Early beta (0.1.0), not yet for critical processes. See the roadmap
PNeX logo

Names and TLS

Get a host name and HTTPS with or without a domain — mDNS, sslip.io / nip.io, your DNS, Let's Encrypt

Browsers, the native apps, passkeys and devices all need a host name that resolves to the server, and a certificate that carries it. Devices pin the certificate authority in their firmware, so pick the name before flashing them.

--domainExampleResolutionTLSWhen
(default)pnex.localmDNS on the LANlocal CARaspberry Pi or Linux on a home or lab LAN
sslip / nippnex-203-0-113-7.sslip.iopublic wildcard DNSLet's Encrypt (--tls cloud)public VM without a domain name
your namepnex.example.comyour DNSLet's Encrypt (--tls cloud) or local CAproduction, public access
an IP192.168.1.20nonelocal CAlast resort: passkeys are unavailable

Wildcard DNS: sslip.io and nip.io

sslip.io and nip.io are free DNS services that answer with the IP address written in the name:

pnex-203-0-113-7.sslip.io  →  203.0.113.7
pnex-203-0-113-7.nip.io    →  203.0.113.7

Their point is Let's Encrypt without DNS: a public VM named this way gets a certificate that every browser, app and device already trusts — no certificate authority to import anywhere.

curl -fsSL https://raw.githubusercontent.com/Pnex/pnex-deploy/main/install.sh \
  | sudo bash -s -- --domain sslip --ip 203.0.113.7 --tls cloud \
      --acme-email [email protected] --admin-user [email protected]

--domain sslip (or nip) builds the name from the server's address; --ip gives the public address when the VM only sees a private one behind the provider's NAT. The installer uses the dashed form: the name stays a single label, which certificates handle best.

With a private IP, a sslip.io name still works, with the local CA: you import the CA as with .local. The only gain over a bare IP is a real host name where mDNS fails (WSL, Android before 12, DNS-over-HTTPS browsers), which keeps passkeys usable. That is why the installer uses it by default on WSL.

Things to know:

  • Clients and devices need internet DNS. A fully offline network needs mDNS or its own DNS server.
  • Some routers drop public names resolving to private addresses (DNS rebinding protection): allow-list sslip.io / nip.io in the router, or use another resolver.
  • The name contains the IP: give the server a DHCP reservation. After an address change, re-run the installer with --domain sslip and re-flash the devices.
  • To depend on no third party, delegate a subdomain of your own zone to a self-hosted sslip.io DNS server, or create a wildcard record (*.lab.example.com) pointing at the server.

Local certificate authority

In local mode the installer creates a root CA once (10 years) and renews the server certificate automatically. Each client trusts the CA once; it is served at https://<server>/api/v1/meta/ca and shown in the web app under Profile → About. Back it up: pnexctl backup includes it, and devices must be re-flashed if it is lost.

Let's Encrypt

--tls cloud replaces the local CA by Let's Encrypt (HTTP-01 challenge, renewal every 12 hours). It needs a public name and ports 80 and 443 reachable from the internet. Devices trust the Let's Encrypt root (ISRG Root X1).

On this page