain, pick a domain, and type the name you want. Setup tells you straight away whether it’s available.
  3. Select Claim in your Maester account. Your Maester account opens with your instance’s details already filled in. Confirm the claim there.
  4. Back in setup, select Verify & bind. Setup adds the address to your instance, issues a free Azure certificate that renews itself, and registers the address for sign-in.

That’s it. Your instance’s original Azure address keeps working too, so scheduled runs, pipelines and bookmarks that use it are unaffected.

The Domains page in your Maester account lists every name registered to you, live or not, and the instance each one points to.

How it works, and why it’s safe

We were careful about one thing in particular: a shared domain must never become a way for one customer to impersonate another, or for us to sit in the middle of your traffic.

  • We never see your traffic. A claim publishes two DNS records: a name that points straight at your instance, and a verification record. Requests go directly from the browser to your Azure environment. The certificate is issued by Azure to your instance, not by us.
  • Only your instance can serve your name. The verification record carries your Azure environment’s own verification ID, so no other environment can bind the name. A claim whose instance doesn’t prove it holds the certificate within 24 hours is removed automatically.
  • Names are reserved to you. If you release a name, it stays reserved to your account before anyone else can claim it. If your subscription lapses, the address keeps working through a 30-day grace period.
  • Some names are off-limits. Infrastructure- and security-shaped names like login, admin or secure can’t be claimed, and neither can names that impersonate another company or product.

The full rules are in the Terms of Service.

Moving to your own domain later

A Maester subdomain doesn’t lock you in. When you get access to your DNS, run the same Custom domain step and choose Your own domain. Setup shows the two DNS records to create, for a subdomain like maester.contoso.com or for an apex domain, then binds the domain and issues the certificate for you. Your instance can carry both addresses while you switch over, and you can release the Maester subdomain from your Maester account when you’re done. The self-hosting guide has the details.

If you have questions, or a name you’d like that’s on the reserved list, write to [email protected].