# Cant forward to a Dedicated Custom Domain Name

**URL:** https://openziti.discourse.group/t/cant-forward-to-a-dedicated-custom-domain-name/2541
**Category:** zrok
**Created:** [May 10, 2024, 9:10pm UTC](https://openziti.discourse.group/t/cant-forward-to-a-dedicated-custom-domain-name/2541 "2024-05-10T21:10:08Z")
**Posts on this page:** 20
**Page:** 1

<div class="post-metadata">

### Author: ![Proximity](https://avatars.discourse-cdn.com/v4/letter/p/3ab097/32.png) [@Proximity](https://openziti.discourse.group/u/Proximity)
#### Post date: [May 10, 2024, 9:10pm UTC](https://openziti.discourse.group/t/cant-forward-to-a-dedicated-custom-domain-name/2541/1 "2024-05-10T21:10:09Z")

</div>

i got zrok standard for the custom domains but i found nothing on the docs on how to forward to a custom domain or where to get one from pls help me here.

---

<div class="post-metadata">

### Author: ![TheLumberjack](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/thelumberjack/32/113_2.png) [@TheLumberjack](https://openziti.discourse.group/u/TheLumberjack)
#### Post date: [May 11, 2024, 4:17am UTC](https://openziti.discourse.group/t/cant-forward-to-a-dedicated-custom-domain-name/2541/2 "2024-05-11T04:17:45Z")

</div>

Hi @Proximity, welcome to the community and to zrok (and OpenZiti)!

There's no way to accommodate custom domains with the cloud-hosted version of zrok at [zrok.io](http://zrok.io) at this time. You can of course, self-host zrok and use any domain you wish. It's a common request, though, and very well might be something we look to enable in the future.

---

<div class="post-metadata">

### Author: ![Proximity](https://avatars.discourse-cdn.com/v4/letter/p/3ab097/32.png) [@Proximity](https://openziti.discourse.group/u/Proximity)
#### Post date: [May 19, 2024, 8:25pm UTC](https://openziti.discourse.group/t/cant-forward-to-a-dedicated-custom-domain-name/2541/3 "2024-05-19T20:25:19Z")

</div>

ok thanks for your help

---

<div class="post-metadata">

### Author: ![icfausn](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/icfausn/32/2089_2.png) [@icfausn](https://openziti.discourse.group/u/icfausn)
#### Post date: [May 24, 2024, 2:41am UTC](https://openziti.discourse.group/t/cant-forward-to-a-dedicated-custom-domain-name/2541/4 "2024-05-24T02:41:14Z")

</div>

Why does [zrok.io](http://zrok.io) advertise "Dedicated Custom Domain Name" for the standard plan if they can 't provide that? I'm glad I ran across this before paying for what you claim to sell, but it seems pretty surprising, and it would certainly have resulted in a refund request. I'm hoping I'm misunderstanding because I'd love to start the standard plan. It looks great and is affordable for hobby work.

---

<div class="post-metadata">

### Author: ![smilindave26](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/smilindave26/32/185_2.png) [@smilindave26](https://openziti.discourse.group/u/smilindave26)
#### Post date: [May 24, 2024, 2:58am UTC](https://openziti.discourse.group/t/cant-forward-to-a-dedicated-custom-domain-name/2541/5 "2024-05-24T02:58:06Z")

</div>

Ugh. We jumped the gun listing this on the pricing page before the feature is released. I’ll make sure we correct the pricing page to be aligned with availability

---

<div class="post-metadata">

### Author: ![icfausn](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/icfausn/32/2089_2.png) [@icfausn](https://openziti.discourse.group/u/icfausn)
#### Post date: [May 24, 2024, 12:05pm UTC](https://openziti.discourse.group/t/cant-forward-to-a-dedicated-custom-domain-name/2541/6 "2024-05-24T12:05:18Z")

</div>

Sounds good. I will probably check back on occasion to see if/when it's added back to the pricing page so I can sign up once it's ready. Thanks for the quick reply and the hard work!

---

<div class="post-metadata">

### Author: ![stefanadelbert](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/stefanadelbert/32/2121_2.png) [@stefanadelbert](https://openziti.discourse.group/u/stefanadelbert)
#### Post date: [June 3, 2024, 6:44am UTC](https://openziti.discourse.group/t/cant-forward-to-a-dedicated-custom-domain-name/2541/7 "2024-06-03T06:44:09Z")

</div>

I'm also very interested in this feature. I can still see the Standard Plan listing "Private Network Option". Is that what we're talking about there or is that something else?

---

<div class="post-metadata">

### Author: ![smilindave26](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/smilindave26/32/185_2.png) [@smilindave26](https://openziti.discourse.group/u/smilindave26)
#### Post date: [June 3, 2024, 3:29pm UTC](https://openziti.discourse.group/t/cant-forward-to-a-dedicated-custom-domain-name/2541/8 "2024-06-03T15:29:12Z")

</div>

[zrok.io](http://zrok.io) today supports private shares: [Private Shares | Zrok](https://docs.zrok.io/docs/concepts/sharing-private/). A private share does not have a public address, and can only be accessed via zrok

[zrok.io](http://zrok.io) today supports reserved shares: [Reserved Shares | Zrok](https://docs.zrok.io/docs/concepts/sharing-reserved/). A reserved share lets you set the name of the share a client uses to access it. E.g., [https://MYRESERVEDSHARENAME.share.zrok.io](https://MYRESERVEDSHARENAME.share.zrok.io)

We are currently working on a "dedicated custom domain" for the hosted zrok offering, which will allow you to configure your own custom replacement of the ".share.zrok.io" part of the URL

---

<div class="post-metadata">

### Author: ![michael.quigley](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/michael.quigley/32/1123_2.png) [@michael.quigley](https://openziti.discourse.group/u/michael.quigley)
#### Post date: [June 3, 2024, 3:52pm UTC](https://openziti.discourse.group/t/cant-forward-to-a-dedicated-custom-domain-name/2541/9 "2024-06-03T15:52:23Z")

</div>

This may have been brought up elsewhere, but I'll put it here again in case it's helpful...

Even with the free tier of [zrok.io](http://zrok.io), it's very easy to to get ultra-cheap VPS hosting and run a `zrok access private` there. Combine that with a DNS entry for that host, and you've got a frontend with custom DNS... today.

In other words... `zrok access private` isn't just useful for workstations. Run it on a VPS or a container in the cloud and you've got an internet-facing gateway for your zrok share.

---

<div class="post-metadata">

### Author: ![stefanadelbert](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/stefanadelbert/32/2121_2.png) [@stefanadelbert](https://openziti.discourse.group/u/stefanadelbert)
#### Post date: [June 3, 2024, 11:59pm UTC](https://openziti.discourse.group/t/cant-forward-to-a-dedicated-custom-domain-name/2541/10 "2024-06-03T23:59:45Z")

</div>

Thanks for this clarity, @smilindave26. I'm a big plus one for dedicated custom domain.

---

<div class="post-metadata">

### Author: ![stefanadelbert](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/stefanadelbert/32/2121_2.png) [@stefanadelbert](https://openziti.discourse.group/u/stefanadelbert)
#### Post date: [June 4, 2024, 12:09am UTC](https://openziti.discourse.group/t/cant-forward-to-a-dedicated-custom-domain-name/2541/11 "2024-06-04T00:09:49Z")

</div>

@michael.quigley Thanks for this. I suppose it's a way to make a private share public, but with a customisable alias. Nice.

One really nice feature of zrok public share is access control with oauth. If that were the use case, then your proposed VPS+DNS solution would need to have some auth layer somewhere. GCP has IAP, but I wonder what you might suggest?

---

<div class="post-metadata">

### Author: ![michael.quigley](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/michael.quigley/32/1123_2.png) [@michael.quigley](https://openziti.discourse.group/u/michael.quigley)
#### Post date: [June 4, 2024, 1:03am UTC](https://openziti.discourse.group/t/cant-forward-to-a-dedicated-custom-domain-name/2541/12 "2024-06-04T01:03:48Z")

</div>

> [@stefanadelbert](#):
>
> One really nice feature of zrok public share is access control with oauth. If that were the use case, then your proposed VPS+DNS solution would need to have some auth layer somewhere. GCP has IAP, but I wonder what you might suggest?

Yeah. The best answer is for us to augment `zrok access private` to include the oauth components... that's not the immediate roadmap, but it's on the feature list once we're finally able to really dig into the `v0.5` work.

In the short term you'd have to stick something in front of `zrok access private`. I'd bet you could get something like that working with Caddy pretty easily... In fact, that's _probably_ what we'll do to incorporate more advanced features (like oauth) into the `zrok access private` server... we'll just embed Caddy.

It adds another piece of complexity to need to run an additional piece of software like Caddy... but I'd still bet one could spin up a tiny little micro-instance in the cloud and stick that proxy and `zrok access private` on it and have a nice little public bridge with custom DNS and such.

You could probably run a handful of `zrok access private` processes on a single instance... it's pretty lightweight. They could all go behind a single Caddy instance.

Obviously it'll all be much nicer when you can just click a couple of buttons in the zrok console and have the service take care of it for you... we're a small team and we're getting there as quickly as we can. Lotta work to do. 🙂

---

<div class="post-metadata">

### Author: ![stefanadelbert](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/stefanadelbert/32/2121_2.png) [@stefanadelbert](https://openziti.discourse.group/u/stefanadelbert)
#### Post date: [June 4, 2024, 2:07am UTC](https://openziti.discourse.group/t/cant-forward-to-a-dedicated-custom-domain-name/2541/13 "2024-06-04T02:07:14Z")

</div>

I'll need to work out where Caddy fits in. I'm very new to `zrok` and OpenZiti - like started using `zrok` day before yesterday (I'm trying to replace `ngrok`). I've seen the example Caddy file in the `frontdoor` installation.

My particular use case is giving support users secure and access controlled connectivity to web portals running in several private environments. The support users are semi-technical at best (so `zrok access private` isn't really an option, unfortunately).

I could see Caddy running on a VPS delegating (demultiplexing) to several `zrok share private`, one for each web portal. And then as long as Caddy can implement the oauth, there is a solution.

---

<div class="post-metadata">

### Author: ![michael.quigley](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/michael.quigley/32/1123_2.png) [@michael.quigley](https://openziti.discourse.group/u/michael.quigley)
#### Post date: [June 4, 2024, 2:24am UTC](https://openziti.discourse.group/t/cant-forward-to-a-dedicated-custom-domain-name/2541/14 "2024-06-04T02:24:50Z")

</div>

> [@stefanadelbert](#):
>
> I'll need to work out where Caddy fits in.

Basically, you'd just stick it as a reverse proxy in front of `zrok access private`.

> [@stefanadelbert](#):
>
> I could see Caddy running on a VPS delegating (demultiplexing) to several `zrok share private`, one for each web portal. And then as long as Caddy can implement the oauth, there is a solution.

Yes, exactly!

This might be useful to get Caddy configured the way you want:

> **[GitHub - greenpau/caddy-security: 🔐 Authentication, Authorization, and...](https://github.com/greenpau/caddy-security)**
>
> 🔐 Authentication, Authorization, and Accounting (AAA) App and Plugin for Caddy v2. 💎 Implements Form-Based, Basic, Local, LDAP, OpenID Connect, OAuth 2.0 (Github, Google, Facebook, Okta, etc.), SAM...

I bet there are similar tools for nginx if you preferred that to Caddy.

But yes... you'd basically be sticking a reverse proxy with authentication in front of a multiplicity of `zrok access private` instances (each of which is proxying through to a `zrok share` instance).

---

<div class="post-metadata">

### Author: ![stefanadelbert](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/stefanadelbert/32/2121_2.png) [@stefanadelbert](https://openziti.discourse.group/u/stefanadelbert)
#### Post date: [June 4, 2024, 6:37am UTC](https://openziti.discourse.group/t/cant-forward-to-a-dedicated-custom-domain-name/2541/15 "2024-06-04T06:37:45Z")

</div>

Thanks for the pointers, @michael.quigley. I have the basics working now. Caddy running on a micro VPS proxying two localhost services (which will later be several `zrok access private`s), accessible using a subdomain of my own domain. Nice.

I'm now looking at oauth configuration, specifically using google. Seems like I need to install Caddy with a 3rd party module, e.g. `greenpau/caddy-security`. I've downloaded Caddy including that plugin and manually replaced `/usr/bin/caddy` (_there must be a better way_ ™). Restarting with the new binary seems to work for the existing setup (without auth). So far so good.

I would find it really useful to have an example Caddy file which shows configuration for auth using Google for the greenpau/caddy-security plugin. Please let me know if you happen to know where I could find one. In the meantime I'm working through these,

- [authentication documentation](https://docs.authcrunch.com/docs/authenticate/intro)
- [google oauth2](https://docs.authcrunch.com/docs/authenticate/oauth/backend-oauth2-0002-google)
- [example Caddyfile](https://github.com/authcrunch/authcrunch.github.io/blob/main/assets/conf/oauth/google/Caddyfile)

---

<div class="post-metadata">

### Author: ![stefanadelbert](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/stefanadelbert/32/2121_2.png) [@stefanadelbert](https://openziti.discourse.group/u/stefanadelbert)
#### Post date: [June 5, 2024, 8:07am UTC](https://openziti.discourse.group/t/cant-forward-to-a-dedicated-custom-domain-name/2541/16 "2024-06-05T08:07:51Z")

</div>

@michael.quigley I've managed to get Caddy working with Google authentication reverse proxying a zrok private share. I took a while to get the Caddy stuff working, mostly because of the caddy-security plugin.

I've been using `frontdoor` (zrok-share) to run persistent public shares (with oauth). But it looks like `frontdoor` doesn't allow for private shares.

What is the recommended way to run long-running private shares? Perhaps @qrkourier has some good input on this.

---

<div class="post-metadata">

### Author: ![qrkourier](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/qrkourier/32/52_2.png) [@qrkourier](https://openziti.discourse.group/u/qrkourier)
#### Post date: [June 5, 2024, 1:14pm UTC](https://openziti.discourse.group/t/cant-forward-to-a-dedicated-custom-domain-name/2541/17 "2024-06-05T13:14:08Z")

</div>

@stefanadelbert Is Docker an option for you? I often run Caddy and zrok in Docker because it simplifies saving and remembering the various interdependent infrastructure and application configs as a handful of files in a single folder with Docker Compose.

That's the only way I can think of to do it with the zrok share examples we've published so far. Frontdoor was conceived for always-on public shares, and I can see the utility of a private share Linux service, too.

[This example](https://openziti.discourse.group/t/zrok-how-do-i-run-multiple-proxies-using-as-a-linux-service/1956/20) could be adapted for private shares or accesses or both. It uses a systemd feature to parameterize the service unit as a template for many service instances.

---

<div class="post-metadata">

### Author: ![michael.quigley](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/michael.quigley/32/1123_2.png) [@michael.quigley](https://openziti.discourse.group/u/michael.quigley)
#### Post date: [June 5, 2024, 2:20pm UTC](https://openziti.discourse.group/t/cant-forward-to-a-dedicated-custom-domain-name/2541/18 "2024-06-05T14:20:40Z")

</div>

> [@stefanadelbert](#):
>
> What is the recommended way to run long-running private shares?

If it were my setup and I needed to run long-running private shares, and I didn't want to use containers... just processes on a host... then I would just write a simple systemd unit file for each of the shares that manages a `zrok access private` process.

You can get very fancy with systemd... but you can also keep it really basic.

---

<div class="post-metadata">

### Author: ![stefanadelbert](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/stefanadelbert/32/2121_2.png) [@stefanadelbert](https://openziti.discourse.group/u/stefanadelbert)
#### Post date: [June 6, 2024, 12:20am UTC](https://openziti.discourse.group/t/cant-forward-to-a-dedicated-custom-domain-name/2541/19 "2024-06-06T00:20:34Z")

</div>

@michael.quigley @qrkourier Thanks, chaps.

I had considered a custom systemd unit (borrowing heavily from zrok-share), but then baulked at having to maintain and distribute that unit.

@qrkourier Thanks for the link to the systemd unit post using templates. I wasn't aware of that functionality - that's really neat.

I use docker compose extensively in other parts of the system, so this does seem like a cleaner option for me.

Something like,

- a `zrok share private` service added to the docker compose of each of my private endpoints
- a new docker compose on the public-facing proxy (Caddy) running services for
  - `zrok access private` for each private endpoint
  - caddy (google oauth, reverse proxy for each private share)

 ![image](https://global.discourse-cdn.com/free1/uploads/netfoundry/original/2X/d/dab5ddc985b672e3b0814c22da7c6e0be14c4879.png)

I've had a look at the [compose files in the zrok repo](https://github.com/openziti/zrok/tree/main/docker/compose). I got the `zrok-private-share` one working easily. But I don't see an example for **reserved** private shares, which I need for this use case. Looks like I'd need to modify one of those compose files to add a `reserve` step. This is a little tricky because `zrok reserve private ...` isn't idempotent. I'd need to mimic what `frontdoor` does for reserved shares or even use `zrok-share.bash` for the functionality. And then we've come full circle.

This is going to need some more thought and time from me. There is definitely a good solution here somewhere. Thanks for the help.

---

<div class="post-metadata">

### Author: ![michael.quigley](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/michael.quigley/32/1123_2.png) [@michael.quigley](https://openziti.discourse.group/u/michael.quigley)
#### Post date: [June 6, 2024, 1:06am UTC](https://openziti.discourse.group/t/cant-forward-to-a-dedicated-custom-domain-name/2541/20 "2024-06-06T01:06:30Z")

</div>

Excited to follow along with what you share.

Also know that we're working as fast as we can to improve the overall zrok experience and provide more of these kinds of capabilities out of the box for you. It's coming... but we're just a small scrappy team going as fast as we can.

[Next page](https://openziti.discourse.group/t/cant-forward-to-a-dedicated-custom-domain-name/2541.md?page=2)
