Custom domain and Cloudflare
Your own domain
Section titled “Your own domain”- In Render, add the domain to the service (Settings → Custom Domains) and follow its
DNS instructions: usually a
CNAMErecord pointing at your….onrender.comaddress. - Once Render shows the certificate as issued, set
PUBLIC_BASE_URLto the new address, and add<new address>/auth/callbackto the Google OAuth client’s redirect URIs.
Requests to any other host, including the ….onrender.com address, are then redirected
to PUBLIC_BASE_URL.
Behind Cloudflare (optional)
Section titled “Behind Cloudflare (optional)”If the domain’s DNS is on Cloudflare, you can proxy it (the orange cloud):
-
Encryption: set the SSL/TLS mode for this hostname to Full (strict), for example with a Configuration Rule. Anything weaker leaves the hop to Render unverified.
-
Scanner noise: as soon as a certificate is issued, scanners that watch the public certificate logs start probing for files like
/.env. Nothing leaks (the app never serves them), but every probe reaches the app and can wake it. A free WAF custom rule stops them at Cloudflare. Under Security → Security rules, create a custom rule with the action Block, using your hostname:(http.host eq "jobs.example.com" and ((http.request.uri.path contains "/." and not starts_with(http.request.uri.path, "/.well-known/"))or starts_with(http.request.uri.path, "/wp-")or ends_with(http.request.uri.path, ".php")or starts_with(http.request.uri.path, "/cgi-bin/")))Keep
/.well-known/open: certificate renewal uses it.