SSL and TLS

Managed HTTPS when you want automation. Your own TLS certificates when you need control.

Use auto-renewed Let's Encrypt certificates or upload and reuse an existing certificate across matching application routes.

  • Issue and renew Let's Encrypt certificates automatically
  • Upload and reuse custom TLS certificates across matching routes
  • Track certificate coverage, usage, status, and expiration

Use managed Let's Encrypt certificates for public routes

Application routes should be able to get trusted certificates without a separate certificate-management project.

Wodby supports trusted Let's Encrypt certificates for teams that want a simple default for public routes, while paid plans can use an uploaded custom certificate when the organization needs to retain its existing certificate workflow. Either choice stays attached to the hostname it secures instead of requiring hand-edited ingress configuration.

Managed Let's Encrypt

Let Wodby issue and renew a certificate automatically for supported technical and custom domains.

Uploaded custom TLS

Bring an existing certificate and reuse it across every route hostname that it covers.

Per-hostname selection

Choose managed TLS, a matching uploaded certificate, or no TLS for each route hostname.

Bring your own certificate without hand-editing ingress configuration

Keep an existing certificate workflow while Wodby handles validation, matching, and route attachment.

Upload a server certificate with its intermediate chain and matching unencrypted private key. Wodby verifies the key pair, validity, TLS server usage, and DNS names before storing the certificate as a reusable organization-level asset.

  • See only active certificates whose DNS names cover the route hostname.
  • Reuse one certificate across multiple matching application routes.
  • Keep certificate and private-key material in secrets while listings expose metadata only.
  • Review issuer, covered hostnames, fingerprint, validity, and every route usage.

Uploaded custom TLS certificates are included with Team and Enterprise plans. See the plan comparison or read the custom certificate documentation for accepted formats and validation details.

Automate managed renewals and get ahead of custom certificate expiration

Each certificate workflow gets the lifecycle behavior it needs without hiding who owns renewal.

Let's Encrypt renewal is handled automatically in the background. Uploaded certificates remain under your organization's renewal control, so Wodby shows their expiration and sends staged warnings to organization admins before a replacement is due.

Upload and select the replacement certificate before the current one expires. On Wodby infrastructure 4.0.0 and newer, certificate changes apply through the app instance's routing deployment, so application images and workloads do not need to be rebuilt or redeployed.

Extend encryption beyond public endpoints into internal services

Secure traffic matters inside the platform too, not only at the browser edge.

Wodby can generate certificates for internal services such as databases, helping teams keep more of the application topology covered by encrypted connections instead of limiting TLS to the public-facing endpoint alone.

Keep certificate inventory and route usage visible

Certificate operations are easier when teams can see what is active, where it is used, and what needs attention.

The organization certificate inventory brings managed and uploaded certificates together with their issuer, status, covered hostnames, validity dates, and current usage. Teams can investigate a certificate from one place, replace it deliberately, and delete uploaded material after it is no longer attached to any route.

Next step

Choose the certificate workflow that fits each domain

Use managed Let's Encrypt for automation or bring an existing certificate when policy, procurement, or an established certificate lifecycle requires it.