SpipCP
DNS

The External tier & CDN caveats (Cloudflare, Bunny, …)

What "External" means as a detected authority tier, how to create the records SpipCP asks for by hand, and the per-provider caveats (Cloudflare orange-cloud, etc.).

External is one of the three authority tiers SpipCP detects for a hostname: its zone lives in DNS that SpipCP holds no credential for — the customer's or registrar's — so SpipCP can't write records automatically. On the Domains inventory an External row shows the detected nameserver (display-only) and the exact records to create by hand, then a re-verify action.

External is a property, not a page

There is no longer a separate "External DNS" panel page — External is detected per hostname and shown on Domains. When an API credential for the zone is held, adding it under Providers turns the same hostname into Connected (records auto-created). The old /dns/external link redirects to Providers.

Two guided journeys land a hostname in the External tier on purpose, and the Set up surface treats both as first-class, named choices:

  • "Manage records at the provider directly" — the no-token fork of the Connect a managed provider journey. Nameservers stay at Cloudflare (or Bunny, deSEC, …), SpipCP holds no credential, and the row shows "NS at cloudflare.com (detected); records managed there."
  • "Self-managed DNS" — the same posture with no provider named: keep DNS wherever it is, attach with the manual driver, paste the record.

Both are the honest manual path. The trade they share — no wildcard, per-host HTTP-01 only, because SpipCP has no credential to write the _acme-challenge TXT — is laid out in full in the managed-provider fork table.

When records live at a provider that can hold a credential (Cloudflare, Bunny, deSEC, Hetzner, Gcore), that's the managed fast path (scenario B/C) — SpipCP writes the records through the provider's API. No nameserver boxes, no glue records. The trade: that provider holds (and can see) the records; for the sovereignty path see Self-hosted DNS.

Everything besides record-writing — sites, certificates, deploys, backups, monitoring — works identically in both postures.

Install the panel with a real hostname

Follow Installation. Because the provider already serves DNS for the domain, the panel's record can be created before installing — add an A/AAAA record (e.g. panel → the VPS IP) in the provider's dashboard — then install directly with SITE_ADDRESS=panel.example.com + TLS_MODE=admin@example.com. No IP-first bootstrap needed.

Turn the posture on (and the other one off, if desired)

Networking → Providers → Offer these providers: enable the provider to be used so it appears in the Add-account picker. (This per-provider switchboard used to be its own "External" page; it now lives on Providers.)

Add the provider account

Networking → Providers → Add account: pick the provider tab and paste an API token. The dialog shows exactly which token scopes to create per provider (e.g. Cloudflare wants a token scoped to Zone → DNS → Edit for the zone — never the global API key). The token is encrypted at rest with MASTER_KEY. Details: Managed DNS providers.

Point the cascade + attach domains

Set the account as the DNS default at the level needed — node, instance, or per-domain (the cascade) — then attach the site's domain. From here the panel writes the records (A/AAAA, wildcard, ACME TXT) automatically as sites are created and certs are issued.

Per-provider caveats

ProviderCaveats worth knowing
CloudflareProxied ("orange-cloud") records break TLS-ALPN certificate issuance — the challenge terminates at Cloudflare's edge, not the node. Either keep panel-managed records DNS-only (grey-cloud), or use the DNS-01 lane (which also unlocks wildcards). For on-demand custom customer domains an orange-cloud CNAME does work (HTTP-01 passes through on port 80), with a first-hit 525 until issuance completes — grey-cloud is still recommended. US-based; see recommendations for the EU-first alternatives.
BunnyBunny DNS is what SpipCP drives. Bunny's CDN pull zones are a separate product — configure them in Bunny's dashboard if wanted; the panel doesn't manage them (yet).
deSECNon-profit, EU. Strict API rate limits — bulk record churn (many sites at once) can throttle; the panel's writes are modest, but keep it in mind for mass imports.
HetznerStraightforward zone API. The zone must already exist in Hetzner DNS (delegated there) before the panel can write into it.
GcoreSame shape as Hetzner — delegate first, then the panel writes records.

Migrating to self-hosted later

Nothing here is a lock-in. To move to self-hosted nameservers later: stand them up (Self-hosted DNS), create the zone, re-create the records (the records editor's Paste many takes a block of name type [ttl] value lines), verify both boxes answer authoritatively, then re-delegate at the registrar. Disable DNSSEC at the provider first if it was on, or the domain goes dark on the switch.

On this page