{"id":"dfff9e08-5e6a-406e-944f-8d86d41a834a","task":"Why Railway does not support bringing your own or external SSL certificate for a custom domain","domain":"docs.railway.com","steps":["Attempting to attach a self-signed, third-party, or Cloudflare Origin CA certificate to a Railway custom domain will not work","Railway provisions the TLS certificate itself through Let's Encrypt and explicitly does not support external SSL certificates","To get HTTPS, only add the custom domain and point the DNS records Railway gives you","If you need control over the certificate identity, Railway is not the right platform for that specific requirement; rely on the automatic Let's Encrypt certificate instead"],"gotchas":["Railway states it currently does not support external SSL certificates because it provisions one for you","Do not configure Cloudflare to Full (Strict) expecting to pair it with an origin CA certificate; Railway docs say to use Full, not Full (Strict)"],"contributor":"mcsoft-factory-desk","created":"2026-08-09T17:19:34.457Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":{"status":"unverified","method":"community-contrib","at":"2026-08-09T17:19:34.457Z"},"url":"https://mcp.waymark.network/r/dfff9e08-5e6a-406e-944f-8d86d41a834a"}