What you need
The certificates cover your base domain — thedomain in _infra/synthetiq.yaml, under which every app is served (my-app.apps.yourcompany.com). For apps.yourcompany.com:
A wildcard does not cover the bare domain — request the CDN certificate with the apex as an additional name (in ACM: a subject alternative name). A wildcard-only certificate fails verification at
generate.
Optional: add spare shard names to the API certificate
To get started, the API certificate only needs*.api.<domain>.
Adding spare shard names is a way to plan for capacity. One load balancer serves at most 100 apps, so an installation that grows past about 90 apps adds load balancer shards, each serving its apps at *.sN.api.<domain>. If the API certificate already lists *.s1.api through *.s9.api, adding a shard later is a config change and one DNS record, with no new certificate per shard. A certificate can’t gain names after it’s issued, so the start is the easiest time to add them. They cost nothing, and 10 names is the default limit for an ACM certificate.
With the AWS CLI:
Validation
Use DNS validation: ACM gives you one CNAME per name it needs to validate (one for the CDN certificate, and one per name on the API certificate) to create at your DNS provider — see DNS. Issuance completes within minutes of the records appearing, and the records also drive auto-renewal.Add the ARNs to your config
Once both certificates areISSUED, get the ARNs into _infra/synthetiq.yaml any of these ways:
- Run
synthetiq infra initwith AWS credentials — it discovers issued certificates for the domain automatically. - Pass them:
synthetiq infra init --cdn-cert-arn <arn> --api-cert-arn <arn>(offline init prompts for them). - Edit the
certs:block directly.
synthetiq infra generate verifies both at plan time — issued, correct region, covering the required names — and fails with the specific reason if not. If you run init before the certificates exist, it stops and prints what’s needed.
Renewal
ACM auto-renews DNS-validated certificates as long as the validation CNAMEs remain in your DNS, and the ARN never changes. This is one-time setup; you won’t revisit it unless you change your domain, or need shard names the API certificate doesn’t list. If you do replace a certificate, put the new ARN in the config and run the usualgenerate → provision: provisioning swaps it on the load balancer in place.
