Custom domain with a TLS/SSL certificate

​Akamai​'s Object Storage service supports shared and custom domain names:

  • By default, files can be accessed through secure, HTTPS URLs within the shared domain \*.linodeobjects.com.
  • You can also use a custom domain, such as a subdomain of \*.example.com.

Here, we cover the configuration of a custom domain and adding a TLS certificate to secure that custom domain. It uses Cloud Manager, but you can use the Linode CLI and the Linode API, too.

📘

Only supported with E0 and E1 endpoints

This configuration is only available for buckets created using an legacy E0 or E1 endpoint type. If your bucket was created using an E2 or E3 endpoint type you can't configure it as a custom domain with a TLS/SSL certificate.

Before you begin

You need a domain name to use with your Object Storage bucket. If you don't already own the domain, purchase it from a trusted registrar.

📘

When configuring Object Storage with a custom domain, you need to use a fully qualified domain name (FQDN), such as assets.example.com or any subdomain of \*.your-domain.tld. Apex (root) domains, such as example.tld, are not supported.

Create a bucket

If you haven't yet, create an E0 or E1 bucket. The bucket needs to be labeled using your fully qualified domain name, such as assets.example.com. If your files already exist in a bucket that doesn't have this label, create a new bucket with this label, and copy or move your files to it. You can use a third-party client like Cyberduck to do this.

Configure DNS

To connect your custom domain, create a CNAME DNS record within the name server for your domain. You can do this through your DNS provider, such as one operated by your domain registrar or a service like ​Akamai​ DNS Manager. Create the CNAME record using these values:

  • Hostname/Name. This is the custom domain you want to use. Each DNS provider may require slightly different formatting. In many cases, enter just the subdomain value. For example, if you plan to use assets.example.com, enter assets.

  • Alias To/Target. This is the full URL on the shared domain, excluding the https:// part of the URL, for your Object Storage bucket. The URL can be the default file host functionality of Object Storage or the URL used to host a static website, for example:

    • File URL. [bucket-label].[cluster-id].linodeobjects.com
    • Website URL. [bucket-label].website-[cluster-id].linodeobjects.com

For more information on DNS records and CNAME records, see our Overview of DNS and DNS Records guide.

Get a TLS/SSL certificate

Next, you need to get a TLS/SSL certificate through a trusted certificate authority (CA). Here, we're using the certbot tool, that lets you create free certificates through the Let's Encrypt CA. Skip this section if you already have a certificate.

Before you begin

You need a specific file with specific contents that's accessible on your custom domain, within a certain directory. Having followed this guide, your custom domain now points to your bucket. You can create this file directly in your ​Akamai​ account. You can use Cyberduck, the Linode CLI, s3cmd, s4cmd, or any other tool or application that integrates with Object Storage and lets you create folders and files.

Set up the certificate

  1. Install certbot. You can use your local machine, a Linode on Akamai Cloud, or any other compatible virtual machine:

  2. Manually generate a certificate with this command:

    sudo certbot certonly --manual
  3. When prompted, enter your custom domain, for example: assets.example.com and press Enter.

  4. At this point, certbot looks for the file you created earlier. If it's found, it generates the certificate along with its private key and saves them to your system:

    {{<output>}}
    Successfully received certificate.  
    Certificate is saved at: /etc/letsencrypt/live/assets.example.com/fullchain.pem  
    Key is saved at:         /etc/letsencrypt/live/assets.example.com/privkey.pem  
    This certificate expires on 2022-05-11.  
    These files will be updated when the certificate renews.  
    {{</output>}}
  5. You can view the saved certificate using a text editor. For instance, on a Linux system you can use sudo cat [file-location] to output the file or sudo nano [file-location] to open the file.

Upload your SSL certificate

To upload your new SSL certificate to an Object Storage Bucket:

  1. Log in to Cloud Manager and select Object Storage from the left menu.

  2. Open your bucket and select the SSL/TLS tab.

    A screenshot of the SSL/TLS Certificate page showing the Certificate and Private Key fields and the Upload Certificate button under them.
  3. In the Certificate field, enter the contents of the certificate file you just created or obtained.

  4. In the Private Key field, enter the contents of the corresponding private key file.

  5. Click the Upload Certificate button to submit the certificate and attach it to your bucket.

Upload your files or static website

Before you can test your custom domain, you need to have files hosted in your Object Storage bucket. Upload your files or your static website. Set the permissions so the files can be read by the public. If you don't, you won't be able to view the files through any URL, either shared or custom.

If you currently don't have any files, you can create a test file called index.html, edit it to include the following text, upload it to your bucket's main directory, and make sure the permissions are set so it can be read by the public.

<html>
    <body>
        <h1>Hello world...</h1>
    </body>
</html>

Access your secured custom domain

You can now access your files or static website using your secured custom domain. Open a web browser and enter your custom domain. If you're using Object Storage just to store and access files, include the file path of the file you want to access. If you are using Object Storage to host a website, you don't need to enter any additional file path, assuming you've uploaded an index.html file, or have set a different file as the default.


Did this page help you?