Your domain
If fepli hosts your instance, there is nothing to install: fepli runs it, updates it and gets its certificates. The one thing that is yours to set up is the domain families reach it at. This page is for whoever manages your organisation's DNS: your IT department, or the agency that looks after your website.
Which address
Every instance starts with an address under fepli's domain, e.g. elmsbrueck.fepli.eu. It works at once and needs nothing from you.
For an address of your own, there are two kinds:
| Example | What you change | |
|---|---|---|
| A domain for the programme alone | ferienpass-elmsbrueck.de | the domain's nameservers, at its registrar |
| A name under your organisation's domain | ferienpass.elmsbrueck.de | three NS records for that one name, in the zone of elmsbrueck.de |
Which one depends on what the domain is used for. A whole domain can only come to fepli if fepli is all it is used for. If the domain also receives e-mail, or serves another website or service, give fepli a name under it instead.
In both cases you point the name at fepli's nameservers, and fepli does the rest:
fepli’s nameservers
ns1.hosting.de
ns2.hosting.de
ns3.hosting.de
The domain stays yours. It remains registered where it is, in your name, and you can point it elsewhere again at any time. Nothing is transferred.
Why nameservers, and not a single record
fepli needs to add and change records for your address without asking you each time:
- the records that lead to the servers, which change when fepli moves or scales its infrastructure,
- the records that prove the domain to the certificate authority, each time your TLS certificate is issued or renewed,
- the address with
www.in front, which redirects to the one without, - the records that allow fepli to send e-mail from your domain (DKIM, SPF),
- further names when you need them, e.g. a separate address for the admin or a reply domain for e-mails (MX).
With the nameservers at fepli, all of that happens by itself. A single CNAME or A record on your side would cover only the first, and every other change would be a request to your IT.
A domain for the programme alone
Use this when the domain exists for the holiday programme and nothing else, such as ferienpass-elmsbrueck.de.
Once the nameservers are fepli's, every record of the domain comes from
fepli, and fepli keeps only the records its own service needs. It does not
take over records for anything else: mailboxes, another website, other
services. If the domain is used for any of those, don't move it. Use a name
under it instead, e.g.
ferienpass. in front of it.
- Tell fepli first, at support@fepli.de: the domain. fepli sets it up on its nameservers before you change anything.
- Change the nameservers of the domain to the three above. You do that where the domain is registered, usually under "Nameserver" or "DNS" in the registrar's customer area.
- Wait until the change has spread. That takes from a few minutes to a day.
- fepli then issues the certificate, and the domain serves your instance.
A name under your organisation's domain
Use this when the programme lives under the domain of your town or organisation, such as ferienpass.elmsbrueck.de, or when a domain of yours is used for more than fepli. You hand over that one name; everything else in your zone stays as it is.
-
Tell fepli first, at support@fepli.de: the name you want. fepli sets it up on its nameservers.
-
Add three
NSrecords for the name in the zone of your domain:In the zone elmsbrueck.de
ferienpass.elmsbrueck.de. NS ns1.hosting.de. ferienpass.elmsbrueck.de. NS ns2.hosting.de. ferienpass.elmsbrueck.de. NS ns3.hosting.de. -
Remove every other record of that name: an
A,CNAMEorTXTrecord forferienpass.elmsbrueck.decan't exist next to theNSrecords. -
Wait until the change has spread, then fepli issues the certificate.
From then on, ferienpass.elmsbrueck.de and every name below it, such as www.ferienpass.elmsbrueck.de, is answered by fepli. Names beside it, such as www.elmsbrueck.de or your mail servers, are not touched.
If your zone is signed with DNSSEC, add no DS record for the name. It is then served unsigned, which every resolver accepts.
Check that it worked
Ask for the nameservers of your address. Once the answer names fepli's, the change has arrived:
On any machine
dig NS ferienpass.elmsbrueck.de +short
Answer
ns1.hosting.de.
ns2.hosting.de.
ns3.hosting.de.
Until fepli has issued the certificate, a browser may warn about it for a short while, or show the instance under its fepli.eu address only. If it still does a day after the change, write to support@fepli.de.
Going back
Set the nameservers back, or remove the NS records, and the name is yours to point anywhere again. Tell fepli beforehand, so that links in e-mails already sent keep leading somewhere.
Running fepli yourself
If you run the fepli image on your own infrastructure, none of this applies: the DNS and the certificates of your tenants are yours. See Self-hosting.