Wildcard TLS
One certificate for myapp.subdy.io and every name under it.
At the end you will have HTTPS on myapp.subdy.io and any
*.myapp.subdy.io — either with Subdy's managed certificate or with
your own ACME client.
Option A — managed certificate (recommended, Pro)
Toggle issue wildcard certificate when creating the subdomain, or press Renew now on Certificates. Subdy completes the DNS-01 challenge on its own nameservers — nothing to configure. When the status is valid, press Download to get the full chain and private key, then point your server at them:
myapp.subdy.io, *.myapp.subdy.io {
tls /etc/ssl/subdy/cert.pem /etc/ssl/subdy/key.pem
reverse_proxy 127.0.0.1:3000
}Renewal is automatic ~30 days before expiry — re-download and reload
(or script it via GET /v1/certificates).
Option B — your own ACME client
Wildcard certificates require DNS-01: the CA checks a TXT record at
_acme-challenge.myapp.subdy.io. Publish it via the Subdy API.
certbot (4.x) manual mode:
certbot certonly --manual --preferred-challenges dns \
-d "myapp.subdy.io" -d "*.myapp.subdy.io"When certbot prints the validation string, set the record (see set_record):
curl -sS -X PUT "https://api.subdy.io/v1/subdomains/$SUBDOMAIN_ID/records" \
-H "Authorization: Bearer $SUBDY_TOKEN" \
-H "Content-Type: application/json" \
-d '{"type":"TXT","name":"_acme-challenge","value":"<validation-string>","ttl":60}'Traefik (v3.x) and Caddy with a DNS plugin need a provider
integration; until a native Subdy plugin ships, use Option A or the
exec provider pattern with the same API call.