Skip to main content
Synthetiq serves all traffic over HTTPS and requires two wildcard ACM certificates in your AWS account. They are a prerequisite: issue them before provisioning, through whatever process you normally use for certificates. The CLI never creates them.

What you need

The certificates cover your base domain — the domain in _infra/synthetiq.yaml, under which every app is served (my-app.apps.yourcompany.com). For apps.yourcompany.com: A wildcard does not cover the bare domain — request the CDN certificate with the apex as an additional name (in ACM: a subject alternative name). A wildcard-only certificate fails verification at generate.

Optional: add spare shard names to the API certificate

To get started, the API certificate only needs *.api.<domain>. Adding spare shard names is a way to plan for capacity. One load balancer serves at most 100 apps, so an installation that grows past about 90 apps adds load balancer shards, each serving its apps at *.sN.api.<domain>. If the API certificate already lists *.s1.api through *.s9.api, adding a shard later is a config change and one DNS record, with no new certificate per shard. A certificate can’t gain names after it’s issued, so the start is the easiest time to add them. They cost nothing, and 10 names is the default limit for an ACM certificate. With the AWS CLI:
If you leave them out, you can still add shards later: issue a certificate for the shard names when you need them.

Validation

Use DNS validation: ACM gives you one CNAME per name it needs to validate (one for the CDN certificate, and one per name on the API certificate) to create at your DNS provider — see DNS. Issuance completes within minutes of the records appearing, and the records also drive auto-renewal.

Add the ARNs to your config

Once both certificates are ISSUED, get the ARNs into _infra/synthetiq.yaml any of these ways:
  • Run synthetiq infra init with AWS credentials — it discovers issued certificates for the domain automatically.
  • Pass them: synthetiq infra init --cdn-cert-arn <arn> --api-cert-arn <arn> (offline init prompts for them).
  • Edit the certs: block directly.
synthetiq infra generate verifies both at plan time — issued, correct region, covering the required names — and fails with the specific reason if not. If you run init before the certificates exist, it stops and prints what’s needed.

Renewal

ACM auto-renews DNS-validated certificates as long as the validation CNAMEs remain in your DNS, and the ARN never changes. This is one-time setup; you won’t revisit it unless you change your domain, or need shard names the API certificate doesn’t list. If you do replace a certificate, put the new ARN in the config and run the usual generate → provision: provisioning swaps it on the load balancer in place.