SSL can remain pending when DNS is not propagated, domain verification failed, the certificate challenge failed, or the TLS secret was not created.
- Helps you check DNS, domain verification, and certificate status.
- Applies to automatic SSL and custom SSL route binding.
- Points to common ACME and ingress/Gateway issues.
- Domain status remains pending.
- HTTPS does not become active.
- The browser shows HTTP only or an invalid certificate.
- A domain added in Kubly.
- Correct DNS records.
- Auto SSL support or a valid custom certificate.
Screenshot Required
- Confirm the generated URL works first.
- Check that DNS records match the values shown in Kubly.
- Wait for DNS propagation.
- Verify the domain in Kubly.
- Check SSL status again.
- If using custom SSL, confirm the certificate and private key match.
- If auto SSL still fails, contact your operator with the domain, route, and SSL status.
- Changing DNS repeatedly before propagation finishes.
- Starting SSL before domain verification succeeds.
- Uploading an invalid PEM pair.
- Keep HTTP or the generated URL available while SSL is pending.
- Use custom SSL temporarily if auto SSL is blocked and production traffic is urgent.