Skip to main content
A wildcard hostname lets one load balancer serve every name under a domain you own, such as app1.example.com and app2.example.com, with one certificate. Use it when you serve many subdomains and do not want to attach each one.
Wildcard hostnames are enabled per project by Datum. Contact Datum to turn them on for yours.

How it differs from an exact hostname

A wildcard covers names one label down. *.example.com serves app.example.com but not a.b.example.com. It also reserves every name beneath it for your project, so another project cannot attach one of those names.

Attach it

Quote the wildcard so your shell leaves the * alone.
hostname add does not wait. If the wildcard is refused, describe shows the reason under the hostname.

Publish the DNS records

describe ends with the records you still need to create at your DNS provider.
Create each record exactly as shown. The values above are examples; use the ones describe prints for your load balancer.

See the status

The same information is in the HTTPProxy status. This example shows a wildcard whose certificate is waiting on the project being enabled.
Each record’s state is Present once it takes effect on the public internet, and Missing while it is absent or wrong. managedBy is Platform for records Datum publishes in a Datum DNS zone, and User for records you publish. Once everything is in place, CertificateReady becomes True with reason CertificateIssued.

When the certificate is not issued

Exact hostnames on the same load balancer are unaffected and keep their own certificates.

If wildcards are later disabled

A certificate that has already been issued keeps serving. Disabling wildcards for a project stops new wildcard certificates from being issued, not existing ones.
Last modified on October 6, 2026