One-domain hosting without a DNS provider API is now available.
Set SITE_ROUTING_MODE=path and MAIN_DOMAIN; leave DNS_PROVIDER and DNS_CREDENTIALS_PATH blank. One A record and reachable ports 80/443 are enough. The main certificate is issued automatically through HTTP-01.
- Projects at /sites/slug-userId/ and drafts at /preview/slug-userId/.
- Custom domains retain automatic DNS checks, HTTP-01 certificates and root paths.
- System-address switch, project passwords and MCP support both modes.
- Path pages isolate management with a browser sandbox; public modules and assets support anonymous CORS. Use relative links/build base paths. Storage, credentialed fetch and service-worker apps should use a custom domain.
- No database migration. Default subdomain mode remains available.
Locally built linux/amd64 images; no GitHub Actions. See README and docs/deployment.md for configuration, and docs/images.md for digests and validation.
Validation: 18 tests, typecheck, lint, OpenAPI validation, dependency audit, real Pebble DNS-01/HTTP-01, management ACL, MCP in both modes, Chromium isolation/password/assets/modules checks, and mode switching on the same volumes. Live Let's Encrypt uses the operator's real domain at installation time.