Domain per service
SSL is automatic. KibanOS obtains and renews SSL certificates via Let's Encrypt for all service domains. Ports 80 and 443 must be reachable for certificate issuance.
KibanOS owns HTTP routing. Every installed service gets a URL automatically. You never configure Traefik labels or Docker networks manually.
How routing works
KibanOS uses Traefik as a reverse proxy. When you install a service, KibanOS generates a URL, writes Traefik labels into the service configuration, and connects the container to a shared Docker network. Traefik handles the rest.
The dashboard and installed services are separated intentionally. Services are exposed through their own hostnames, not as subpaths of the dashboard. This avoids common issues with static assets, cookies, redirects, and WebSocket connections that break when services run under a subpath.
Domain format
Service URLs follow a fixed pattern:
{service}-{environment}-{project}.{base-domain}With a wildcard domain like services.example.com:
grafana-development-crossmetrics.services.example.com
n8n-production-myproject.services.example.comWithout a wildcard domain, services fall back to .localhost:
grafana-development-crossmetrics.localhost
n8n-production-myproject.localhostThe flattened subdomain format keeps generated service names under a single DNS label before the base domain, so a future wildcard certificate like *.services.example.com can cover all generated service URLs.
Localhost
The .localhost domain is reserved by RFC 6761 for loopback resolution. It works when KibanOS runs on your own machine — the browser and KibanOS are on the same host.
It does not work on remote servers, through tunnels, or from other devices on your network. If you need remote access, you need a real domain with DNS records.
Wildcard domain
The wildcard domain is the base domain for all installed service URLs. Configure it in Settings under Services Wildcard Domain.
services.example.comThen create a DNS wildcard record:
A *.services.example.com → your server IPEvery new service installed after this will get a URL under that domain. Existing services keep their current domain until you change them.
You can use any subdomain you control: apps.example.com, tools.example.com, internal.company.com.
Per-service override
Every installed service can have its own custom domain, overriding the generated default.
Open the service detail page. The Service domain section shows the current hostname. Change it to your custom domain:
n8n.example.comWhen saved, KibanOS updates the Traefik labels and restarts the service. The override is independent of the wildcard domain — if you change the wildcard later, services with overrides keep their custom domain.
Remote servers
When KibanOS runs on a VPS or is accessed through a tunnel, you need a real domain with DNS records for service URLs to work from other machines.
- Configure a wildcard domain in Settings.
- Create a DNS wildcard record pointing to your server.
- All installed services become accessible at their generated URLs.
If you use a tunnel provider with wildcard DNS (like Cloudflare Tunnel), configure the wildcard domain to match your tunnel hostname pattern. The tunnel routes all generated service URLs automatically.